Terminal access method and system based on star flash protocol

Passive discovery mechanism and encryption authentication of sending unique identifiers by terminals solve the security risks and manual connection problems caused by active broadcast of star flash devices, and realizes an automated and secure terminal access process.

CN120456028AActive Publication Date: 2025-08-08NEW SINGULARITY INT TECHN DEV

Patent Information

Application Number
CN202510953544.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-11
Publication Date
2025-08-08
Estimated Expiration
2045-07-11

AI Technical Summary

Technical Problem

When existing equipment based on star flash technology is actively broadcasting, there are security risks caused by information exposure, and the terminal connection process requires user manual selection, affecting user experience and security.

Method used

The passive discovery mechanism is adopted, and the terminal sends broadcast information carrying a unique identifier. The star flash device determines permissions based on the identifier and responds, realizes automatic access, and ensures security through encryption keys and dual-factor authentication.

Benefits of technology

It effectively avoids interference from illegal terminals, improves the security and stability of the connection between the satellite flash device and the terminal, simplifies the connection process, and improves user experience and access efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120456028A_ABST
    Figure CN120456028A_ABST
Patent Text Reader

Abstract

The invention provides a terminal access method and system based on a satellite flash protocol, relates to the technical field of wireless private network communication, and can avoid potential safety hazards caused by exposure of own information due to active broadcast of satellite flash equipment and improve the connection security of the satellite flash equipment and a terminal. The method is applied to a first terminal and comprises the steps that first information based on a satellite flash protocol is sent in a broadcast mode, and the first information comprises a unique identifier of the first terminal and is used for discovering peripheral satellite flash equipment; second information based on the satellite flash protocol from the satellite flash device is obtained through scanning, the second information comprises a unique identifier of the satellite flash device, and the second information is sent after the satellite flash device determines that the first terminal has the access permission based on the unique identifier of the first terminal; analyzing the second information to obtain a unique identifier of the satellite flash device; and sending an access request to the star flash device according to the unique identifier of the star flash device, wherein the access request is used for triggering establishment of star flash service interaction protocol connection with the star flash device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of wireless private network communication technology, and in particular to a terminal access method and system based on the Star Flash protocol. Background Art

[0002] Near Link is a new wireless short-range communication standard technology released by the International Near Link Wireless Short-Range Communication Alliance. Compared with Wi-Fi and Bluetooth, it has the advantages of lower power consumption, faster speed, lower latency, more stable connection, wider coverage, and larger networking. It will bring experience changes to scenarios such as smart terminals, smart homes, smart cars, and smart manufacturing.

[0003] Currently, Starflash devices based on Starflash technology use an active broadcast discovery mechanism, that is, Starflash devices continuously send broadcast messages to the surrounding environment. Terminals obtain broadcast messages by scanning and display the scanned Starflash devices in the list of connectable devices. Users manually select the target Starflash device from the list of connectable devices and trigger the connection. Although this solution realizes device discovery and connection, the active broadcast of Starflash devices exposes their own information, and all terminals can receive the broadcast messages of Starflash devices. In this case, a large number of unknown and untrusted terminals can easily detect the existence of Starflash devices. Malicious terminals may exploit this vulnerability to carry out malicious attacks or data theft, etc., which brings potential security risks to Starflash devices and may also affect other terminals connected to Starflash devices.

[0004] Therefore, there is an urgent need for a new terminal access method based on the Star Flash protocol, which can improve the security of the connection between Star Flash devices and terminals to meet the security requirements of wireless private network communications. Summary of the Invention

[0005] The present application provides a terminal access method and system based on the Star Flash protocol, which can avoid the security risks caused by the active broadcast of the Star Flash device that exposes its own information, and improve the security of the connection between the Star Flash device and the terminal.

[0006] In a first aspect, a terminal access method based on the Star Flash protocol is provided, which is applied to a first terminal and includes: Sending first information based on the StarFlash protocol in a broadcast manner, where the first information includes a unique identifier of the first terminal, and the first information is used to discover surrounding StarFlash devices; Acquire, by scanning, second information based on the Star Flash protocol from the Star Flash device, the second information including a unique identifier of the Star Flash device, and sent by the Star Flash device after determining that the first terminal has access permission based on the unique identifier of the first terminal; Parsing the second information to obtain a unique identifier of the Star Flash device; According to the unique identifier of the Star Flash device, an access request is sent to the Star Flash device, and the access request is used to trigger the establishment of a Star Flash service interaction protocol connection with the Star Flash device.

[0007] In one feasible design, the second information includes a password index uniquely corresponding to the first terminal. After the first terminal establishes a Starflash service interaction protocol connection with the Starflash device, the method includes: After receiving the authentication request from the Star Flash device, an authentication response is determined. The authentication response includes the unique identifier of the first terminal and preset content encrypted using an encryption key. The encryption key is determined by the first terminal based on the password index. The encrypted preset content is used by the Star Flash device to decrypt to determine whether the identity authentication of the first terminal is passed; Send an authentication response to the Starflash device.

[0008] In a feasible design, parsing the second information includes: If the second information includes a private protocol header and invisible characters corresponding to the name of the Star Flash device, the second information is parsed according to the private protocol; wherein, the invisible characters are used to prevent the name of the Star Flash device from being rendered as readable text in the list of connectable devices of the first terminal.

[0009] In a feasible design, before sending the first information based on the Star Flash protocol in a broadcast manner, the method includes: Send a registration request to the authentication server, where the registration request includes a unique identifier of the first terminal and is used to obtain permission to access the Starflash device; Receive a registration response from the authentication server, the registration response including an association table and an encryption method identifier, the association table including a mapping relationship between a password index and an encryption key, and the encryption method identifier indicating the type of encryption algorithm used for identity authentication.

