Terminal network distribution system and method
By having smart home devices continuously send encrypted Bluetooth broadcast data and establish an encrypted connection with the control terminal after power-on, the cumbersome problem of users actively triggering network configuration is solved, resulting in a better user experience and security.
Patent Information
- Application Number
- CN202410575142.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-09
- Publication Date
- 2025-11-18
AI Technical Summary
In the current process of configuring smart home devices, users need to actively trigger the devices to enter the configuration state, which makes the process cumbersome and results in a poor user experience. At the same time, Bluetooth broadcast data is easily exploited by malicious control terminals, posing a security risk.
After powering on, the terminal continuously sends Bluetooth broadcast data carrying encrypted messages. After decryption, the control end generates a response encrypted message and establishes a Bluetooth connection. The encryption mechanism ensures data security and connection legitimacy. The dynamic communication key is used for WIFI network access.
It improves the user's network configuration experience, prevents Bluetooth connections from being maliciously controlled, and enhances the security and privacy protection of the network configuration process.
Smart Images

Figure CN120980640A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of smart home technology, and in particular to a terminal network configuration system and method. Background Technology
[0002] Currently, in the Internet of Things (IoT) technology, different smart home devices and other terminals can connect to the WIFI network to achieve data sharing between smart home devices. With the rapid development of IoT technology, more and more smart home devices support WIFI network connection, leading to an increasing demand for different smart home devices to connect to the WIFI network.
[0003] In related technologies, when smart home devices need to access a Wi-Fi network, they must first establish a Bluetooth connection with a manufacturer-designated control terminal (such as an app that controls the smart home devices) before they can access the Wi-Fi network through the control terminal. Establishing a connection with the control terminal usually requires active user intervention, such as pressing a specific button on the smart home device to put it into pairing mode, in which case a Bluetooth connection can be established with the control terminal.
[0004] In the methods described above, users need to actively control the smart home devices each time they are configured to connect to the network, putting them into configuration mode and enabling Wi-Fi access. This cumbersome configuration process results in a poor user experience during the smart home device configuration process. Summary of the Invention
[0005] This application provides a terminal network configuration system and method, which can improve the user experience during the network configuration process of smart home devices. The technical solution is as follows:
[0006] On the one hand, a terminal distribution network system is provided, the system comprising: a terminal and a control terminal;
[0007] The terminal is configured to continuously send Bluetooth broadcast data after power-on, the Bluetooth broadcast data carrying a first encrypted message;
[0008] The control terminal is used to obtain a second encrypted message after receiving the Bluetooth broadcast data. The second encrypted message is generated in response to the successful decryption of the first encrypted message.
[0009] The terminal is further configured to establish a Bluetooth connection with the control terminal after receiving the second encrypted message and successfully decrypting the second encrypted message, so as to access the WIFI network through the control terminal.
[0010] Optionally, the control terminal is further configured to acquire and store a dynamic communication key when acquiring the second encrypted message, wherein the second encrypted message also carries the dynamic communication key, and the dynamic communication key is generated based on a random method;
[0011] The terminal is also used to store the dynamic communication key if the second encrypted message is successfully decrypted;
[0012] The dynamic communication key is used for communication between the terminal and the control terminal, so as to enable the terminal to access the WIFI network through the control terminal.
[0013] Optionally, the terminal is further configured to obtain a WIFI list when a Bluetooth connection is established with the control terminal, and send the WIFI list to the control terminal via the Bluetooth connection. The WIFI list includes at least one WIFI identifier, which is used to indicate the WIFI that the terminal can currently identify.
[0014] The control terminal is further configured to, after receiving the WIFI list, respond to the user's operation, determine the target WIFI identifier and the target key corresponding to the target WIFI identifier from the at least one WIFI identifier, encrypt the target WIFI identifier and the target key based on the dynamic communication key, generate a network configuration encryption message, and send the network configuration encryption message to the terminal;
[0015] The terminal is further configured to, upon receiving the network encryption message, decrypt the network encryption message based on the dynamic communication key, and access the target WIFI network corresponding to the target WIFI identifier based on the target WIFI identifier and the target key in the network encryption message.
[0016] Optionally, the system further includes a cloud platform corresponding to the control terminal;
[0017] The control terminal is used to send the Bluetooth broadcast data to the cloud platform after receiving the Bluetooth broadcast data;
[0018] The cloud platform is configured to, upon receiving the Bluetooth broadcast data, determine the terminal private key corresponding to the terminal from at least one stored private key based on the terminal's identifier, decrypt the first encrypted message based on the terminal private key, generate the dynamic communication key, encrypt the decrypted first encrypted message and the dynamic communication key based on the terminal private key, generate the second encrypted message, and send the second encrypted message and the dynamic communication key to the control terminal.
[0019] The control terminal is also used to receive the second encrypted message and the dynamic communication key.
