Network access method and terminal equipment
By generating session keys and routing information between terminal devices, the problem of high latency and complexity of terminal devices is solved, and efficient networking of massive devices is achieved.
Patent Information
- Application Number
- CN202410174631.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-06
- Publication Date
- 2025-08-08
AI Technical Summary
In the prior art, terminal equipment needs mutual authentication when forming networking, resulting in large network delays and high complexity, and cannot support efficient networking of massive equipment.
The first terminal device generates a session key between the second terminal device and the third terminal device, and sends the key and routing information to both, so that the second terminal device can join the network without directly authenticating with the third terminal device.
It reduces the network delay and complexity and supports efficient networking of massive equipment.
Smart Images

Figure CN120456016A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of networking technology, and in particular to a network access method and terminal equipment. Background Art
[0002] With the construction of smart ecology, terminal devices (such as mobile phones, tablets, etc.) can be connected to each other through various methods such as wireless fidelity (Wi-Fi), Bluetooth (BT) or soft bus to communicate with each other and share resources.
[0003] When terminal devices are connected to a network through various methods such as Wi-Fi, Bluetooth or soft bus, mutual authentication is required between the terminal devices. That is, when N terminal devices are connected to a network, mutual authentication is required. For example, network 1 includes device 1, device 2, device 3, device 4 and device 5. Device 1, device 2, device 3, device 4 and device 5 need to authenticate each other to form network 1, that is, device 1, device 2, device 3, device 4 and device 5 need to authenticate each other. Certification, among which, If device 6 wants to join the network 1, device 6 needs to exchange authentication information with device 1, device 2, device 3, device 4 and device 5 in the network 1 respectively, that is, device 6 needs to perform five authentications.
[0004] As can be seen, when a terminal device seeking to join a network establishes a connection with a terminal device in the network, it must scan the terminal devices in the network one by one, resulting in significant network delays. Furthermore, as the number of terminal devices seeking to join increases, the number of authentication times also increases, leading to increased network complexity. Therefore, existing networking solutions cannot efficiently support the networking of massive numbers of terminal devices. Summary of the Invention
[0005] The embodiments of the present application provide a network access method and terminal device for supporting efficient networking of a large number of terminal devices.
[0006] In a first aspect, an embodiment of the present application provides a network access method, which is applicable to a first terminal device or a component in the first terminal device (such as a unit / module, circuit or chip, etc.). Taking the method applicable to the first terminal device as an example, the first terminal device is a central device of the first network, and the method includes: receiving a first authentication request from a second terminal device, the first authentication request is used to request to join the first network; sending a first authentication response to the second terminal device, the first authentication response is used to confirm that the second terminal device joins the first network; generating a first session key, the first session key is a session key between the second terminal device and a third terminal device, and the third terminal device is a non-central device of the first network other than the second terminal device; sending the first session key and first routing information to the second terminal device, and sending the first session key and second routing information to the third terminal device, the first routing information and the second routing information are used for the second terminal device to communicate with the third terminal device.
[0007] In an embodiment of the present application, if the second terminal device wants to join the first network, after the first terminal device and the second terminal device authenticate each other, the first terminal device can generate a session key between the second terminal device and the third terminal device, and send the session key and the routing information used for the second terminal device and the third terminal device to the second terminal device and the third terminal device respectively, so that the second terminal device and the third terminal device do not need to authenticate each other to communicate. That is, the second terminal device only needs to authenticate with the first terminal device once to join the first network, which reduces the networking delay and networking complexity, thereby being able to support efficient networking of a large number of devices.
[0008] In one possible implementation, before receiving the first authentication request from the second terminal device, the method further includes: sending first information to the third terminal device, the first information including one or more of the following: device information of the first terminal device; first indication information, used to indicate that the first terminal device is a central device; or, second indication information, used to indicate a key distribution mode, the key distribution mode including point-to-point distribution or broadcast distribution.
[0009] In this implementation, after the first network determines that the first terminal device is a central device and the third terminal device is a non-central device, the third terminal device can determine, based on the first information from the first terminal device, that the session keys between all non-central devices in the first network are distributed point-to-point or broadcast by the first terminal device. Compared with the method in which devices in the network need to authenticate each other to negotiate session keys between devices, the network delay and network complexity are reduced, thereby supporting efficient networking of a large number of devices.
[0010] In one possible implementation, the first authentication request includes the public key of the second terminal device and the device information of the second terminal device, the first authentication response includes the public key of the first terminal device and the device information of the first terminal device, the public key of the second terminal device and the device information of the second terminal device are used to generate a second session key, the public key of the first terminal device and the device information of the first terminal device are used to generate the second session key, and the second session key is the session key between the first terminal device and the second terminal device.
[0011] In this implementation, the first terminal device and the second terminal device can authenticate each other and negotiate a session key by transmitting their own device information and public keys to each other. Since the session key determined by the first terminal device based on the public key of the second terminal device and the device information of the second terminal device is the same as the session key determined by the second terminal device based on the public key of the first terminal device and the device information of the first terminal device, the first terminal device and the second terminal device do not need to transmit the session key to each other, thereby improving the security of communication.
[0012] In one possible implementation, the second terminal device is a central device of the second network, and the fourth terminal device is a non-central device of the second network; the method also includes: receiving third routing information from the second terminal device and device information of the fourth terminal device, the third routing information being used for communication between the second terminal device and the fourth terminal device; generating a third session key, the third session key being a session key between the fourth terminal device and the third terminal device; sending the third session key and fourth routing information to the second terminal device, and sending the third session key and fifth routing information to the third terminal device, the fourth routing information and the fifth routing information being used for communication between the fourth terminal device and the third terminal device.
[0013] In this implementation, if the second terminal device and the fourth terminal device located in the second network both want to join the first network, after the first terminal device and the second terminal device mutually authenticate each other, the second terminal device can send the device information of the fourth terminal device and the routing information used for communication between the second terminal device and the fourth terminal device to the first terminal device. The first terminal device can generate a session key between the fourth terminal device and the third terminal device and determine the routing information used for communication between the fourth terminal device and the third terminal device, and send the session key and the routing information used for communication between the fourth terminal device and the third terminal device to the second terminal device and the third terminal device, respectively. The second terminal device can send the session key and the routing information used for communication between the fourth terminal device and the third terminal device, respectively, to the fourth terminal device, so that the fourth terminal device can communicate with the first terminal device and the third terminal device without mutual authentication. That is, the fourth terminal device can join the first network without authentication, which reduces the network delay and network complexity, thereby supporting efficient networking of a large number of devices.
[0014] In one possible implementation, the second terminal device and the fifth terminal device are not located in the same network, and the method further includes: receiving a second authentication request from the fifth terminal device, the second authentication request being used to request joining the first network; sending a second authentication response to the fifth terminal device, the second authentication response being used to confirm that the fifth terminal device has joined the first network; generating a fourth session key, the fourth session key being the session key between the fifth terminal device and the third terminal device; sending the fourth session key and sixth routing information to the fifth terminal device, and sending the fourth session key and seventh routing information to the third terminal device, the sixth routing information and the seventh routing information being used for the fifth terminal device to communicate with the third terminal device.