[0010] In a second aspect, a terminal access method based on the Star Flash protocol is provided, which is applied to a Star Flash device, including: receiving first information based on the StarFlash protocol sent by a first terminal in a broadcast manner, where the first information includes a unique identifier of the first terminal and is used to enable the first terminal to discover surrounding StarFlash devices; determining whether the first terminal has access authority based on a unique identifier of the first terminal; If the first terminal does not have access authority, keep the communication silent; If the first terminal has access permission, send second information based on the Star Flash protocol to the first terminal, where the second information includes a unique identifier of the Star Flash device; After receiving the access request from the first terminal, a Starflash service interaction protocol connection is established with the first terminal. The access request is information sent by the first terminal after obtaining the second information, which is used to trigger the first terminal to establish a Starflash service interaction protocol connection with the Starflash device.

[0011] In a feasible design, after the Star Flash device establishes a Star Flash service interaction protocol connection with the first terminal, the method includes: Sending an authentication request to the first terminal, where the authentication request is used to trigger the first terminal to perform identity authentication; receiving an authentication response from the first terminal, the authentication response including a unique identifier of the first terminal and encrypted preset content, where the encrypted preset content is encrypted by an encryption key determined by the first terminal according to the password index; determining a cryptographic index based on the unique identifier of the first terminal in the authentication response, and determining an encryption key based on the cryptographic index; If the encrypted preset content is successfully decrypted using the encryption key, it is determined that the first terminal has passed the identity authentication; If the encrypted preset content fails to be decrypted using the encryption key, it is determined that the first terminal has not passed the identity authentication and the Star Flash service interaction protocol connection with the first terminal is disconnected.

[0012] In one feasible design, if the first terminal has access authority, the method includes: Converting the name of the Starflash device into invisible characters, wherein the invisible characters are used to prevent the name of the Starflash device from being rendered as readable text in the connectable device list of the first terminal; According to the private protocol, the private protocol header and the invisible characters corresponding to the name of the Star Flash device are encapsulated into the second information.

[0013] In one feasible design, determining whether the first terminal has access permission based on the unique identifier of the first terminal includes: According to the unique identifier of the first terminal, query the locally stored permission table, the permission table is used to record the unique identifier of each terminal with access permission; If the permission table contains the unique identifier of the first terminal, determining that the first terminal has access permission, and generating second information according to the password index corresponding to the unique identifier of the first terminal in the permission table; If the permission table does not include the unique identifier of the first terminal, it is determined whether the first terminal has the access permission by interacting with the authentication server.

[0014] In a third aspect, a terminal access system based on the Star Flash protocol is provided, comprising a first terminal and a Star Flash device; The first terminal is configured to send first information based on the StarFlash protocol in a broadcast manner, where the first information includes a unique identifier of the first terminal, and the first information is configured to enable the first terminal to discover surrounding StarFlash devices; The Star Flash device is configured to determine, after receiving the first information, whether the first terminal has access authority based on the unique identifier of the first terminal; If the first terminal does not have access permission, the Star Flash device remains in silent communication mode; If the first terminal has access authority, the Starflash device is used to send second information based on the Starflash protocol to the first terminal, where the second information includes a unique identifier of the Starflash device; The first terminal is configured to obtain the second information by scanning and then parse the second information to obtain a unique identifier of the Star Flash device; The first terminal is used to send an access request to the Star Flash device according to the unique identifier of the Star Flash device, where the access request is used to trigger the establishment of a Star Flash service interaction protocol connection with the Star Flash device; The Starflash device is used to establish a Starflash service interaction protocol connection with the first terminal after receiving the access request.

[0015] In one possible design, an authentication server is included; The Xingshan device is further configured to send a permission query request to the authentication server if the locally stored permission table does not include the unique identifier of the first terminal, the permission table being used to record the unique identifier of each terminal with access permission, the permission query request including the unique identifier of the first terminal, and the permission query request being used to determine whether the first terminal has access permission; The authentication server is used to query the registration and activation table based on the unique identifier of the first terminal in the permission query request after receiving the permission query request from the Star Flash device. The registration and activation table is used to record the unique identifier of each registered and activated terminal; If the registration activation table includes the unique identifier of the first terminal, the authentication server sends an authority query response to the Star Flash device, where the authority query response includes first indication information, where the first indication information is used to indicate that the first terminal has access authority; If the registration activation table does not include the unique identifier of the first terminal, the authentication server sends an authority query response to the Star Flash device, where the authority query response includes second indication information, and the second indication information is used to indicate that the first terminal does not have access authority.

[0016] In the terminal access method based on the Star Flash protocol provided in the present application, the Star Flash device no longer actively initiates a broadcast based on the Star Flash protocol (referred to as Star Flash broadcast). Instead, the first terminal actively initiates a Star Flash broadcast carrying its own unique identifier when it needs to connect to the Star Flash device to trigger the process of automatically accessing the Star Flash device, thereby realizing a passive discovery mechanism of the Star Flash device based on demand. This passive discovery mechanism reduces the risk of active exposure of the Star Flash device, so that the Star Flash device responds and returns the second information only after receiving the Star Flash broadcast from a terminal with access authority, effectively avoiding interference from illegal terminals that do not have access authority, blocking the perception of the Star Flash device by unauthorized terminals, and improving the security and stability of the connection between the Star Flash device and the first terminal. The first terminal sends an access request to the Star Flash device based on the unique identifier of the Star Flash device in the second information, thereby realizing automatic access of the first terminal with access authority, and completing the pairing connection with the Star Flash device without the user manually selecting the device, thereby improving the efficiency, convenience and user experience of accessing the Star Flash device. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solution of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0018] Figure 1 This is a schematic flow chart of a terminal access method based on the Star Flash protocol provided by an exemplary embodiment of the present application; Figure 2 This is a schematic flowchart of another terminal access method based on the Star Flash protocol provided by an exemplary embodiment of the present application; Figure 3 This is a schematic diagram of a terminal access system based on the Star Flash protocol provided by an exemplary embodiment of the present application. DETAILED DESCRIPTION

[0019] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0020] In the current Starflash protocol-based terminal access solution, Starflash devices use an active broadcasting method. When a terminal requests access to a Starflash device, it initiates a scan to search for nearby available Starflash devices. After obtaining a list of connectable devices, the user manually selects the desired Starflash device to access.