[0020] Optionally, the terminal is further configured to delete the stored dynamic communication key after accessing the target WIFI network, and send a network access success message to the control terminal through the target WIFI network;
[0021] The control terminal is also used to delete the stored dynamic communication key upon receiving the network access success message.
[0022] Optionally, the first encrypted message and the second encrypted message also carry a target timestamp, which is used to indicate the generation time of the first encrypted message;
[0023] The terminal is configured to establish a Bluetooth connection with the control terminal after receiving the second encrypted message, and if the second encrypted message is successfully decrypted and the difference between the current time of the terminal and the target timestamp in the second encrypted message is less than or equal to the target difference, so as to access the WIFI network through the control terminal.
[0024] On the other hand, a terminal network configuration method is provided, the method being applied to a terminal network configuration system, the terminal network configuration system including a control terminal and terminals, the method comprising:
[0025] The terminal continuously sends Bluetooth broadcast data after power-on, and the Bluetooth broadcast data carries a first encrypted message;
[0026] After receiving the Bluetooth broadcast data, the control terminal obtains the second encrypted message, which is generated in response to the successful decryption of the first encrypted message.
[0027] After receiving the second encrypted message, the terminal establishes a Bluetooth connection with the control terminal after successfully decrypting the second encrypted message, so as to access the WIFI network through the control terminal.
[0028] Optionally, the method further includes:
[0029] When the control terminal obtains the second encrypted message, it acquires and stores the dynamic communication key. The second encrypted message also carries the dynamic communication key, which is generated based on a random method.
[0030] If the terminal successfully decrypts the second encrypted message, it stores the dynamic communication key.
[0031] The dynamic communication key is used for communication between the terminal and the control terminal, so as to enable the terminal to access the WIFI network through the control terminal.
[0032] Optionally, the method further includes:
[0033] When the terminal establishes a Bluetooth connection with the control terminal, it obtains a WIFI list and sends the WIFI list to the control terminal via the Bluetooth connection. The WIFI list includes at least one WIFI identifier, which is used to indicate the WIFI that the terminal can currently recognize.
[0034] After receiving the WIFI list, the control terminal responds to the user's operation by determining the target WIFI identifier and the target key corresponding to the target WIFI identifier from the at least one WIFI identifier, encrypting the target WIFI identifier and the target key based on the dynamic communication key, generating a network configuration encryption message, and sending the network configuration encryption message to the terminal.
[0035] After receiving the encrypted distribution network message, the terminal decrypts the encrypted distribution network message based on the dynamic communication key, and accesses the target WIFI network corresponding to the target WIFI identifier based on the target WIFI identifier and the target key in the encrypted distribution network message.
[0036] Optionally, the system further includes a cloud platform corresponding to the terminal, and the method further includes:
[0037] After receiving the Bluetooth broadcast data, the control terminal sends the Bluetooth broadcast data to the cloud platform;
[0038] After receiving the Bluetooth broadcast data, the cloud platform determines the terminal private key corresponding to the terminal from at least one stored private key based on the terminal's identifier, decrypts the first encrypted message based on the terminal private key, generates the dynamic communication key, encrypts the decrypted first encrypted message and the dynamic communication key based on the terminal private key, generates the second encrypted message, and sends the second encrypted message and the dynamic communication key to the control terminal.
[0039] The control terminal receives the second encrypted message and the dynamic communication key.
[0040] Optionally, the method further includes: after the terminal accesses the target WIFI network, deleting the stored dynamic communication key and sending a network access success message to the control terminal through the target WIFI network;
[0041] Upon receiving the network access success message, the control terminal deletes the stored dynamic communication key.
[0042] Optionally, the first encrypted message and the second encrypted message further carry a target timestamp, the target timestamp being used to indicate the generation time of the first encrypted message; the method further includes:
[0043] After receiving the second encrypted message, if the terminal successfully decrypts the second encrypted message and the difference between the terminal's current time and the target timestamp in the second encrypted message is less than or equal to the target difference, it establishes a Bluetooth connection with the control terminal to access the WIFI network through the control terminal.