[0015] In this implementation, if the second terminal device and the fifth terminal device, which are not in the same network, want to join the first network at the same time, after the first terminal device and the fifth terminal device authenticate each other, the first terminal device can generate a session key between the fifth terminal device and the third terminal device, and send the session key and the routing information used for the fifth terminal device to communicate with the third terminal device to the fifth terminal device and the third terminal device respectively, so that the fifth terminal device and the third terminal device can communicate without mutual authentication, that is, the fifth terminal device only needs to authenticate with the first terminal device once to join the first network, which reduces the network delay and network complexity, thereby supporting efficient networking of a large number of devices.
[0016] In a possible implementation, generating the first session key includes: generating a root key of a session key between terminal devices in the first network; and generating the first session key based on the root key.
[0017] In this implementation, a method for generating a first session key is provided. For example, the first terminal device may generate the first session key based on a root key of a session key between terminal devices in the first network.
[0018] In one possible implementation, generating the first session key based on the root key includes: deriving the first session key based on the device information of the second terminal device, the device information of the third terminal device and the root key; or randomly generating the first session key and encrypting the first session key based on the root key.
[0019] This implementation provides multiple methods for generating a first session key based on the root key of the session key between terminal devices in the first network. For example, the first terminal device can derive the first session key. Since the derived first session key is associated with the device information of the second and third terminal devices, the security of the first session key is improved. Alternatively, the first terminal device can randomly generate the first session key. Since the randomly generated first session key is independent of the device information of the second and third terminal devices, the method for generating the first session key by the first terminal device is more flexible.
[0020] In one possible implementation, the first session key is a session-level key, and the session-level key is used to indicate that the session keys between the terminal devices of the first network are different; or, the first session key is a network-level key, and the network-level key is used to indicate that the session keys between the terminal devices of the first network are the same.
[0021] In this implementation, the session keys between the terminal devices of the first network generated by the first terminal device can be the same or different. For example, the same session keys between the terminal devices of the first network are suitable for small-scale network scenarios, and different session keys between the terminal devices of the first network are suitable for large-scale network scenarios where data can be shared between devices, making the way the first terminal device generates the first session key more flexible.
[0022] In a possible implementation, generating the third session key includes: generating a root key of the session key between terminal devices in the first network; and generating the third session key based on the root key.
[0023] In this implementation, a method for generating the third session key is provided. For example, the first terminal device may generate the third session key based on the root key of the session key between the terminal devices in the first network.
[0024] In one possible implementation, the third session key is generated based on the root key, including: deriving the third session key based on the device information of the fourth terminal device, the device information of the third terminal device and the root key; or, randomly generating the third session key and encrypting the third session key based on the root key.
[0025] This implementation provides multiple methods for generating a third session key based on the root key of the session key between terminal devices in the first network. For example, the first terminal device can derive the third session key. Since the derived third session key is associated with the device information of the fourth terminal device and the third terminal device, the security of the third session key is improved. Alternatively, the first terminal device can randomly generate the third session key. Since the randomly generated third session key is independent of the device information of the fourth terminal device and the third terminal device, the method for generating the third session key by the first terminal device is more flexible.
[0026] In one possible implementation, the third session key is a session-level key, which is used to indicate that the session keys between the terminal devices of the first network are different; or, the third session key is a network-level key, which is used to indicate that the session keys between the terminal devices of the first network are the same.
[0027] In this implementation, the session keys between the terminal devices of the first network generated by the first terminal device can be the same or different. For example, the same session keys between the terminal devices of the first network are suitable for small-scale network scenarios, and different session keys between the terminal devices of the first network are suitable for large-scale network scenarios where data can be shared between devices, making the way the first terminal device generates the third session key more flexible.
[0028] In a possible implementation, generating the fourth session key includes: generating a root key of the session key between terminal devices in the first network; and generating the fourth session key based on the root key.
[0029] In this implementation, a method for generating the fourth session key is provided. For example, the first terminal device may generate the fourth session key based on the root key of the session key between the terminal devices in the first network.
[0030] In one possible implementation, the fourth session key is generated based on the root key, including: deriving the fourth session key based on the device information of the fifth terminal device, the device information of the third terminal device and the root key; or, randomly generating the fourth session key and encrypting the fourth session key based on the root key.
[0031] This implementation provides multiple methods for generating a fourth session key based on the root key of the session key between terminal devices in the first network. For example, the first terminal device can derive the fourth session key. Since the derived fourth session key is associated with the device information of the fifth terminal device and the third terminal device, the security of the fourth session key is improved. Alternatively, the first terminal device can randomly generate the fourth session key. Since the randomly generated fourth session key is independent of the device information of the fifth terminal device and the third terminal device, the method for generating the fourth session key by the first terminal device is more flexible.
[0032] In one possible implementation, the fourth session key is a session-level key, which is used to indicate that the session keys between the terminal devices of the first network are different; or, the fourth session key is a network-level key, which is used to indicate that the session keys between the terminal devices of the first network are the same.
[0033] In this implementation, the session keys between the terminal devices of the first network generated by the first terminal device can be the same or different. For example, the same session keys between the terminal devices of the first network are suitable for small-scale network scenarios, and different session keys between the terminal devices of the first network are suitable for large-scale network scenarios where data can be shared between devices, making the way the first terminal device generates the fourth session key more flexible.
[0034] In a second aspect, an embodiment of the present application further provides a network access device. The network access device has the function of implementing the behavior in the method embodiment described in the first aspect or any possible design of the first aspect. The network access device may be the first terminal device described in the first aspect, or a functional module (such as a chip system) configured in the first terminal device, or a larger device including the first terminal device. The first terminal device includes corresponding means (means) or modules for executing the above method. For example, the network access device may include a processing unit (sometimes also referred to as a processing module) and a transceiver unit (sometimes also referred to as a transceiver module).
[0035] Optionally, the transceiver unit is used to receive a first authentication request from a second terminal device, where the first authentication request is used to request to join the first network.
[0036] Optionally, the transceiver unit is further used to send a first authentication response to the second terminal device, where the first authentication response is used to confirm that the second terminal device has joined the first network.
[0037] Optionally, the processing unit is configured to generate a first session key, where the first session key is a session key between the second terminal device and a third terminal device, and the third terminal device is a non-central device in the first network other than the second terminal device.
[0038] Optionally, the transceiver unit is also used to send the first session key and first routing information to the second terminal device, and to send the first session key and second routing information to a third terminal device, where the first routing information and the second routing information are used for communication between the second terminal device and the third terminal device.
[0039] In a third aspect, an embodiment of the present application also provides a terminal device, comprising a processor, a memory, and one or more programs; wherein the one or more programs are stored in the memory, and the one or more programs include instructions, which, when executed by the processor, enable the terminal device to execute the method described in the first aspect or any possible design of the first aspect.
[0040] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, which is used to store a computer program. When the computer program runs on a computer, the computer executes the method described in the first aspect or any possible design of the first aspect.
[0041] In a fifth aspect, an embodiment of the present application further provides a computer program product, comprising a computer program, which, when run on a computer, enables the computer to execute the method described in the first aspect or any possible design of the first aspect.
[0042] In a sixth aspect, an embodiment of the present application also provides a chip system, comprising a processor and an interface, wherein the processor is used to call and run instructions from the interface so that the chip system executes the method described in the first aspect or any possible design of the first aspect.