[0021] However, this existing terminal access solution has some significant issues. First, Starflash devices actively broadcast, exposing their information and allowing all terminals to receive their broadcast signals. This makes it easy for a large number of unknown and untrusted terminals to detect the presence of Starflash devices and potentially exploit these vulnerabilities to launch malicious attacks or steal data, posing a potential security risk to Starflash devices and potentially affecting other terminals connected to them.

[0022] Secondly, in the current terminal access process, the terminal must manually select the target Star Flash device in the list of connectable devices before it can connect to the target Star Flash device. This increases the user's operating burden and lacks automation and convenience. Especially in some scenarios where Star Flash devices need to be connected quickly and efficiently, this manual connection method will seriously affect the user experience and work efficiency, and cannot meet the user's expectations for fast, secure and automatic connection to devices.

[0023] In order to solve the above problems, Figure 1 As shown, the present application provides a terminal access method based on the Star Flash protocol, which is applied to a first terminal, including: S110: Send first information based on the Star Flash protocol in a broadcast manner.

[0024] The first information includes a unique identifier of the first terminal, and the first information is used to discover surrounding Starflash devices.

[0025] Specifically, the first terminal generates first information including a unique identifier of the first terminal according to the Star Flash protocol, and then periodically sends the first information to the surrounding environment in a broadcast manner.

[0026] It should be noted that this application does not limit the system type used by the first terminal, such as Hongmeng system, Android system, Apple system, etc.

[0027] It should be noted that the unique identifier of each device in this application is used to uniquely identify the device and ensure the uniqueness of the device's identity. The unique identifier is used to implement functions such as device addressing and discovery. In this application, unless otherwise specified, any information sent by the first terminal, Star Flash device, and authentication server contains its own unique identifier by default.

[0028] In a feasible design, before sending the first information based on the Star Flash protocol in a broadcast manner, the method includes: Send a registration request to the authentication server, where the registration request includes a unique identifier of the first terminal and is used to obtain permission to access the Starflash device; Receive a registration response from the authentication server, the registration response including an association table and an encryption method identifier, the association table including a mapping relationship between a password index and an encryption key, and the encryption method identifier indicating the type of encryption algorithm used for identity authentication.

[0029] Exemplarily, the encryption algorithm type may be national encryption SM4.

[0030] Specifically, the first terminal can obtain registration information entered by the user through the application program interface, encapsulate the registration information and the first terminal's unique identifier, generate a registration request, and send it to the authentication server. After verifying the registration information, the authentication server generates a registration response and returns it to the first terminal. The registration response includes the mapping between each password index and each encryption key, as well as an encryption method identifier.

[0031] In the above example, the first terminal obtains the right to access the Star Flash device by registering and activating on the authentication server, ensuring that only terminals with access rights (i.e., authorized terminals) can access the Star Flash device through automatic connection, effectively preventing malicious attacks from terminals without access rights (i.e., unauthorized terminals). On the other hand, the authentication server provides the first terminal with an association table and an encryption method identifier during the registration and activation phase, so that the terminal has the ability to complete identity authentication in subsequent processes. This design controls the terminal's permissions at the source (unregistered and activated terminals cannot access the Star Flash device) and strengthens the encryption algorithm, completely blocking the possibility of unauthorized terminals accessing the Star Flash device. Compared to the transmission key, the present application provides the first terminal with an association table and an encryption method identifier so that the first terminal can subsequently determine the encryption key based on the password index, thereby avoiding the illegal use of the encryption key after it is leaked. This fundamentally ensures that the Star Flash device only responds to the connection request of the authorized terminal, thereby improving the security and reliability of the automatic connection between the Star Flash device and the terminal.

[0032] S120: Acquire second information based on the Starflash protocol from the Starflash device through scanning.

[0033] The second information includes the unique identifier of the Star Flash device, and the second information is sent by the Star Flash device after determining that the first terminal has access authority based on the unique identifier of the first terminal.

[0034] Exemplarily, the second information includes a password index uniquely corresponding to the first terminal, which is used for subsequent identity authentication after the first terminal establishes a connection with the Starflash device.

[0035] In this example, the password index uniquely corresponds to the terminal. The terminal and the Star Flash device determine the encryption key by querying the association table based on the password index. They then encrypt the plaintext using the encryption key and the adopted encryption algorithm, such as the SM4 algorithm. Therefore, different terminals calculate different encryption keys based on their respective password indexes. This approach improves the security of the encryption key and reduces the risk of key leakage.

[0036] Exemplarily, the second information includes a private protocol header and invisible characters corresponding to the name of the Star Flash device, wherein the invisible characters are used to prevent the name of the Star Flash device from being rendered as readable text in the connectable device list of the first terminal.

[0037] The private protocol header is used to declare the name of the Starflash device to be hidden. This means that upper-layer applications on the terminal (such as the connectable device list) cannot obtain the correct characters of the Starflash device name.

[0038] At present, the device name is composed of visible characters in the ASCII table, and the list of connectable devices of the first terminal can correctly render the visible characters into readable text, but this method easily leaks the name information of the Star Flash device. The present application converts the visible characters of the device name, that is, subtracts a preset value from each visible character to convert the visible characters of the device name into invisible characters, and the list of connectable devices of the first terminal cannot render the invisible characters into readable text. After such processing, the name of the Star Flash device finally displayed is garbled, such as "XXXX", or the name of the Star Flash device is not displayed in the list of connectable devices, that is, the area originally used to display the name of the Star Flash device is blank. The preset value can be any integer greater than or equal to 30, ensuring that the converted characters are control characters that cannot be rendered as visual graphic symbols.

[0039] Exemplarily, the second information includes a Basic Service Set Identifier (BSSID) of the Star Flash device.

[0040] Unlike unique identifiers, which are used to identify devices, BSSIDs are used to identify infrastructure nodes.