[0044] The technical solution provided in this application can bring at least the following beneficial effects:
[0045] After powering on, the terminal continuously sends Bluetooth broadcast data. Therefore, without user intervention, the terminal automatically enters network configuration mode and continues sending Bluetooth broadcast data, improving the user experience during network configuration. Furthermore, because the Bluetooth broadcast data sent by the terminal carries a first encrypted message, the terminal only establishes a Bluetooth connection with the control terminal after receiving and successfully decrypting the second encrypted message (response to the first encrypted message). Thus, although the terminal continuously sends Bluetooth broadcast data via broadcast, the encrypted nature of the first encrypted message ensures that the Bluetooth broadcast data sent by the terminal cannot be exploited by malicious control terminals. Furthermore, the terminal will only establish a Bluetooth connection with the control terminal that sent the second encrypted message if it successfully decrypts the second encrypted message. In other words, if the encrypted message received by the terminal is not generated in response to the successful decryption of the first encrypted message, or if the terminal cannot successfully decrypt the message, the terminal will not establish a Bluetooth connection with the control terminal that sent the encrypted message. This avoids the terminal's Bluetooth connection channel being preempted by a malicious control terminal, which could lead to the terminal being controlled by a malicious control terminal, thereby improving the security of the terminal during network configuration. Attached Figure Description
[0046] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0047] Figure 1 This is a signal timing diagram of a terminal distribution network in a scenario provided by an embodiment of this application;
[0048] Figure 2 This is a schematic diagram of a terminal distribution network system provided in an embodiment of this application;
[0049] Figure 3 This is a signal timing diagram of a terminal distribution network system provided in an embodiment of this application;
[0050] Figure 4 This is a signal timing diagram of another terminal distribution network system provided in an embodiment of this application;
[0051] Figure 5 This is a schematic diagram of another terminal distribution network system provided in the embodiments of this application;
[0052] Figure 6 This is a signal timing diagram of another terminal distribution network system provided in an embodiment of this application;
[0053] Figure 7 This is a signal timing diagram of another terminal distribution network system provided in an embodiment of this application;
[0054] Figure 8 This is a signal timing diagram of another terminal distribution network system provided in an embodiment of this application;
[0055] Figure 9 This is a schematic flowchart of a terminal network configuration method provided in an embodiment of this application;
[0056] Figure 10 This is a schematic diagram of the structure of a terminal provided in an embodiment of this application;
[0057] Figure 11 This is a schematic diagram of the structure of a cloud platform provided in an embodiment of this application. Detailed Implementation
[0058] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0059] Before providing a detailed explanation of the terminal network distribution system provided in the embodiments of this application, the application scenarios involved in the embodiments of this application will be introduced first.
[0060] Smart home devices typically refer to home devices connected via Internet of Things (IoT) technology. These devices can be associated with a manufacturer-designated control terminal and access the network, allowing users to control the devices and obtain their operational information without direct contact, thus enabling intelligent management of the home devices.
[0061] In smart home applications, users typically need to install the corresponding control terminal for the smart home device on their electronic devices (such as mobile phones and computers). This can be achieved by installing a manufacturer-specified application (APP) to control the smart home device. This allows users to remotely control the smart home device, such as controlling its access to a specific network and enabling intelligent use of the device.
[0062] In some scenarios, refer to Figure 1 In the network configuration process for smart home devices and other terminals, users typically need to manually trigger specific modules on the terminal to enter network configuration mode and send Bluetooth broadcast data, thereby establishing a Bluetooth connection with the control terminal. After establishing the Bluetooth connection, if the control terminal needs to access the network, it usually searches for nearby Wi-Fi networks, generates a Wi-Fi list, and transmits the list to the control terminal via Bluetooth. The user selects the desired Wi-Fi network on the control terminal and enters the Wi-Fi password. The control terminal then sends the Wi-Fi name and password to the terminal via Bluetooth, enabling the terminal to access the corresponding Wi-Fi network based on the Wi-Fi name and password, thus completing the network configuration.
[0063] In the above process, on the one hand, since the terminal usually needs to manually trigger a specific module of the terminal to enter the network configuration state, the user experience during the network configuration process is poor; on the other hand, since the terminal sends Bluetooth broadcast data in the network configuration state by broadcasting, the privacy is poor, which may lead to the Bluetooth broadcast data being used by malicious control terminals, such as malicious third-party software, to seize the Bluetooth connection with the terminal, thus posing a security risk.
[0064] Based on this, the embodiments of this application provide a terminal network configuration method, which can not only improve the user experience during the terminal network configuration process, but also ensure that the Bluetooth broadcast data sent by the terminal will not be used by malicious control terminals, thereby improving the security of the terminal network configuration process.
[0065] Please refer to Figure 2 , Figure 2 This is a schematic diagram of a terminal distribution network system according to an exemplary embodiment. The terminal distribution network system includes a terminal 201 and a control terminal 202, and the terminal 201 can communicate with the control terminal 202.
[0066] Terminal 201 is used to continuously send Bluetooth broadcast data after power-on, the Bluetooth broadcast data carrying a first encrypted message. Control terminal 202 is used to obtain a second encrypted message after receiving the Bluetooth broadcast data; the second encrypted message is generated in response to successful decryption of the first encrypted message. Terminal 201 is also used to establish a Bluetooth connection with control terminal 202 after receiving and successfully decrypting the second encrypted message, so as to access the WIFI network through control terminal 202.
[0067] The terminal 201 can be any kind of smart home device, such as a smart TV, smart speaker, smart socket, smart lamp, etc. Optionally, the embodiments of this application can also be applied to other smart devices, such as smartwatches and other smart wearable devices.