[0043] The beneficial effects of the second to sixth aspects and their possible designs can refer to the description of the beneficial effects of the method described in the first aspect and any possible design thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 A schematic diagram of a home networking scenario provided in an embodiment of the present application;
[0045] Figure 2 A schematic diagram of a cockpit networking scenario provided in an embodiment of the present application;
[0046] Figure 3 A schematic diagram of a networking scenario provided in an embodiment of the present application;
[0047] Figure 4 A schematic diagram of the architecture of a network access system provided in an embodiment of the present application;
[0048] Figure 5 A schematic diagram of the hardware structure of a terminal device provided in an embodiment of the present application;
[0049] Figure 6 A flowchart of a network access method provided in an embodiment of the present application;
[0050] Figure 7 A flowchart of another network access method provided in an embodiment of the present application;
[0051] Figure 8 A flowchart of another network access method provided in an embodiment of the present application;
[0052] Figure 9 A schematic diagram of another networking scenario provided in an embodiment of the present application;
[0053] Figure 10 A flowchart of another network access method provided in an embodiment of the present application;
[0054] Figure 11 A schematic diagram of another networking scenario provided in an embodiment of the present application;
[0055] Figure 12 A schematic diagram of the hardware structure of another terminal device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0056] Below, some terms used in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.
[0057] 1) The at least one involved in the embodiments of the present application includes one or more; wherein, more means greater than or equal to two. In addition, it should be understood that, in the description of this specification, words such as "first" and "second" are only used for the purpose of distinguishing the description, and cannot be understood as expressing or implying relative importance, nor can they be understood as expressing or implying order. For example, the first operation and the second operation do not represent the importance of the two or the order of the two, but are only for distinguishing the description. In the embodiments of the present application, "and / or" is only a description of the association relationship, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the previous and next associated objects are in an "or" relationship.
[0058] In the description of the embodiments of the present application, it should be noted that, unless otherwise clearly specified and limited, the terms "installation" and "connection" should be understood in a broad sense. For example, "connection" can be a detachable connection or a non-detachable connection; it can be a direct connection or an indirect connection through an intermediate medium. The directional terms mentioned in the embodiments of the present application, such as "up", "down", "left", "right", "inside", "outside", etc., are only reference to the directions of the accompanying drawings. Therefore, the directional terms used are for better and clearer explanation and understanding of the embodiments of the present application, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on the embodiments of the present application.
[0059] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of the specification. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in yet other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0060] 2) The soft bus is a unified base for multiple terminal devices, providing unified communication capabilities for interconnection between terminal devices (including but not limited to central processing unit (CPU) / graphics processing unit (GPU) capabilities, screen capabilities, storage capabilities, microphone (microphone, MIC) capabilities, sensing capabilities, camera capabilities, keyboard, mouse, and stylus input capabilities, and speaker capabilities). It can quickly discover and connect terminal devices and efficiently distribute tasks and transmit data.
[0061] 3) Networking: Terminal devices can be connected to each other through various methods such as wireless fidelity (Wi-Fi), Bluetooth (BT) or soft bus to communicate with each other and share resources.
[0062] For example, Figure 1 A schematic diagram of a home networking scenario provided in an embodiment of the present application is shown in FIG. Figure 1 As shown, taking a home scenario as an example, multiple devices, such as mobile phones, tablets, smart speakers, smart TVs, smart soymilk makers, and smart range hoods, can be connected to a network via various methods, including Wi-Fi, BT, or soft bus. Furthermore, devices in different areas can also be connected to form subnets within the network. For example, the smart TV and smart speakers in the living room can be connected to form subnet 1, while the smart soymilk maker and smart range hood in the kitchen can be connected to form subnet 2.
[0063] For example, Figure 2 A schematic diagram of a cockpit networking scenario provided in an embodiment of the present application is shown as follows: Figure 2 As shown, taking the terminal devices in the cockpit scenario as an example, the mobile phone, the central control screen of the vehicle terminal, the co-pilot screen of the vehicle terminal and the rear screen of the vehicle terminal can be connected to the network through various methods such as Wi-Fi, BT or soft bus.
[0064] Multiple terminal devices in the same network can be bound to each other through the same account. A router or modem can store information about multiple terminal devices associated with the same account. Any terminal device can remotely control other terminal devices bound to it through the router or modem, and other terminal devices bound to it can also report their status information to the terminal device through the router or modem.
[0065] For example, Figure 1Take the home networking scenario shown as an example. The router or modem can receive instructions from the mobile phone to control the smart speaker (such as instructions to turn on the smart speaker). When it is determined that the mobile phone and the smart speaker are associated with the same account, the router or modem can send the control instruction to the smart speaker, so that the smart speaker performs the operation corresponding to the control instruction. The router or modem can also receive messages from the smart speaker to report its own status information to the mobile phone (such as messages indicating the battery level of the smart speaker). When it is determined that the mobile phone and the smart speaker are associated with the same account, the router or modem can send the above-mentioned message indicating the status information of the smart speaker to the mobile phone, so that the mobile phone updates the status information of the smart speaker.
[0066] When terminal devices are connected to a network through various methods such as Wi-Fi, Bluetooth or soft bus, mutual authentication is required between the terminal devices. It can be understood that when N terminal devices are connected to a network, mutual authentication is required. The whole networking process can be completed only after two authentications. For example, Figure 3 This is a schematic diagram of a networking scenario provided by an embodiment of the present application. Figure 3 As shown in the figure, network 1 includes device 1, device 2, device 3, device 4 and device 5. Device 1, device 2, device 3, device 4 and device 5 need to authenticate each other to form network 1, that is, devices 1, device 2, device 3, device 4 and device 5 need to authenticate each other. Certification, among which, If device 6 wants to join the network 1, device 6 needs to exchange authentication information with device 1, device 2, device 3, device 4 and device 5 in the network 1 respectively, that is, device 6 needs to perform five authentications.
[0067] As can be seen, when a terminal device seeking to join a network establishes a connection with a terminal device in the network, it must scan the terminal devices in the network one by one, resulting in significant network delays. Furthermore, as the number of terminal devices seeking to join increases, the number of authentication times also increases, leading to increased network complexity. Consequently, this approach cannot efficiently support the networking of a large number of terminal devices.
[0068] In view of this, an embodiment of the present application provides a network access method to support efficient networking of a large number of terminal devices.
[0069] The technical solution of the embodiments of the present application can be applied to a network access system composed of multiple terminal devices, or can also be applied to a network access system composed of multiple terminal devices and multiple network devices. The embodiments of the present application do not limit this. For the sake of convenience, the technical solution of the embodiments of the present application is applied to a network access system composed of multiple terminal devices as an example. Figure 4 This is a schematic diagram of the architecture of a network access system. Figure 4As shown, the network access system may include terminal devices 100, 200, 300, 400, and 500. The terminal devices 100, 200, 300, 400, and 500 may be mobile phones, tablet computers, desktop computers, laptop computers, handheld computers, notebook computers, ultra-mobile personal computers (UMPCs), netbooks, personal digital assistants (PDAs), and smart devices (e.g., smart lights, smart ovens, smart fans, smart air conditioners, smart TVs, smart bracelets, smart speakers, smart refrigerators, smart doors and windows, smart cars, smart monitors, smart robots, etc.). The embodiments of the present application do not limit the specific types of the terminal devices 100, 200, 300, 400, and 500.