[0041] Currently, the BSSID obtained by the upper-layer application of the terminal is usually obtained by the underlying application through virtual conversion of the actual BSSID. Considering the upper-layer application's demand for the actual BSSID, this application also designs a solution in which the second information includes the actual BSSID.

[0042] The above-mentioned second information can be regarded as an extended Star Flash message. In addition to complying with the Star Flash protocol, the information encapsulation format of the extended part of the Star Flash message complies with a private protocol.

[0043] S130: parse the second information to obtain a unique identifier of the Star Flash device.

[0044] In a feasible design, the second information is parsed in the following manner: If the second information includes a private protocol header and invisible characters corresponding to the name of the Star Flash device, the second information is parsed according to the private protocol; wherein, the invisible characters are used to prevent the name of the Star Flash device from being rendered as readable text in the list of connectable devices of the first terminal.

[0045] The private protocol is also used to specify the encapsulation format of the invisible characters corresponding to the private protocol header and the name of the Star Flash device, and the content of the private protocol header. Therefore, the first terminal needs to parse the second information according to the Star Flash protocol and the private protocol.

[0046] In this example, after the first terminal scans the name information of the Starflash device with a private protocol header, it parses the second information according to the private protocol to obtain the content of the second information. This prevents terminals that do not support the private protocol from accessing the Starflash device due to their inability to recognize the second information, ensuring the security and privacy of the Starflash device name information and the source of the terminals accessing the Starflash device. In addition, although the first terminal can parse the second information, the first terminal's connectable device list (and other upper-layer applications) still cannot recognize the name of the Starflash device and cannot display the name of the Starflash device. This can prevent illegal access due to the leakage of the Starflash device name and enhance the security of the first terminal's access to the Starflash device.

[0047] S140: Send an access request to the Starflash device according to the unique identifier of the Starflash device.

[0048] The access request is used to trigger the establishment of a SparkLink Service Access Protocol (SSAP) connection with the SparkLink device, and the access request includes at least a unique identifier of the first terminal.

[0049] Specifically, the underlying application of the first terminal generates an access request including the first terminal's unique identifier, and then sends the access request to the Starflash device based on the Starflash device's unique identifier. After receiving the access request, the underlying application of the Starflash device negotiates with the underlying application of the first terminal through the protocol stack. The completion of the negotiation indicates that a Starflash service interaction protocol connection has been established between the Starflash device and the first terminal.

[0050] In a feasible design, when the second information includes a password index uniquely corresponding to the first terminal, after the first terminal establishes a Starflash service interaction protocol connection with the Starflash device, the method includes: After receiving an authentication request from the Star Flash device, an authentication response is determined. The authentication request is used to trigger the first terminal to perform identity authentication. The authentication response includes a unique identifier of the first terminal and preset content encrypted using an encryption key. The encryption key is determined by the first terminal based on the password index. The encrypted preset content is used by the Star Flash device to decrypt to determine whether the identity authentication of the first terminal is successful. Send an authentication response to the Starflash device.

[0051] The preset content may be set according to actual needs, for example, it may be the BSSID of the Star Flash device and / or the Media Access Control (MAC) address of the first terminal.

[0052] The authentication request at least includes the unique identifier of the Starflash device.

[0053] It should be noted that after the negotiation of the underlying application of the Star Flash device is completed, a notification will be sent to the upper-layer application responsible for terminal access through the interface, indicating that the connection with the first terminal is successfully established. After receiving the notification, the upper-layer application of the Star Flash device sends an authentication request to the first terminal to trigger the identity authentication process. The underlying application is an application that interacts with hardware resources in the system and provides a service interface for the upper-layer application. The upper-layer application relies on the service interface provided by the underlying application to implement user-oriented services for users to use.

[0054] In the above example, after the first terminal establishes a Starlight service interaction protocol connection with the Starlight device, the Starlight device will actively send an authentication request to trigger the first terminal to authenticate its identity. After receiving the authentication request, the first terminal uses the encryption key corresponding to the password index to encrypt the preset content, and generates an authentication response in combination with the plaintext of the unique identifier, so that the Starlight device can determine the password index corresponding to the first terminal through the plaintext of the unique identifier, and decrypt the ciphertext of the preset content according to the password index, thereby verifying the legitimacy of the terminal identity. If the decryption is successful, the Starlight device will maintain the connection with the first terminal and allow the first terminal to transmit data with the Starlight device; if the decryption fails, the Starlight device will disconnect from the first terminal. Based on the permission authentication of the first terminal, the above scheme further authenticates the identity of the first terminal after the connection is successful, thereby realizing dual authentication, which can fundamentally prevent illegal access by unauthorized terminals and ensure the credibility of the identity of the access terminal.

[0055] In the terminal access method based on the Star Flash protocol provided in the present application, the Star Flash device no longer actively initiates a broadcast based on the Star Flash protocol (referred to as Star Flash broadcast). Instead, the first terminal actively initiates a Star Flash broadcast carrying its own unique identifier when it needs to connect to the Star Flash device to trigger the process of automatically accessing the Star Flash device, thereby realizing a passive discovery mechanism of the Star Flash device based on demand. This passive discovery mechanism reduces the risk of active exposure of the Star Flash device, so that the Star Flash device responds and returns the second information only after receiving the Star Flash broadcast from a terminal with access authority, effectively avoiding interference from illegal terminals that do not have access authority, blocking the perception of the Star Flash device by unauthorized terminals, and improving the security and stability of the connection between the Star Flash device and the first terminal. The first terminal sends an access request to the Star Flash device based on the unique identifier of the Star Flash device in the second information, thereby realizing automatic access of the first terminal with access authority, and completing the pairing connection with the Star Flash device without the user manually selecting the device, thereby improving the efficiency, convenience and user experience of accessing the Star Flash device.

[0056] Based on the above embodiments, the present application also provides a terminal access method based on the Star Flash protocol, which is applied to a Star Flash device, including: S210: Receive first information based on the StarFlash protocol sent by a first terminal in a broadcast manner.