[0068] The control terminal 202 is designated by the manufacturer of the terminal 201 and is used to control the management terminal 201, such as an APP used to control the terminal 201.
[0069] Terminal 201 can periodically send Bluetooth broadcast data after power-on, such as sending Bluetooth broadcast data once per second.
[0070] Optionally, once a Bluetooth connection is established between the terminal 201 and the control terminal 202, the terminal 201 may stop sending Bluetooth broadcast data to save power consumption.
[0071] In some embodiments, the first decryption message may be generated based on the terminal private key of terminal 201, or it may be generated in other ways. The following is an illustration of a specific scenario.
[0072] Scenario 1: Terminal 201 may include a terminal private key. The first encrypted message may be an encrypted message generated based on the terminal private key of terminal 201, and the second encrypted message may be an encrypted message generated based on the terminal private key in response to the successful decryption of the first encrypted message. In this case, the process of establishing a Bluetooth connection between terminal 201 and control terminal 202 can be as follows.
[0073] Terminal 201 encrypts the message based on its private key to obtain a first encrypted message, and continuously sends Bluetooth broadcast data carrying the first encrypted message and the identifier of terminal 201. This message can be selected according to actual usage requirements; for example, the message may include a verification code to verify the connection between the terminal 201 and the control terminal 202 during the Bluetooth connection process.
[0074] For example, the first encrypted message of terminal 201 carries a first verification code. Terminal 201 will only establish a Bluetooth connection with the control terminal 202 that sent the second encrypted message if it receives a second encrypted message containing a second verification code that matches the first verification code.
[0075] In some embodiments, the control terminal 202 may include an authentication module. After receiving Bluetooth broadcast data, the control terminal 202 sends the Bluetooth broadcast data to the authentication module. The authentication module can generate a second encrypted message based on the Bluetooth broadcast data, thereby enabling the control terminal 202 to obtain the second encrypted message.
[0076] The authentication module can store terminal private keys corresponding to different terminal identifiers. Based on the identifier of terminal 201 carried in the Bluetooth broadcast data, the terminal private key corresponding to terminal 201 is determined. Then, the first encrypted message in the Bluetooth broadcast data is decrypted based on the terminal private key. After successfully decrypting the first encrypted message, a second encrypted message is generated based on the successfully decrypted first encrypted message.
[0077] For example, in conjunction with the above, the first encrypted message includes a first verification code. After successfully decrypting the first encrypted message based on the terminal private key, the authentication module can determine the second verification code based on the first verification code, encrypt the second verification code based on the terminal private key, obtain the second encrypted message, and send the second encrypted message to the control terminal 202.
[0078] Optionally, after obtaining the second encrypted message, the control terminal 202 may send a Bluetooth connection request carrying the second encrypted message to the terminal 201 to request the establishment of a Bluetooth connection with the terminal 201.
[0079] Optionally, if after receiving a Bluetooth connection request, the terminal 201 is unable to successfully decrypt the second encrypted message in the Bluetooth connection request based on the terminal's private key, or if the second encrypted message after successful decryption is not generated in response to the successful decryption of the first encrypted message, such as the second verification code in the second encrypted message not matching the first verification code in the first encrypted message, then the control terminal 202 is considered an abnormal control terminal, and the establishment of a Bluetooth connection with the control terminal 202 is refused.
[0080] In some embodiments, the signal timing diagram for establishing a Bluetooth connection between terminal 201 and control terminal 202 can be as shown in Figure 3. Combined with... Figure 3 After powering on, terminal 201 continuously sends Bluetooth broadcast data bData, which carries the identifier dId of terminal 201 and a first encrypted message AES_ENC(pkey) generated based on the terminal's private key pkey. After receiving bData, control terminal 202 obtains the second encrypted message encData(pkey) and sends encData(pkey) to terminal 201 to request to establish a Bluetooth connection with terminal 201. After receiving encData(pkey), terminal 201 decrypts it based on pkey. If decryption is successful, a Bluetooth connection is established with control terminal 202; otherwise, the connection is refused.
[0081] Scenario 2: Terminal 201 may include a public key and a private key. The first encrypted message may be an encrypted message generated by terminal 201 based on the public key, and the second encrypted message may be an encrypted message generated based on the private key in response to successful decryption of the first encrypted message. In this case, the process of establishing a Bluetooth connection between terminal 201 and control terminal 202 can be as follows.
[0082] Terminal 201 can generate a first encrypted message based on the public key. This first encrypted message includes the identifier of terminal 201. At this time, the Bluetooth broadcast data sent by terminal 201 may not include the identifier of terminal 201. After receiving the Bluetooth broadcast data, control terminal 202 sends the Bluetooth broadcast data to the authentication module. The authentication module can generate a second encrypted message based on the Bluetooth broadcast data, thereby enabling control terminal 202 to obtain the second encrypted message.