[0070] like Figure 4 As shown, terminal device 100 and terminal device 300 can be located in a first network, where terminal device 100 can be the central device of the first network and terminal device 300 can be a non-central device of the first network. Terminal device 200 and terminal device 400 can be located in a second network, where terminal device 200 can be the central device of the second network and terminal device 400 can be a non-central device of the second network. Terminal device 500 can be located in neither the first network nor the second network; that is, terminal device 500 is an independent terminal device that is not a member of either network.
[0071] It should be understood that Figure 4 For ease of understanding only, an exemplary network access system is shown, but this should not constitute any limitation to the present application. The network access system may also include a larger number of terminal devices. For example, the first network may also include more non-central devices (for example, terminal device 600), and the second network may also include more non-central devices (for example, terminal device 700). The non-central devices included in the first network and the non-central devices included in the second network may be all the same (for example, terminal device 300 and terminal device 400 are the same terminal device), or may be all different (that is, terminal device 300 and terminal device 400 are different terminal devices), or may be partially the same (for example, terminal device 300 and terminal device 600 are non-central devices of network 1, terminal device 400 and terminal device 700 are non-central devices of the second network, terminal device 300 and terminal device 400 are the same terminal device, and terminal device 600 and terminal device 700 are different terminal devices). The number of non-central devices included in the first network and the number of non-central devices included in the second network may be the same or different, and the embodiments of the present application do not specifically limit this.
[0072] Figure 5 This is a schematic diagram of the hardware structure of a terminal device. Figure 5 As shown, the terminal device may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc.
[0073] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors. The controller may serve as the nerve center and command center of the terminal device. The controller may generate operation control signals based on instruction opcodes and timing signals to control instruction fetching and execution. The processor 110 may also include memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a high-speed cache memory. This memory may store instructions or data that have just been used or are being recycled by the processor 110. If the processor 110 needs to use the instruction or data again, it can directly call the instruction or data from the memory. This avoids duplicate accesses, reduces the processor 110's waiting time, and thus improves system efficiency. The execution of the network access method provided in the embodiment of the present application can be controlled by the processor 110 or completed by calling other components, such as calling the processing program of the embodiment of the present application stored in the internal memory 121, or calling the processing program of the embodiment of the present application stored in a third-party device through the external memory interface 120.
[0074] The internal memory 121 can be used to store computer executable program codes, which include instructions. The processor 110 executes various functional applications and data processing of the terminal device by running the instructions stored in the internal memory 121. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system, and the software code of at least one application, etc. The data storage area can store data generated during the use of the terminal device (such as captured images, recorded videos, etc.). In addition, the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0075] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the terminal device. The external memory card communicates with the processor 110 via the external memory interface 120 to implement data storage functions. For example, files such as pictures and videos can be saved on the external memory card.
[0076] The USB interface 130 is an interface that complies with USB standard specifications, and can specifically be a Mini USB interface, a Micro USB interface, a USB Type-C interface, etc. The USB interface 130 can be used to connect a charger to charge the terminal device, and can also be used to transfer data between the terminal device and peripheral devices. The charging management module 140 is used to receive charging input from the charger. The power management module 141 is used to connect the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140, and provides power to the processor 110, the internal memory 121, the external memory, the display 194, the camera 193, and the wireless communication module 160.
[0077] The wireless communication function of the terminal device can be implemented through antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, modem processor and baseband processor.
[0078] Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the terminal device can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch.
[0079] The mobile communication module 150 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied to terminal devices. The mobile communication module 150 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the processor 110. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the same device as at least some of the modules of the processor 110.
[0080] The wireless communication module 160 can provide wireless communication solutions including WLAN (such as wireless fidelity (WIFI) network), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication technology (NFC), infrared technology (IR), etc. applied to the terminal device. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, frequency modulates and filters the electromagnetic wave signal, and sends the processed signal to the processor 110. The wireless communication module 160 can also receive the signal to be sent from the processor 110, frequency modulate it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.
[0081] In some embodiments, antenna 1 of the terminal device is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, so that the terminal device can communicate with a network and other devices via wireless communication technology. The wireless communication technology may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology. The GNSS may include a global positioning system (GPS), a global navigation satellite system (GLONASS), a Beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS) and / or a satellite based augmentation system (SBAS).
[0082] Display screen 194 is used to display the display interface of the application, such as the display page of the application installed on the terminal device. Display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode or an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a MiniLED, a MicroLed, a Micro-oLed, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the terminal device may include one or N display screens 194, where N is a positive integer greater than one.
[0083] The camera 193 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, and then passes the electrical signal to the ISP for conversion into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV or other format. In some embodiments, the terminal device may include 1 or N cameras 193, where N is a positive integer greater than 1.
[0084] The terminal device can implement audio functions such as music playback and recording through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the headphone jack 170D, and the application processor.
[0085] Among them, the sensor module 180 may include a pressure sensor 180A, an acceleration sensor 180B, a touch sensor 180C, etc.
[0086] The pressure sensor 180A is used to sense the pressure signal and convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor 180A can be disposed on the display screen 194 .
[0087] Touch sensor 180C, also known as a "touch panel," can be disposed on display screen 194. The touch sensor 180C and display screen 194 form a touch screen, also known as a "touch screen." Touch sensor 180C is used to detect touch operations applied thereto or in the vicinity thereof. The touch sensor can transmit the detected touch operations to an application processor to determine the type of touch event. Visual output related to the touch operations can be provided via display screen 194. In other embodiments, touch sensor 180C can also be disposed on the surface of the terminal device, at a location different from that of display screen 194.
[0088] The buttons 190 include a power button, a volume button, etc. The button 190 can be a mechanical button. It can also be a touch button. The terminal device can receive button input and generate key signal input related to the user settings and function control of the terminal device. Motor 191 can generate vibration prompts. Motor 191 can be used for incoming call vibration prompts, and can also be used for touch vibration feedback. For example, touch operations acting on different applications (such as taking pictures, audio playback, etc.) can correspond to different vibration feedback effects. The touch vibration feedback effect can also support customization. The indicator 192 can be an indicator light, which can be used to indicate the charging status, power changes, and can also be used to indicate messages, missed calls, notifications, etc. The SIM card interface 195 is used to connect the SIM card. The SIM card can be inserted into the SIM card interface 195 or pulled out from the SIM card interface 195 to achieve contact and separation with the terminal device.
[0089] It is understandable that Figure 5 The components shown do not constitute a specific limitation on the terminal device. The terminal device may also include more or fewer components than shown in the figure, or combine some components, or split some components, or arrange the components differently. Figure 5 The combination / connection relationship between the components can also be adjusted and modified.
[0090] The above content describes the system architecture and possible application scenarios applicable to the technical solutions of the embodiments of the present application. In order to better understand the technical solutions of the embodiments of the present application, the following will be combined with the above Figure 4 The structure of the access system shown and Figure 5 The structure of the terminal device shown further introduces the network access method provided in the embodiment of the present application.