[0057] The first information includes a unique identifier of the first terminal, and the first information is used to enable the first terminal to discover surrounding Starflash devices.

[0058] S220: Determine whether the first terminal has access authority based on the unique identifier of the first terminal.

[0059] In a feasible design, determining whether the first terminal has access authority based on the unique identifier of the first terminal is implemented in the following manner: According to the unique identifier of the first terminal, query the locally stored permission table, the permission table is used to record the unique identifier of each terminal with access permission; If the permission table contains the unique identifier of the first terminal, determining that the first terminal has access permission, and generating second information according to the password index corresponding to the unique identifier of the first terminal in the permission table; If the permission table does not include the unique identifier of the first terminal, it is determined whether the first terminal has the access permission by interacting with the authentication server.

[0060] Exemplarily, the permission table may also record other information of the terminal according to actual needs, such as a password index corresponding to the terminal.

[0061] Exemplarily, the manner in which the Star Flash device determines whether the first terminal has access authority by interacting with the authentication server includes: Sending an authorization query request to the authentication server, where the authorization query request includes a unique identifier of the first terminal, and the authorization query request is used to determine whether the first terminal has access authority; Receive permission query response from the authentication server; If the permission query response includes first indication information indicating that the first terminal has access permission, the first terminal is determined to have access permission, and the permission table is updated based on the content included in the permission query response. For example, if the permission query response also includes the password index of the first terminal, the Starflash device adds this information and the unique identifier of the first terminal to the permission table to ensure the efficiency and security of subsequent access by the first terminal.

[0062] If the authority query response includes second indication information for indicating that the first terminal does not have access authority, it is determined that the first terminal does not have access authority.

[0063] In the above example, the Star Flash device first quickly matches the unique identifier of the first terminal in the locally stored permission table. If the permission table contains the corresponding information of the first terminal, the Star Flash device can quickly respond to the first terminal with access permission, thereby reducing the access delay of the first terminal. If the permission table does not contain the corresponding information of the first terminal, it will continue to initiate a permission query request to the authentication server, and dynamically update the permission table using the permission query response returned by the authentication server. This not only avoids the lag of the local permission table that causes legitimate terminals to be mistakenly rejected, but also ensures the real-time and accuracy of the permission table through the permission query response returned by the server.

[0064] S230: If the first terminal does not have access authority, maintain a silent communication state.

[0065] S240: If the first terminal has access authority, send second information based on the Starflash protocol to the first terminal, where the second information includes a unique identifier of the Starflash device.

[0066] S250: After receiving an access request from the first terminal, establish a Starflash service interaction protocol connection with the first terminal.

[0067] Among them, the access request is information sent by the first terminal after obtaining the second information, which is used to trigger the first terminal to establish a Star Flash service interaction protocol connection with the Star Flash device.

[0068] The Star Flash device may send the second information to the first terminal in a unicast manner or a broadcast manner.

[0069] The content of the second information is described in S110-S140 and will not be repeated here.

[0070] Exemplarily, when the permission table contains a password index uniquely corresponding to the first terminal, the Star Flash device also encapsulates the password index into the second information according to a private protocol, so that the first terminal can determine the encryption key based on the password index and perform subsequent identity authentication.

[0071] Exemplarily, the Starflash device further encapsulates the basic service set identifier of the Starflash device into the second information according to a private protocol.

[0072] In one feasible design, if the first terminal has access authority, the method includes: Converting the name of the Starflash device into invisible characters, wherein the invisible characters are used to prevent the name of the Starflash device from being rendered as readable text in the connectable device list of the first terminal; According to the private protocol, the private protocol header and the invisible characters corresponding to the name of the Star Flash device are encapsulated into the second information.

[0073] Among them, the Star Flash device obtains the invisible characters corresponding to the name of the Star Flash device by subtracting a preset value from each visible character in the name of the Star Flash device.

[0074] For the description of the private protocol, please refer to the description in S110-S140 and will not be repeated here.

[0075] In the above example, the Starflash device converts the name of the Starflash device into invisible characters, making it impossible for the upper-layer application of the first terminal to recognize the name of the Starflash device. This effectively hides its own identity and improves the security of the Starflash device. In addition, since terminals that do not support the private protocol cannot recognize the second information sent by the Starflash device, the source of the terminal accessing the Starflash device is guaranteed, preventing malicious terminals from identifying and connecting.

[0076] In a feasible design, after the Star Flash device establishes a Star Flash service interaction protocol connection with the first terminal, the method includes: Sending an authentication request to the first terminal, where the authentication request is used to trigger the first terminal to perform identity authentication; receiving an authentication response from the first terminal, the authentication response including a unique identifier of the first terminal and encrypted preset content, where the encrypted preset content is encrypted by an encryption key determined by the first terminal according to the password index; determining a cryptographic index based on the unique identifier of the first terminal in the authentication response, and determining an encryption key based on the cryptographic index; If the encrypted preset content is successfully decrypted using the encryption key, it is determined that the first terminal has passed the identity authentication; If the encrypted preset content fails to be decrypted using the encryption key, it is determined that the first terminal has not passed the identity authentication and the Star Flash service interaction protocol connection with the first terminal is disconnected.

[0077] The authentication request at least includes the unique identifier of the Starflash device.

[0078] For the description of the preset content, please refer to the description in S110-S140 and will not be repeated here.

[0079] The encapsulation format of the authentication request and authentication response is determined according to a private protocol.

[0080] Exemplarily, when the permission table records the unique identifier of the terminal with access permission and the corresponding password index, the Star Flash device determines the password index by querying the permission table according to the unique identifier of the first terminal in the authentication response.

[0081] Exemplarily, the Star Flash device determines the encryption key according to the password index in the following manner: The Xingshan device determines the corresponding encryption key by querying the association table based on the password index.