[0083] The authentication module can store a public key and a private key corresponding to different terminal identifiers, so as to decrypt the first encrypted message based on the public key.
[0084] If the authentication module successfully decrypts the first encrypted message using the public key and obtains the identifier of terminal 201, it determines the corresponding private key based on the identifier of terminal 201, generates a second encrypted message based on the private key, and sends the second encrypted message to the control terminal 202. After receiving the second encrypted message, the control terminal 202 sends a second encrypted message to terminal 201 to request the establishment of a Bluetooth connection with terminal 201.
[0085] After receiving the second encrypted message, if the terminal 201 successfully decrypts the second encrypted message based on the terminal's private key, it establishes a Bluetooth connection with the control terminal 202; otherwise, it does not establish a Bluetooth connection with the control terminal 202.
[0086] If the authentication module's public key fails to decrypt the first encrypted message, it can return a verification failure message to the control terminal 202. Upon receiving the verification failure message from the authentication module, the control terminal 202 will not send a Bluetooth connection request to the terminal 201. The specific process for establishing a Bluetooth connection between the terminal 201 and the control terminal 202 can be described in conjunction with the above. Figure 3 And about Figure 3 The relevant descriptions will not be repeated here.
[0087] Thus, when establishing a Bluetooth connection between terminal 201 and control terminal 202, dual authentication is achieved during the Bluetooth connection process by separating the key used in the first encrypted message from the key used in the second encrypted message. Specifically, if control terminal 202 needs to establish a Bluetooth connection with terminal 201, not only must the authentication module be able to determine the public key and decrypt the Bluetooth broadcast data sent by terminal 201 based on the public key, but the cloud platform 203 must also be able to determine the terminal private key corresponding to terminal 201 and generate a second encrypted message based on the terminal private key, thereby improving the security of the Bluetooth connection process.
[0088] Scenario 3: Terminal 201 may also include a first terminal private key and a second terminal private key. The first encrypted message may be an encrypted message generated by terminal 201 based on the first terminal private key, and the second encrypted message may be generated based on the second terminal private key in response to successful decryption of the first encrypted message. In this case, the process of establishing a Bluetooth connection between terminal 201 and control terminal 202 can be described as follows.
[0089] Terminal 201 can generate a first encrypted message based on a first terminal private key and send Bluetooth broadcast data carrying the first encrypted message and the identifier of terminal 201. After receiving the Bluetooth broadcast data, control terminal 202 sends the Bluetooth broadcast data to the authentication module. The authentication module can generate a second encrypted message based on the Bluetooth broadcast data, thereby enabling control terminal 202 to obtain the second encrypted message.
[0090] The authentication module stores a first terminal private key and a second terminal private key corresponding to different terminal identifiers, so as to determine the first terminal private key and the second terminal private key corresponding to terminal 201 based on the identifier of terminal 201.
[0091] The authentication module decrypts the first encrypted message based on the first terminal's private key. If the authentication module successfully decrypts the first encrypted message, it generates a second encrypted message based on the second terminal's private key and sends the second encrypted message to the control terminal 202. Upon receiving the second encrypted message, the control terminal 202 sends the second encrypted message to the terminal 201 to request the establishment of a Bluetooth connection. If the terminal 201 successfully decrypts the second encrypted message based on the second terminal's private key, it establishes a Bluetooth connection with the control terminal 202; otherwise, it does not establish a Bluetooth connection. If the authentication module fails to decrypt the first encrypted message, it returns a verification failure message to the control terminal 202. Upon receiving the verification failure message from the authentication module, the control terminal 202 does not send a Bluetooth connection request to the terminal 201. The specific signal timing diagram for establishing a Bluetooth connection between the terminal 201 and the control terminal 202 is described above. Figure 3 And about Figure 3 The relevant descriptions will not be repeated here.
[0092] In this way, by separating the first terminal private key used in the first encrypted message from the second terminal private key used in the second encrypted message, dual authentication is achieved during the Bluetooth connection process between terminal 201 and control terminal 202. Specifically, if control terminal 202 needs to establish a Bluetooth connection with terminal 201, the authentication module not only needs to determine the first terminal private key and decrypt the first encrypted message sent by terminal 201 based on the first terminal private key, but also needs to determine the second terminal private key and generate a second encrypted message based on the second terminal private key, thereby further improving the security of the Bluetooth connection process.
[0093] In addition, since the network configuration process also involves the transmission of private data such as WIFI passwords, during the transmission process, the control terminal 202 can usually only generate keys and encrypt the private data using a fixed encryption algorithm, or transmit it without encryption. This results in poor security of the private data, and some malicious software or viruses can easily obtain the transmitted encrypted password or plaintext password through sniffing attacks. After obtaining the encrypted password, they can reverse engineer the key generation algorithm by combining it with the code on the control terminal, and then obtain the key and decrypt it to obtain the plaintext password, leading to the leakage of private data.