[0091] Figure 6 The first terminal device described below can be Figure 4 The terminal device 100 shown in FIG. 1 , the second terminal device hereinafter may be Figure 4 The terminal device 200 shown in FIG. 200 , the third terminal device described below may be Figure 4The terminal device 300 shown in FIG. 3 may be a fourth terminal device described below. Figure 4 The terminal device 400 shown in FIG. 4 may be a terminal device 400. The fifth terminal device described below may be a terminal device 400. Figure 4 The terminal device 500 is shown. In the embodiment of the present application, the first terminal device is used as an example to introduce the execution subject of the method, or the execution subject of the method can also be other devices or systems, such as a chip, chip system or processor applied to the first terminal device.
[0092] Step 601: The second terminal device sends a first authentication request to the first terminal device. Correspondingly, the first terminal device receives the first authentication request from the second terminal device.
[0093] In the embodiments of the present application, the first terminal device may be located in a first network, and the first terminal device may be a central device of the first network. The second terminal device may be located in a second network, and the second terminal device may be a central device of the second network. Alternatively, the second terminal device may not be located in the second network, and it can be understood that the second terminal device is an independent terminal device that is not part of any network.
[0094] Among them, the central device of any network can be elected based on the configuration file corresponding to the network, for example, network 1 includes terminal device 1 and terminal device 2, and the configuration file corresponding to network 1 elects terminal device 1 as the central device of network 1; or, the central device of any network can also be elected based on the device type of each terminal device in the network, for example, network 1 includes terminal device 1 and terminal device 2, the device type of terminal device 1 is type 1, and the device type of terminal device 2 is type 2, and the priority of type 1 is higher than the priority of type 2, so terminal device 1 will be elected as the central device of network 1; or, the central device of any network can also be elected based on the device weight of each terminal device in the network, for example, network 1 includes terminal device 1 and terminal device 2, the device weight of terminal device 1 is weight 1, and the device weight of terminal device 2 is weight 2, and weight 1 is greater than weight 2, so terminal device 1 will be elected as the central device of network 1. The embodiments of the present application do not impose any restrictions on this.
[0095] The central device of any network can be used to manage the root key (also called the master key) of the session key between any two terminal devices in the network, such as generating, deleting, and updating the root key of the session key between any two terminal devices in the network. For example, when the first network determines that the first terminal device is the central device, the first terminal device can derive the root key of the session key between any two terminal devices in the first network based on the hardware unique key (HUK) of the first terminal device or the device information of the first terminal device, that is, the HUK or device information of the first terminal device can be used as a derivation factor of the root key of the session key between any two terminal devices in the first network. Alternatively, the first terminal device can also randomly generate the root key of the session key between any two terminal devices in the first network, and encrypt the root key of the session key between any two terminal devices in the first network based on the HUK or device information of the first terminal device. The embodiment of the present application does not impose any limitation on the method of generating the root key of the session key between any two terminal devices in the first network. Among them, the device information of the first terminal device may include but is not limited to one or more of the following: a unique device identifier (UDID) of the first terminal device; a network address of the first terminal device, such as a media access control (MAC) address of the first terminal device or an internet protocol (IP) address of the first terminal device.
[0096] The central device of any network can also manage the session key between any two terminal devices in the network, such as generating, deleting, and updating the session key between any two terminal devices in the network. For example, when the first network determines that the first terminal device is the central device, the first terminal device can derive the session key between any two terminal devices in the first network based on the root key of the session key between any two terminal devices in the first network and the device information of any two terminal devices in the first network, that is, the device information of any two terminal devices in the first network can be used as a derivation factor of the session key between any two terminal devices in the first network. Alternatively, the first terminal device can also randomly generate the session key between any two terminal devices in the first network, and encrypt the session key between any two terminal devices in the first network based on the root key of the session key between any two terminal devices in the first network. The first terminal device can store the mapping relationship between any two terminal devices in the first network and the session key between any two terminal devices in the first network. The embodiment of the present application does not impose any limitation on the method of generating the session key between any two terminal devices in the network.
[0097] When a second terminal device wishes to join the first network, the second terminal device may send a first authentication request to the first terminal device. Correspondingly, the first terminal device may receive the first authentication request from the second terminal device. The first authentication request may be used to request joining the first network. The first authentication request may include the public key of the second terminal device and the device information of the second terminal device. The device information of the second terminal device may include, but is not limited to, one or more of the following: the UDID of the second terminal device; the network address of the second terminal device, such as the MAC address of the second terminal device or the IP address of the second terminal device.
[0098] During the specific implementation process, before the second terminal device wants to join the first network, the first terminal device, as the central device of the first network, can perform one or more of the following central device initialization operations: generate and store the root key of the session key between any two terminal devices in the first network. Update the central device identifier corresponding to the first terminal device to yes, which can be understood as the field of the central device identifier corresponding to the first terminal device is true. Send one or more of the following information to the non-central device of the first network: the key distribution mode of the session key between any two terminal devices in the first network, wherein the key distribution mode includes point-to-point distribution or broadcast distribution. For the non-central device of the first network, it is not necessary to actively monitor the central device of the first network in the point-to-point distribution mode, and it is necessary to actively monitor the central device of the first network in the broadcast distribution model; indication information for indicating that the first terminal device is the central device of the first network; device information of the first terminal device.
[0099] Accordingly, the third terminal device, as a non-central device in the first network, can perform one or more of the following non-central device initialization operations: receiving one or more of the following information from the central device in the first network: device information of the first terminal device; indication information indicating that the first terminal device is the central device in the first network; and a key distribution mode for a session key between any two terminal devices in the first network. Updating the central device identifier corresponding to the third terminal device to "no" can be understood as indicating that the central device identifier field corresponding to the third terminal device is false.
[0100] It is understandable that when the central device of the first network is switched from the first terminal device to the third terminal device, the third terminal device, as the new central device of the first network, can re-execute one or more of the above central device initialization operations. Among them, the third terminal device as the new central device of the first network can be re-elected based on the configuration file corresponding to the first network after the first terminal device exits the first network, or can be re-elected based on the device type of each terminal device in the first network after the first terminal device exits the first network, or can be re-elected based on the device weight of each terminal device in the first network after the first terminal device exits the first network. The embodiments of the present application do not limit this.
[0101] For example, Figure 7 As shown, before executing step 601, the present application may further execute the following steps:
[0102] Step A1: The first terminal device generates a root key for a session key between any two terminal devices in the first network.
[0103] Step A2: The first terminal device sends first information to the third terminal device, and the third terminal device receives the first information from the first terminal device. The first information may include, but is not limited to, one or more of the following: device information of the first terminal device; first indication information indicating that the first terminal device is the central device of the first network; or second indication information indicating a key distribution mode, where the key distribution mode includes point-to-point distribution or broadcast distribution.
[0104] Step 602: The first terminal device sends a first authentication response to the second terminal device. Correspondingly, the second terminal device receives the first authentication response from the first terminal device.
[0105] In an embodiment of the present application, after a first terminal device receives a first authentication request from a second terminal device, the first terminal device may send a first authentication response to the second terminal device. Correspondingly, the second terminal device may receive the first authentication response from the first terminal device. The first authentication response may be used to confirm that the second terminal device has joined the first network. The first authentication response may include the public key of the first terminal device and device information of the first terminal device.