[0082] In the above example, after establishing a connection with the first terminal, the Star Flash device actively sends an authentication request to authenticate the first terminal, driving the first terminal to return a response containing the plaintext of the first terminal's unique identifier and the ciphertext of the preset content. The Star Flash device determines the password index through the unique identifier of the first terminal, and then determines the encryption key. The ciphertext of the preset content is decrypted using the encryption key. If the decryption is successful, the identity of the first terminal is considered legal and the connection is maintained; if the decryption fails, the identity of the first terminal is considered untrustworthy and the connection is disconnected, thereby ensuring the identity credibility of the access terminal, effectively preventing illegal access by malicious terminals, and ensuring the security of the Star Flash device.

[0083] In the terminal access method based on the Star Flash protocol provided in the present application, the Star Flash device no longer actively initiates the Star Flash broadcast, but the first terminal actively initiates the Star Flash broadcast carrying its own unique identifier to trigger the process of automatically accessing the Star Flash device. After the Star Flash device receives the Star Flash broadcast from the first terminal, it will reply to the first terminal with the second information carrying the unique identifier of the Star Flash device only after determining that the first terminal has access authority, which effectively avoids the interference of illegal terminals that do not have access authority, blocks the perception of the Star Flash device by unauthorized terminals, and improves the security and stability of the connection between the Star Flash device and the first terminal. The second information enables the first terminal to automatically establish a connection with the Star Flash device, realizing the automatic access of the first terminal with access authority without the user manually selecting the device. After establishing the Star Flash service interaction protocol connection, a secondary identity authentication is performed, which further improves the security of the connection between the Star Flash device and the first terminal.

[0084] like Figure 2As shown, based on the above embodiment, the present application also provides a terminal access method based on the Star Flash protocol, including: S310: The authentication server receives a permission query request from a Star Flash device, where the permission query request includes a unique identifier of a first terminal, and the permission query request is used to determine whether the first terminal has access permission. S320, the authentication server queries a registration activation table based on the unique identifier of the first terminal in the authority query request, where the registration activation table is used to record the unique identifier of each registered and activated terminal; S330: If the registration activation table includes the unique identifier of the first terminal, the authentication server sends a permission query response to the Star Flash device, where the permission query response includes first indication information, where the first indication information is used to indicate that the first terminal has access permission; S340: If the registration activation table does not include the unique identifier of the first terminal, the authentication server sends an authority query response to the Star Flash device, where the authority query response includes second indication information, and the second indication information is used to indicate that the first terminal does not have access authority.

[0085] Exemplarily, the registration activation table also records the unique password index assigned to each terminal, allowing the terminal and the Starflash device to determine their own encryption key based on the password index. Because the password index uniquely corresponds to a terminal, different terminals determine different encryption keys based on the password index. This improves the security of the encryption key and reduces the risk of key leakage.

[0086] Exemplarily, the method further includes: The authentication server receives a registration request from the first terminal, the registration request including a unique identifier of the first terminal, and the registration request is used to obtain permission to access the Starflash device; If the authentication server determines that the first terminal is a legitimate terminal based on the unique identifier of the first terminal, it adds the unique identifier, the assigned password index, and the corresponding encryption method identifier to the registration activation table, and sends a registration response to the first terminal, the registration response including an association table and an encryption method identifier, the association table including a mapping relationship between the password index and the encryption key, and the encryption method identifier indicating the type of encryption algorithm used for identity authentication; If the authentication server determines that the first terminal is an illegal terminal according to the unique identifier of the first terminal, the authentication server sends a registration response indicating that the registration has failed to the first terminal.

[0087] In the above example, to ensure the security and automation of access to the Starflash device, the first terminal needs to actively initiate a registration request to the authentication server to complete activation and obtain access to the Starflash device. The authentication server verifies the unique identifier of the first terminal to ensure that only legitimate terminals can access. The authentication server sends a registration response to the first terminal, including an association table and an encryption method identifier, to facilitate subsequent identity verification by the first terminal.

[0088] When the permission table locally stored in the Star Flash device does not contain relevant information of the first terminal, the authentication server in the embodiment of the present application provides the Star Flash device with a permission query service, so that the Star Flash device can accurately verify whether the first terminal has access authority, ensuring that the authenticated terminal will not be misjudged, and further improving the access security of the Star Flash device.

[0089] like Figure 3 As shown, the present application also provides a terminal access system based on the Star Flash protocol, including a first terminal and a Star Flash device; The first terminal is configured to send first information based on the StarFlash protocol in a broadcast manner, where the first information includes a unique identifier of the first terminal, and the first information is configured to enable the first terminal to discover surrounding StarFlash devices; The Star Flash device is configured to determine, after receiving the first information, whether the first terminal has access authority based on the unique identifier of the first terminal; If the first terminal does not have access permission, the Star Flash device remains in silent communication mode; If the first terminal has access authority, the Starflash device is used to send second information based on the Starflash protocol to the first terminal, where the second information includes a unique identifier of the Starflash device; The first terminal is configured to obtain the second information by scanning and then parse the second information to obtain a unique identifier of the Star Flash device; The first terminal is used to send an access request to the Star Flash device according to the unique identifier of the Star Flash device, where the access request is used to trigger the establishment of a Star Flash service interaction protocol connection with the Star Flash device; The Starflash device is used to establish a Starflash service interaction protocol connection with the first terminal after receiving the access request.

[0090] In one possible design, an authentication server is included; The Star Flash device is further configured to send a permission query request to the authentication server if the locally stored permission table does not include the unique identifier of the first terminal, the permission table being configured to record the unique identifier of each terminal with access permission, the permission query request including the unique identifier of the first terminal, and the permission query request being configured to determine whether the first terminal has access permission; The authentication server is configured to, after receiving the permission query request from the Star Flash device, query a registration activation table based on the unique identifier of the first terminal in the permission query request, wherein the registration activation table is configured to record the unique identifier of each registered and activated terminal; If the registration activation table includes the unique identifier of the first terminal, the authentication server sends a permission query response to the Star Flash device, where the permission query response includes first indication information, where the first indication information is used to indicate that the first terminal has access permission; If the registration activation table does not include the unique identifier of the first terminal, the authentication server sends a permission query response to the Star Flash device, and the permission query response includes second indication information, and the second indication information is used to indicate that the first terminal does not have access permission.