[0094] Based on this, in some embodiments, the control terminal 202 is further configured to acquire and store a dynamic communication key when acquiring the second encrypted message. The second encrypted message also carries the dynamic communication key, which is generated randomly. The terminal 201 is further configured to store the dynamic communication key upon successfully decrypting the second encrypted message. The dynamic encrypted communication key is used for communication between the terminal 201 and the control terminal 202, enabling the terminal 201 to access the WIFI network through the control terminal 202.
[0095] In some embodiments, in conjunction with the authentication module described above, when generating the second encrypted message, the authentication module can generate a dynamic communication key and carry the dynamic communication key in the second encrypted message, thereby sending the second encrypted message to the control terminal 202.
[0096] Optionally, the dynamic communication key may not be acquired when acquiring the second encrypted message, depending on the specific usage requirements. In some embodiments, the control terminal 202 may also acquire the dynamic communication key and an encrypted message carrying the dynamic communication key in response to the user's network configuration command, and store the dynamic communication key and the encrypted message carrying the dynamic communication key. Then, after establishing a Bluetooth connection with the terminal 201, the control terminal 202 may send the encrypted message carrying the dynamic communication key to the terminal 201 via Bluetooth. In other embodiments, the control terminal 202 may also periodically acquire the dynamic communication key and an encrypted message carrying the dynamic communication key, and store the dynamic communication key and the encrypted message carrying the dynamic communication key. Then, after establishing a Bluetooth connection with the terminal 201, the control terminal 202 may send the most recently stored encrypted message carrying the dynamic communication key to the terminal 201 via Bluetooth.
[0097] In some embodiments, in order to improve the security of dynamic communication keys, a certain usage period can be set for the dynamic communication keys. The usage period can be determined in combination with actual usage needs, such as 5 hours, 10 hours, etc. When the generation time of the dynamic communication key exceeds the usage period, the dynamic communication key will become an invalid key that cannot be used.
[0098] In some embodiments, terminal 201 is further configured to obtain a WIFI list when a Bluetooth connection is established with control terminal 202, and send the WIFI list to control terminal 202 via Bluetooth connection. The WIFI list includes at least one WIFI identifier, which indicates the WIFI that terminal 201 can currently identify. Control terminal 202 is further configured to, upon receiving the WIFI list, in response to a user operation, determine a target WIFI identifier and a target key corresponding to the target WIFI identifier from the at least one WIFI identifier, encrypt the target WIFI identifier and the target key based on a dynamic communication key, generate a network configuration encryption message, and send the network configuration encryption message to terminal 201. Terminal 201 is further configured to, upon receiving the network configuration encryption message, decrypt the network configuration encryption message based on the dynamic communication key, and access the target WIFI network corresponding to the target WIFI identifier based on the target WIFI identifier and the target key in the network configuration encryption message.
[0099] Optionally, after establishing a Bluetooth connection with the control terminal 202, the terminal 201 can scan for surrounding Wi-Fi to determine the currently identifiable Wi-Fi and generate a Wi-Fi list.
[0100] In some embodiments, when sending a WIFI list, if the terminal 201 currently stores a dynamic communication key, it can also encrypt the WIFI list based on the dynamic communication key before sending it to the control terminal 202.
[0101] After receiving the WIFI list, the control terminal 202 can display the WIFI list. If the control terminal 202 is an APP in an electronic device, the WIFI list can be displayed on the APP page. Based on the WIFI list, the user can determine the target WIFI identifier from at least one WIFI identifier in the list and enter the target key corresponding to the target WIFI identifier, that is, the WIFI password required to access the target WIFI network corresponding to the target WIFI identifier.
[0102] The control terminal 202 can determine the target WIFI identifier and target key based on the user's selection and input, and encrypt the target WIFI identifier and target key through a dynamic communication key to generate a network configuration encrypted message. The control terminal 202 then sends the network configuration encrypted message to the terminal 201 through a Bluetooth connection with the terminal 201.
[0103] Optionally, if terminal 201, after successfully decrypting the network configuration encryption message, is unable to access the target Wi-Fi network corresponding to the target Wi-Fi identifier based on the target Wi-Fi identifier and target key in the network configuration encryption message, such as due to user error causing a mismatch between the target Wi-Fi identifier and the target key, then terminal 201 can send a network configuration failure message to control terminal 202 to indicate that it cannot currently connect to the target Wi-Fi network. Upon receiving the network configuration failure message, control terminal 202 can display the network configuration failure message and, in response to the user's subsequent operation, re-determine the target Wi-Fi identifier and the target key corresponding to the target Wi-Fi identifier until terminal 201 can access the target Wi-Fi network corresponding to the target Wi-Fi identifier.