[0106] The first terminal device may store the public key of the second terminal device and the device information of the second terminal device included in the first authentication request, and the second terminal device may store the public key of the first terminal device and the device information of the first terminal device included in the first authentication response, so that after the first terminal device and the second terminal device subsequently establish a connection, the first terminal device may generate a second session key based on the public key of the second terminal device and the device information of the second terminal device, and the second terminal device may generate a second session key based on the public key of the first terminal device and the device information of the first terminal device. The second session key is the session key between the first terminal device and the second terminal device. In this way, the first terminal device and the second terminal device can encrypt and decrypt data to be transmitted between the first terminal device and the second terminal device.
[0107] Step 603: The first terminal device generates a first session key.
[0108] In an embodiment of the present application, after the first terminal device sends a first authentication response to the second terminal device, that is, after the second terminal device joins the first network, the first terminal device can generate a first session key. The first session key can be a session key between the second terminal device and the third terminal device. The third terminal device can be a non-central device in the first network other than the second terminal device.
[0109] During the specific implementation process, the first session key can be a session-level key, that is, the session keys between any two terminal devices in the first network are different. The different session keys between any two terminal devices in the first network are applicable to large-scale network scenarios where data can be shared between devices (such as cockpit networking scenarios). At this time, the first terminal device can derive the first session key based on the device information of the second terminal device (that is, the derived factor corresponding to the second terminal device), the device information of the third terminal device (that is, the derived factor corresponding to the third terminal device) and the root key of the session key between any two terminal devices in the first network. The device information of the third terminal device may include but is not limited to one or more of the following: the UDID of the first terminal device; the network address of the first terminal device, such as the MAC address of the first terminal device or the IP address of the first terminal device.
[0110] Alternatively, the first session key can be a network-level key, that is, the session keys between any two terminal devices in the first network are the same, and the session keys between any two terminal devices in the first network are different, which is suitable for small-scale network scenarios (such as home networking scenarios). In this case, the first terminal device can randomly generate the first session key and encrypt the first session key based on the root key of the session key between any two terminal devices in the first network. The first terminal device can store the mapping relationship between the second terminal device and the third terminal device and the first session key.
[0111] Step 604: The first terminal device sends the first session key and the first routing information to the second terminal device and sends the first session key and the second routing information to the third terminal device. Accordingly, the second terminal device receives the first session key and the first routing information from the first terminal device, and the third terminal device receives the first session key and the second routing information from the first terminal device.
[0112] In an embodiment of the present application, after the first terminal device generates the first session key, that is, after the second terminal device joins the first network, the first terminal device can send the first session key and the first routing information to the second terminal device and send the first session key and the second routing information to the third terminal device. Accordingly, the second terminal device receives the first session key and the first routing information from the first terminal device, and the third terminal device receives the first session key and the second routing information from the first terminal device. The first routing information and the second routing information are used for communication between the second terminal device and the third terminal device. Optionally, the first routing information and the second routing information may only include routing information between the second terminal device and the third terminal device, or the first routing information and the second routing information may also include routing information between any two terminal devices in the first network. This embodiment of the present application does not limit this.
[0113] In one possible implementation, the second terminal device and the fourth terminal device are located in the second network, and the second terminal device is the central device of the second network, and the fourth terminal device is the non-central device of the second network. If the fourth terminal device also wants to join the first network after the second terminal device joins the first network, then Figure 8 As shown, the embodiment of the present application may further perform the following steps:
[0114] Step B1: the second terminal device sends the third routing information and the device information of the fourth terminal device to the first terminal device. Correspondingly, the first terminal device can receive the third routing information and the device information of the fourth terminal device from the second terminal device.
[0115] The third routing information is used for communication between the second terminal device and the fourth terminal device. Optionally, the third routing information may only include routing information between the second terminal device and the fourth terminal device, or the third routing information may also include routing information between any two terminal devices in the second network. This embodiment of the present application does not limit this. The device information of the fourth terminal device may include, but is not limited to, one or more of the following: the UDID of the fourth terminal device; the network address of the fourth terminal device, such as the MAC address of the fourth terminal device or the IP address of the fourth terminal device.
[0116] Step B2: The first terminal device generates a third session key.
[0117] The third session key is a session key between the fourth terminal device and the third terminal device.
[0118] During specific implementation, the third session key can be a session-level key, that is, the session keys between any two terminal devices in the first network are different. The different session keys between any two terminal devices in the first network are applicable to large-scale network scenarios where data can be shared between devices (such as cockpit networking scenarios). In this case, the first terminal device can derive the third session key based on the device information of the fourth terminal device (that is, the derivation factor corresponding to the fourth terminal device), the device information of the third terminal device (that is, the derivation factor corresponding to the third terminal device), and the root key of the session key between any two terminal devices in the first network.
[0119] Alternatively, the third session key can be a network-level key, that is, the session keys between any two terminal devices in the first network are the same, and the session keys between any two terminal devices in the first network are different, which is suitable for small-scale network scenarios (such as home networking scenarios). In this case, the first terminal device can randomly generate the third session key and encrypt the third session key based on the root key of the session key between any two terminal devices in the first network. The first terminal device can store the mapping relationship between the fourth terminal device, the third terminal device, and the third session key.
[0120] Step B3: The first terminal device sends the third session key and the fourth routing information to the second terminal device and sends the third session key and the fifth routing information to the third terminal device. Accordingly, the second terminal device receives the third session key and the fourth routing information from the first terminal device, and the third terminal device receives the third session key and the fifth routing information from the first terminal device.
[0121] The fourth routing information and the fifth routing information are used for communication between the fourth terminal device and the third terminal device. Optionally, the fourth routing information and the fifth routing information may only include routing information between the fourth terminal device and the third terminal device, or the fourth routing information and the fifth routing information may also include routing information between any two terminal devices in the first network and routing information between any two terminal devices in the second network. This embodiment of the present application is not limited to this.
[0122] Step B4: the second terminal device sends the third session key and the fourth routing information to the fourth terminal device. Correspondingly, the fourth terminal device receives the third session key and the fourth routing information from the second terminal device.
[0123] For example. Figure 9This is a schematic diagram of another networking scenario provided by the embodiment of the present application. Figure 9 As shown in the figure, network 1 includes device 1, device 2, device 3, device 4 and device 5. Device 1, device 2, device 3, device 4 and device 5 need to authenticate each other to form network 1, that is, devices 1, device 2, device 3, device 4 and device 5 need to authenticate each other. Certification, among which, Device 1 is the central device in network 1, and devices 2, 3, 4, and 5 are non-central devices in network 1. Network 2 includes devices 6, 7, and 8. Devices 6, 7, and 8 need to authenticate each other to form network 2. Certification, among which, Device 6 is the central device in network 2, and devices 7 and 8 are non-central devices in network 2.
[0124] If Network 2 wants to join Network 1, it only needs Device 6 to exchange authentication information with Device 1 in Network 1, that is, Device 6 only needs to perform one authentication. For example, Device 6 and Device 1 can perform the following steps:
[0125] Device 6 sends authentication request 1 to device 1, and device 1 receives authentication request 1 from device 6. Authentication request 1 is used to request to join network 1;
[0126] Device 1 sends authentication response 1 to device 6, and device 6 receives authentication response 1 from device 1. Authentication response 1 is used to confirm that device 6 has joined network 1.