[0091] In one feasible design, the second information includes a password index uniquely corresponding to the first terminal. After the first terminal establishes a Starflash service interaction protocol connection with the Starflash device, the first terminal is further configured to: After receiving the authentication request from the Starflash device, determining an authentication response, the authentication response including a unique identifier of the first terminal and preset content encrypted using an encryption key, the encryption key being determined by the first terminal based on the password index; the encrypted preset content is decrypted by the Starflash device to determine whether the identity authentication of the first terminal is successful; Send the authentication response to the Star Flash device.

[0092] In a feasible design, the first terminal parses the second information in the following manner: If the second information includes a private protocol header and invisible characters corresponding to the name of the Star Flash device, the second information is parsed according to the private protocol; wherein, the invisible characters are used to prevent the name of the Star Flash device from being rendered as readable text in the list of connectable devices of the first terminal.

[0093] In a feasible design, before the first terminal sends the first information based on the Star Flash protocol in a broadcast manner, the first terminal is further configured to: Send a registration request to the authentication server, where the registration request includes a unique identifier of the first terminal and is used to obtain permission to access the Starflash device; Receive a registration response from the authentication server, the registration response including an association table and an encryption method identifier, the association table including a mapping relationship between a password index and an encryption key, and the encryption method identifier indicating the type of encryption algorithm used for identity authentication.

[0094] In a feasible design, after the Star Flash device establishes a Star Flash service interaction protocol connection with the first terminal, the Star Flash device is further configured to: Sending an authentication request to the first terminal, where the authentication request is used to trigger the first terminal to perform identity authentication; receiving an authentication response from the first terminal, the authentication response including a unique identifier of the first terminal and encrypted preset content, where the encrypted preset content is encrypted by an encryption key determined by the first terminal according to the password index; Determining a cryptographic index based on the unique identifier of the first terminal in the authentication response, and determining an encryption key based on the cryptographic index; If the encrypted preset content is successfully decrypted using the encryption key, it is determined that the first terminal has passed the identity authentication; If the encrypted preset content fails to be decrypted using the encryption key, it is determined that the first terminal has not passed the identity authentication and the Star Flash service interaction protocol connection with the first terminal is disconnected.

[0095] In a feasible design, if the first terminal has access authority, the Star Flash device is further configured to: Converting the name of the Starflash device into invisible characters, wherein the invisible characters are used to prevent the name of the Starflash device from being rendered as readable text in the connectable device list of the first terminal; According to the private protocol, the private protocol header and the invisible characters corresponding to the name of the Star Flash device are encapsulated into the second information.

[0096] In a feasible design, the Star Flash device determines whether the first terminal has access authority based on the unique identifier of the first terminal in the following manner: According to the unique identifier of the first terminal, query the locally stored permission table, the permission table is used to record the unique identifier of each terminal with access permission; If the permission table contains the unique identifier of the first terminal, determining that the first terminal has access permission, and generating second information according to the password index corresponding to the unique identifier of the first terminal in the permission table; If the permission table does not include the unique identifier of the first terminal, it is determined whether the first terminal has the access permission by interacting with the authentication server.

[0097] For other implementation methods and effects of the above system, please refer to the description in the embodiment of the terminal access method based on the Star Flash protocol, which will not be repeated here.

[0098] The basic principles of the present application have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, and effects mentioned in this application are merely illustrative and not restrictive, and it should not be assumed that these advantages, strengths, and effects are required of each embodiment of this application. In addition, the specific details disclosed above are merely illustrative and facilitating understanding, and are not restrictive. The above details do not limit this application to necessarily being implemented using the above specific details.

[0099] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.

[0100] The block diagrams of the devices, devices, equipment, and systems involved in this application are intended only as illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As will be appreciated by those skilled in the art, these devices, devices, equipment, and systems can be connected, arranged, or configured in any manner. Words such as "include," "comprise," "have," and the like are open-ended words, meaning "including but not limited to," and can be used interchangeably therewith. The words "or" and "and" used herein refer to the words "and / or" and can be used interchangeably therewith, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to," and can be used interchangeably therewith.

[0101] It should also be noted that in the apparatus, device, and method of the present application, each component or each step can be decomposed and / or recombined, and such decomposition and / or recombination should be regarded as equivalent solutions of the present application.

[0102] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present application. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present application. Therefore, the present application is not intended to be limited to the aspects shown herein, but rather to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0103] The above description has been provided for the purpose of illustration and description. Furthermore, this description is not intended to limit the embodiments of the present application to the forms disclosed herein. Although a number of example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.

Claims

1. A terminal access method based on the Star Flash protocol, applied to a first terminal, characterized in that: include: Sending first information based on the StarFlash protocol in a broadcast manner, where the first information includes a unique identifier of the first terminal, and the first information is used to discover surrounding StarFlash devices; Acquire, by scanning, second information based on the Star Flash protocol from the Star Flash device, where the second information includes a unique identifier of the Star Flash device, and the second information is sent by the Star Flash device after determining that the first terminal has access permission based on the unique identifier of the first terminal; Parsing the second information to obtain a unique identifier of the Star Flash device; According to the unique identifier of the Star Flash device, an access request is sent to the Star Flash device, where the access request is used to trigger the establishment of a Star Flash service interaction protocol connection with the Star Flash device.

2. The method according to claim 1, characterized in that The second information includes a password index uniquely corresponding to the first terminal. After the first terminal establishes a Starflash service interaction protocol connection with the Starflash device, the method includes: After receiving the authentication request from the Starflash device, determining an authentication response, the authentication response including a unique identifier of the first terminal and preset content encrypted using an encryption key, the encryption key being determined by the first terminal based on the password index; the encrypted preset content being decrypted by the Starflash device to determine whether the identity authentication of the first terminal is successful; Send the authentication response to the Star Flash device.