[0104] In some embodiments, considering that an unstable Bluetooth connection between the control terminal 202 and the terminal 201 may also lead to transmission failure of the target Wi-Fi identifier and the corresponding target key, if the number of times the target Wi-Fi identifier and the corresponding target key are re-determined exceeds the target number, in order to improve the user experience and avoid the user needing to frequently select the target Wi-Fi identifier and enter the target key due to Bluetooth connection problems, the control terminal 202 can disconnect the Bluetooth connection with the terminal 201 and re-establish a Bluetooth connection with the terminal 201. Specific Bluetooth connection methods can be found in the relevant descriptions above and will not be repeated here.
[0105] In some embodiments, the signal timing diagram for enabling WIFI network access between terminal 201 and control terminal 202 can be as follows: Figure 4 As shown. Combined with Figure 4When terminal 201 establishes a Bluetooth connection with control terminal 202, it scans for nearby Wi-Fi networks to generate a Wi-Fi list (WIFI List) and sends it to control terminal 202 via Bluetooth. In response to the user's operation, control terminal 202 determines the target Wi-Fi identifier (SSID) and its corresponding target key (password), and encrypts the SSID and password using a dynamic communication key (dkey) to generate a network configuration encryption message (wData), where wData = AES_Enc(dkey, SSID + password), i.e., the SSID and password encrypted based on dkey. Control terminal 202 sends wData to terminal 201. Upon receiving wData, terminal 201 decrypts it based on dkey. If decryption is successful, the SSID and password are obtained, and the terminal uses them to access the network and complete network configuration. If decryption fails, meaning terminal 201 cannot successfully decrypt the network configuration encryption message using the dynamic communication key, terminal 201 determines that control terminal 202 is an abnormal control terminal and directly disconnects the Bluetooth connection with control terminal 202.
[0106] In some embodiments, such as Figure 4 As shown, if a Bluetooth connection is established between terminal 201 and control terminal 202, and terminal 201 receives wData, if terminal 201 cannot successfully decrypt wData based on dkey, then the current control terminal 202 can be considered an abnormal control terminal, and the Bluetooth connection between the control terminal 202 and control terminal 202 can be disconnected.
[0107] Additionally, in some embodiments, such as Figure 5 As shown, the terminal network configuration system also includes a cloud platform 203 corresponding to the control terminal 202. The control terminal 202, upon receiving Bluetooth broadcast data, sends the Bluetooth broadcast data to the cloud platform 203. The cloud platform 203, upon receiving the Bluetooth broadcast data, determines the terminal private key corresponding to terminal 201 from at least one stored private key based on the identifier of terminal 201, decrypts a first encrypted message based on the terminal private key, generates a dynamic communication key, generates a second secret message based on the first encrypted message encrypted and decrypted using the terminal private key and the dynamic communication key, and sends the second encrypted message and the dynamic communication key to the control terminal 202. The control terminal 202 is also used to receive the second encrypted message and the dynamic communication key.
[0108] The cloud platform 203 corresponding to the control terminal 202 can be understood as a set of cloud infrastructure and services specified by the manufacturer and used in conjunction with the control terminal 202. For example, in this embodiment, the control terminal 202 can use the cloud platform 203 to verify the Bluetooth broadcast data sent by the terminal 201 to obtain a second encrypted message, and to obtain a dynamic communication key.
[0109] In some embodiments, in conjunction with the above description of establishing a Bluetooth connection between terminal 201 and control terminal 202 in scenarios with different methods of generating the first encrypted message, the decryption method of the cloud platform 203 for decrypting the first encrypted message and the generation method for generating the second encrypted message will also differ for the first encrypted message generated in different ways.
[0110] For example, if the first encrypted message is an encrypted message generated by terminal 201 based on its private key, then cloud platform 203 can decrypt the first encrypted message based on the private key corresponding to terminal 201, and in response to successfully decrypting the first encrypted message, generate a second encrypted message based on the private key corresponding to terminal 201, i.e., scenario 1 above; if the first encrypted message is an encrypted message generated by terminal 201 based on its public key, then cloud platform 203 can decrypt the first encrypted message based on its public key, and in response to successfully decrypting the first encrypted message, generate a second encrypted message based on the private key corresponding to terminal 201, i.e., scenario 2 above; if the first encrypted message is an encrypted message generated by terminal 201 based on its first private key, then cloud platform 203 can decrypt the first encrypted message based on the first private key corresponding to terminal 201, and in response to successfully decrypting the first encrypted message, generate a second encrypted message based on the second private key corresponding to terminal 201, i.e., scenario 3 above.