[0127] Device 6 sends information a to device 1, and device 1 receives information a from device 6. Information a includes routing information for communication between device 7 and device 6, device information of device 7, routing information for communication between device 8 and device 6, and device information of device 8.
[0128] Device 1 generates session keys between device 6 and device 2, device 3, device 4, and device 5, respectively; session keys between device 7 and device 2, device 3, device 4, and device 5, respectively; and session keys between device 8 and device 2, device 3, device 4, and device 5, respectively. The session keys between device 6, device 7, or device 8 and device 2, device 3, device 4, and device 5, respectively, may be the same or different.
[0129] Device 1 sends information b to device 2, and device 2 receives information b from device 1. Information b includes session keys between device 2 and devices 6, 7, and 8, and routing information for communication between device 2 and devices 6, 7, and 8, respectively.
[0130] Device 1 sends information c to device 3, and device 3 receives information c from device 1. Information c includes session keys between device 3 and devices 6, 7, and 8, and routing information for communication between device 3 and devices 6, 7, and 8, respectively.
[0131] Device 1 sends information d to device 4, and device 4 receives information d from device 1. Information d includes session keys between device 4 and devices 6, 7, and 8, and routing information for communication between device 4 and devices 6, 7, and 8.
[0132] Device 1 sends information e to device 5, and device 5 receives information e from device 1. Information e includes session keys between device 5 and devices 6, 7, and 8, and routing information for communication between device 5 and devices 6, 7, and 8, respectively.
[0133] Device 1 sends information f to device 6, and device 6 receives information f from device 1. Information f includes session keys between device 6 and devices 2, 3, 4, and 5, and routing information for communication between device 6 and devices 2, 3, 4, and 5, respectively; session keys between device 7 and devices 2, 3, 4, and 5, and routing information for communication between device 7 and devices 2, 3, 4, and 5, respectively; and session keys between device 8 and devices 2, 3, 4, and 5, and routing information for communication between device 8 and devices 2, 3, 4, and 5, respectively.
[0134] Device 6 sends information g to device 7, and device 7 receives information g from device 6. Information g includes session keys between device 7 and devices 2, 3, 4, and 5, and routing information for communication between device 7 and devices 2, 3, 4, and 5, respectively.
[0135] Device 6 sends information h to device 8, and device 8 receives information h from device 6. Information h includes session keys between device 8 and devices 2, 3, 4, and 5, and routing information for communication between device 8 and devices 2, 3, 4, and 5, respectively.
[0136] because Figure 9 In the networking scenario shown, Network 2 only needs to be authenticated once to join Network 1, which reduces networking complexity and enables efficient networking of a large number of devices.
[0137] In one possible implementation, the second terminal device and the fifth terminal device are not located in the same network. It can be understood that the second terminal device and the fifth terminal device are independent terminal devices that have not joined any network; or the second terminal device is located in the second network, and the fifth terminal device is an independent terminal device that has not joined any network; or the second terminal device is an independent terminal device that has not joined any network, and the fifth terminal device is located in the third network; or the second terminal device is located in the second network, and the fifth terminal device is located in the third network. If the fifth terminal device also wants to join the first network after the second terminal device joins the first network, then as follows Figure 10 As shown, the embodiment of the present application may further perform the following steps:
[0138] Step C1: The fifth terminal device sends a second authentication request to the first terminal device. In response, the first terminal device receives the second authentication request from the fifth terminal device. The second authentication request is used to request to join the first network. This step can be referred to as step 601 above and will not be repeated here.
[0139] Step C2: The first terminal device sends a second authentication response to the fifth terminal device. In response, the fifth terminal device receives the second authentication response from the first terminal device. The second authentication response confirms that the fifth terminal device has joined the first network. This step is similar to step 602 above and will not be repeated here.
[0140] Step C3: The first terminal device generates a fourth session key.
[0141] The fourth session key is a session key between the fifth terminal device and the third terminal device.
[0142] During specific implementation, the fourth session key can be a session-level key, that is, the session keys between any two terminal devices in the first network are different. The different session keys between any two terminal devices in the first network are applicable to large-scale network scenarios where data can be shared between devices (such as cockpit networking scenarios). In this case, the first terminal device can derive the fourth session key based on the device information of the fifth terminal device (that is, the derivation factor corresponding to the fifth terminal device), the device information of the third terminal device (that is, the derivation factor corresponding to the third terminal device), and the root key of the session key between any two terminal devices in the first network.
[0143] Alternatively, the fourth session key may be a network-level key, that is, the session keys between any two terminal devices in the first network are the same, and the session keys between any two terminal devices in the first network are different, which is suitable for small-scale network scenarios (such as home networking scenarios). In this case, the first terminal device can randomly generate the fourth session key and encrypt the fourth session key based on the root key of the session key between any two terminal devices in the first network. The first terminal device can store the mapping relationship between the fifth terminal device, the third terminal device, and the fourth session key.
[0144] Step C4: The first terminal device sends the fourth session key and the sixth routing information to the fifth terminal device and sends the fourth session key and the seventh routing information to the third terminal device. Accordingly, the fifth terminal device receives the fourth session key and the sixth routing information from the first terminal device, and the third terminal device receives the fourth session key and the seventh routing information from the first terminal device.
[0145] The sixth routing information and the seventh routing information are used for communication between the fifth terminal device and the third terminal device. Optionally, the sixth routing information and the seventh routing information may include only routing information between the fifth terminal device and the third terminal device, or may include routing information between any two terminal devices in the first network, which is not limited in this embodiment of the present application.
[0146] For example, Figure 11 This is a schematic diagram of another networking scenario provided by an embodiment of the present application. Figure 11 As shown in the figure, network 1 includes device 1, device 2, device 3, device 4 and device 5. Device 1, device 2, device 3, device 4 and device 5 need to authenticate each other to form network 1, that is, devices 1, device 2, device 3, device 4 and device 5 need to authenticate each other. Certification, among which, = 10. Device 1 is the central device in network 1, and devices 2, 3, 4, and 5 are non-central devices in network 1.
[0147] If device 6 and device 7 want to join network 1, they only need to exchange authentication information with device 1 in network 1, that is, only device 6 needs to perform one authentication and device 7 needs to perform one authentication. For example, devices 6 and 7 can perform the following steps with device 1:
[0148] Device 6 sends authentication request 1 to device 1, and device 1 receives authentication request 1 from device 6. Authentication request 1 is used to request to join network 1. Device 7 sends authentication request 2 to device 1, and device 1 receives authentication request 2 from device 7. Authentication request 2 is used to request to join network 1.
[0149] Device 1 sends authentication response 1 to device 6, and device 6 receives authentication response 1 from device 1. Authentication response 1 confirms that device 6 has joined network 1. Furthermore, device 1 sends authentication response 2 to device 7, and device 7 receives authentication response 2 from device 1. Authentication response 1 confirms that device 7 has joined network 1.
[0150] Device 1 generates session keys between device 6 and device 2, device 3, device 4, and device 5, and between device 7 and device 2, device 3, device 4, and device 5, respectively. The session keys between device 6 or device 7 and device 2, device 3, device 4, and device 5, respectively, can be the same or different.