3. The method according to claim 1 or 2, characterized in that The parsing of the second information includes: If the second information includes a private protocol header and invisible characters corresponding to the name of the Star Flash device, the second information is parsed according to the private protocol; wherein, the invisible characters are used to prevent the name of the Star Flash device from being rendered as readable text in the list of connectable devices of the first terminal.

4. The method according to claim 1 or 2, characterized in that Before sending the first information based on the Star Flash protocol in a broadcast manner, the method includes: Sending a registration request to an authentication server, the registration request including a unique identifier of the first terminal, the registration request being used to obtain permission to access a Starflash device; A registration response from the authentication server is received, wherein the registration response includes an association table and an encryption method identifier, wherein the association table includes a mapping relationship between a password index and an encryption key, and the encryption method identifier is used to indicate the type of encryption algorithm used for identity authentication.

5. A terminal access method based on the Star Flash protocol, applied to Star Flash equipment, characterized in that: include: receiving first information based on the StarFlash protocol sent by a first terminal in a broadcast manner, where the first information includes a unique identifier of the first terminal, and the first information is used to enable the first terminal to discover surrounding StarFlash devices; determining, based on a unique identifier of the first terminal, whether the first terminal has access authority; If the first terminal does not have access authority, keep the communication silent; If the first terminal has access permission, send second information based on the Star Flash protocol to the first terminal, where the second information includes a unique identifier of the Star Flash device; After receiving the access request from the first terminal, a Starflash service interaction protocol connection is established with the first terminal. The access request is information sent by the first terminal after obtaining the second information, which is used to trigger the first terminal to establish a Starflash service interaction protocol connection with the Starflash device.

6. The method according to claim 5, characterized in that After the Star Flash device establishes a Star Flash service interaction protocol connection with the first terminal, the method includes: Sending an authentication request to the first terminal, where the authentication request is used to trigger the first terminal to perform identity authentication; receiving an authentication response from the first terminal, the authentication response including a unique identifier of the first terminal and encrypted preset content, the encrypted preset content being encrypted by an encryption key determined by the first terminal according to the password index; determining a password index based on the unique identifier of the first terminal in the authentication response, and determining an encryption key based on the password index; if the encrypted preset content is successfully decrypted using the encryption key, determining that the first terminal has passed the identity authentication; If the encrypted preset content fails to be decrypted using the encryption key, it is determined that the first terminal has failed identity authentication and the Starflash service interaction protocol connection with the first terminal is disconnected.

7. The method according to claim 5 or 6, characterized in that If the first terminal has access authority, the method includes: Converting the name of the Starflash device into invisible characters, wherein the invisible characters are used to prevent the name of the Starflash device from being rendered as readable text in the connectable device list of the first terminal; According to the private protocol, the private protocol header and the invisible characters corresponding to the name of the Star Flash device are encapsulated into the second information.

8. The method according to claim 5 or 6, characterized in that The determining, based on the unique identifier of the first terminal, whether the first terminal has access permission includes: querying a locally stored permission table according to the unique identifier of the first terminal, the permission table being used to record the unique identifier of each terminal having access permission; If the permission table contains the unique identifier of the first terminal, determining that the first terminal has access permission, and generating second information according to the password index corresponding to the unique identifier of the first terminal in the permission table; If the permission table does not include the unique identifier of the first terminal, it is determined whether the first terminal has access permission by interacting with the authentication server.

9. A terminal access system based on the Star Flash protocol, characterized in that: Including the first terminal and the star flash device; The first terminal is configured to send first information based on the StarFlash protocol in a broadcast manner, where the first information includes a unique identifier of the first terminal, and the first information is configured to enable the first terminal to discover surrounding StarFlash devices; The Star Flash device is configured to determine, after receiving the first information, whether the first terminal has access permission based on a unique identifier of the first terminal; If the first terminal does not have access permission, the Star Flash device remains in a communication silent state; If the first terminal has access permission, the Starflash device is used to send second information based on the Starflash protocol to the first terminal, where the second information includes a unique identifier of the Starflash device; The first terminal is configured to obtain the second information by scanning and then parse the second information to obtain a unique identifier of the Star Flash device; The first terminal is used to send an access request to the Star Flash device according to the unique identifier of the Star Flash device, where the access request is used to trigger establishment of a Star Flash service interaction protocol connection with the Star Flash device; The Starflash device is used to establish a Starflash service interaction protocol connection with the first terminal after receiving the access request.

10. The system according to claim 9, characterized in that Including authentication server; The Star Flash device is further configured to send a permission query request to the authentication server if the locally stored permission table does not include the unique identifier of the first terminal, the permission table being configured to record the unique identifier of each terminal with access permission, the permission query request including the unique identifier of the first terminal, and the permission query request being configured to determine whether the first terminal has access permission; The authentication server is configured to, after receiving the permission query request from the Star Flash device, query a registration activation table based on the unique identifier of the first terminal in the permission query request, wherein the registration activation table is configured to record the unique identifier of each registered and activated terminal; If the registration activation table includes the unique identifier of the first terminal, the authentication server sends a permission query response to the Star Flash device, where the permission query response includes first indication information, where the first indication information is used to indicate that the first terminal has access permission; If the registration activation table does not include the unique identifier of the first terminal, the authentication server sends a permission query response to the Star Flash device, and the permission query response includes second indication information, and the second indication information is used to indicate that the first terminal does not have access permission.

Citation Information

Patent Citations

  • Switching method, storage medium and wireless communication device

    CN114449602A

  • Method for establishing SLB connection, electronic equipment and communication system

    CN116017377A

  • Wireless communication method and wireless communication device

    CN117221826A

  • Star flash-based set top box remote controller security authentication system and method

    CN117915130A

  • Communication method based on short-distance wireless communication technology

    CN118215029A

Cited By

  • Intelligent terminal non-inductive connection method and system supporting multi-device priority decision

    CN121262672A

  • Data processing device and communication method based on open-source honk and star flash communication protocol

    CN122372996A