[0151] Device 1 sends information a to device 2. In response, device 2 receives information a from device 1, where information a includes session keys between device 2 and devices 6 and 7, and routing information for communication between device 2 and devices 6 and 7.
[0152] Device 1 sends information b to device 3. In response, device 3 receives information b from device 1, where information b includes session keys between device 3 and devices 6 and 7, and routing information for communication between device 3 and devices 6 and 7.
[0153] Device 1 sends information c to device 4. In response, device 4 receives information c from device 1, where information c includes session keys between device 4 and devices 6 and 7, and routing information for communication between device 4 and devices 6 and 7.
[0154] Device 1 sends information d to device 5. In response, device 5 receives information d from device 1, where information d includes session keys between device 5 and devices 6 and 7, and routing information for communication between device 5 and devices 6 and 7.
[0155] Device 1 sends information e to device 6. In response, device 6 receives information e from device 1. Information e includes session keys between device 6 and devices 2, 3, 4, and 5, and routing information for communication between device 6 and devices 2, 3, 4, and 5, respectively.
[0156] Device 1 sends information f to device 7. In response, device 7 receives information f from device 1. Information f includes session keys between device 7 and devices 2, 3, 4, and 5, and routing information for communication between device 7 and devices 2, 3, 4, and 5, respectively.
[0157] because Figure 11 In the networking scenario shown, device 6 only needs to be authenticated once to join network 1, and device 7 only needs to be authenticated once to join network 1, which reduces the complexity of networking and can support efficient networking of a large number of devices.
[0158] Based on the above embodiments and the same concept, an embodiment of the present application also provides a terminal device, which is used to implement the network access method provided in the embodiment of the present application.
[0159] like Figure 12 As shown, terminal device 1200 may include: a memory 1201, one or more processors 1202, and one or more computer programs (not shown). The aforementioned components may be coupled via one or more communication buses 1203. Optionally, when terminal device 1200 is used to implement the network access method provided in the embodiments of the present application, terminal device 1200 may further include a display screen 1204.
[0160] Memory 1201 stores one or more computer programs (codes), each of which includes computer instructions. Processors 1202 invoke the computer instructions stored in memory 1201, causing terminal device 1200 to execute the network access method provided in the embodiments of the present application. Display screen 1204 is used to display images, videos, application interfaces, and other related user interfaces.
[0161] In a specific implementation, the memory 1201 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more disk storage devices, flash memory devices or other non-volatile solid-state storage devices. The memory 1201 can store an operating system (hereinafter referred to as system), such as ANDROID, IOS, WINDOWS, or embedded operating systems such as LINUX. The memory 1201 can be used to store the implementation program of the embodiment of the present application. The memory 1201 can also store a network communication program, which can be used to communicate with one or more additional devices, one or more user devices, or one or more terminal devices. The one or more processors 1202 can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.
[0162] It should be noted that Figure 12This is only one implementation of the terminal device 1200 provided in the embodiment of the present application. In actual applications, the terminal device 1200 may also include more or fewer components, which is not limited here.
[0163] Based on the above embodiments and the same concept, an embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program runs on a computer, the computer executes the network access method provided in the above embodiments.
[0164] Based on the above embodiments and the same concept, an embodiment of the present application further provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are run on a computer, the computer executes the network access method provided in the above embodiments.
[0165] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0166] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0167] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0168] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0169] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.
Claims
1. A network access method, characterized in that: Applied to a first terminal device, where the first terminal device is a central device of a first network, the method includes: receiving a first authentication request from a second terminal device, where the first authentication request is used to request joining the first network; Sending a first authentication response to the second terminal device, where the first authentication response is used to confirm that the second terminal device has joined the first network; Generate a first session key, where the first session key is a session key between the second terminal device and a third terminal device, where the third terminal device is a non-central device in the first network other than the second terminal device; The first session key and first routing information are sent to the second terminal device, and the first session key and second routing information are sent to a third terminal device, where the first routing information and the second routing information are used for communication between the second terminal device and the third terminal device.
2. The method according to claim 1, wherein Before receiving the first authentication request from the second terminal device, the method further includes: Sending first information to the third terminal device, where the first information includes one or more of the following: device information of the first terminal device; The first indication information is used to indicate that the first terminal device is a central device; or The second indication information is used to indicate a key distribution mode, where the key distribution mode includes point-to-point distribution or broadcast distribution.
3. The method according to claim 1 or 2, wherein: The first authentication request includes the public key of the second terminal device and the device information of the second terminal device, the first authentication response includes the public key of the first terminal device and the device information of the first terminal device, the public key of the second terminal device and the device information of the second terminal device are used to generate a second session key, the public key of the first terminal device and the device information of the first terminal device are used to generate the second session key, and the second session key is the session key between the first terminal device and the second terminal device.
4. The method according to any one of claims 1 to 3, characterized in that: The second terminal device is a central device of the second network, and the fourth terminal device is a non-central device of the second network; the method further includes: receiving third routing information from the second terminal device and device information of the fourth terminal device, wherein the third routing information is used for communication between the second terminal device and the fourth terminal device; generating a third session key, where the third session key is a session key between the fourth terminal device and the third terminal device; The third session key and fourth routing information are sent to the second terminal device, and the third session key and fifth routing information are sent to the third terminal device, where the fourth routing information and the fifth routing information are used for the fourth terminal device to communicate with the third terminal device.
5. The method according to any one of claims 1 to 4, characterized in that: The second terminal device and the fifth terminal device are not located in the same network, and the method further includes: receiving a second authentication request from the fifth terminal device, where the second authentication request is used to request to join the first network; Sending a second authentication response to the fifth terminal device, where the second authentication response is used to confirm that the fifth terminal device has joined the first network; generating a fourth session key, where the fourth session key is a session key between the fifth terminal device and the third terminal device; The fourth session key and the sixth routing information are sent to the fifth terminal device, and the fourth session key and the seventh routing information are sent to the third terminal device, where the sixth routing information and the seventh routing information are used for the fifth terminal device to communicate with the third terminal device.
6. The method according to any one of claims 1 to 5, characterized in that: Generating the first session key includes: Generating a root key for a session key between terminal devices in the first network; Based on the root key, the first session key is generated.
7. The method according to claim 6, wherein Generating the first session key based on the root key includes: deriving the first session key based on the device information of the second terminal device, the device information of the third terminal device, and the root key; or The first session key is randomly generated and encrypted based on the root key.
8. The method according to claim 7, wherein The first session key is a session-level key, and the session-level key is used to indicate that the session keys between the terminal devices in the first network are different; or, The first session key is a network-level key, and the network-level key is used to indicate that the session keys between terminal devices in the first network are the same.
9. A terminal device, characterized in that: The terminal device includes: a processor, a memory, and one or more programs; The one or more programs are stored in the memory, and the one or more programs include instructions. When the instructions are executed by the processor, the terminal device executes the method according to any one of claims 1 to 8.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium is used to store a computer program, and when the computer program is run on a computer, the computer is caused to perform the method according to any one of claims 1 to 8.
11. A computer program product, characterized in that The invention comprises a computer program, which, when being run on a computer, causes the computer to execute the method according to any one of claims 1 to 8.