[0111] Therefore, this section only uses the scenario where the first encrypted message is an encrypted message generated by terminal 201 based on its private key as an example to illustrate the generation process of the second encrypted message by cloud platform 203, and the implementation process of establishing a Bluetooth connection between terminal 201 and control terminal 202 through cloud platform 203. For other scenarios, the generation process of the second encrypted message and the implementation process of establishing a Bluetooth connection between terminal 201 and control terminal 202 through cloud platform 203 can be referred to the implementation process of establishing a Bluetooth connection between terminal 201 and control terminal 202 through the authentication module in the corresponding scenarios described above, and will not be repeated here.
[0112] Optionally, the cloud platform 203 may store a mapping table indicating terminal identifiers and terminal private keys, as well as at least one terminal private key. After receiving Bluetooth broadcast data, the cloud platform 203 may determine the terminal private key corresponding to terminal 201 by querying the mapping table based on the identifier of terminal 201.
[0113] In some embodiments, if the cloud platform 203 cannot determine the terminal private key based on the identifier of the terminal 201, or if the determined terminal private key cannot successfully decrypt the first encrypted message, it indicates that the terminal 201 is an abnormal terminal. In this case, the cloud platform 203 can return a verification failure message to the control terminal 202, indicating that the Bluetooth broadcast data corresponding to the terminal 201 cannot be successfully verified. After receiving the verification failure message returned by the cloud platform 203, the control terminal 202 will not establish a Bluetooth connection with the terminal 201, that is, it will not send a Bluetooth connection request to the terminal 201. For detailed verification procedures, please refer to the relevant description of the authentication module above, which will not be repeated here.
[0114] Optionally, the cloud platform 203 can determine and modify the generation method of the dynamic communication key based on actual usage needs, such as selecting the key generation algorithm based on the generation time or the number of times the dynamic communication key has been generated. For example, when generating a dynamic communication key for the first time, the cloud platform 203 can generate the dynamic communication key based on key generation algorithm A, and the next time it generates a dynamic communication key, it can generate it based on key generation algorithm B. In this way, the generation method of the dynamic communication key can be changed arbitrarily according to actual usage needs. At the control terminal 202 and terminal 201, it is impossible to determine how the dynamic communication key was generated; they can only receive and store the dynamic communication key, and then use it to achieve encrypted data transmission, thereby improving the security of the dynamic communication key.
[0115] In some embodiments, the signal timing diagram for achieving Bluetooth connection and dynamic communication key synchronization between terminal 201, control terminal 202, and cloud platform 203 can be as follows: Figure 6 As shown. Combined with Figure 6After powering on, terminal 201 continuously sends Bluetooth broadcast data bData, which carries the identifier dId of terminal 201 and a first encrypted message AES_ENC(pkey) generated based on the terminal's private key pkey. Upon receiving bData, control terminal 202 sends it to cloud platform 203, requesting verification. Upon receiving bData, cloud platform 203 determines the terminal's private key pkey based on dId and decrypts AES_ENC(pkey) based on pkey. If decryption is successful, it randomly generates a dynamic communication key dkey. The pkey is used to encrypt the dkey to generate a second encrypted message encData(pkey, dkey), and the dkey and encData are sent to the control terminal 202. After receiving the dkey and encData, the control terminal 202 stores the dkey and sends the encData to the terminal 201, requesting to establish a Bluetooth connection with the terminal 201. After receiving the encData, the terminal 201 decrypts the encData based on the pkey. If the decryption is successful, the terminal stores the dkey and establishes a Bluetooth connection with the control terminal 202. If the decryption fails, the terminal refuses to establish a Bluetooth connection with the control terminal 202.
[0116] Optionally, such as Figure 6 As shown, after receiving bData, if the cloud platform 203 cannot decrypt AES_ENC(pkey) based on pkey, it returns a verification failure message to the control terminal 202; upon receiving the verification failure message, the control terminal 202 does not send a Bluetooth connection request to the terminal 201.
[0117] In some scenarios, the cloud platform 203 can also be used solely for verifying Bluetooth broadcast data. For example, after receiving Bluetooth broadcast data sent by the terminal 201, the control terminal 202 can send the Bluetooth broadcast data to the cloud platform 203. Based on the identifier of the terminal 201, the cloud platform 203 determines the terminal key corresponding to the terminal 201, uses the terminal key to decrypt the first encrypted message in the Bluetooth broadcast data, generates a second encrypted message based on the terminal key, and sends the second encrypted message to the control terminal 202.
[0118] The signal timing diagram in this scenario can be as follows: Figure 7 As shown. Combined with Figure 7After powering on, terminal 201 continuously sends Bluetooth broadcast data bData, which carries the identifier dId of terminal 201 and a first encrypted message AES_ENC(pkey) generated based on the terminal's private key pkey. Upon receiving bData, control terminal 202 sends bData to cloud platform 203, requesting verification. Upon receiving bData, cloud platform 203 determines the terminal's private key pkey based on dId and decrypts AES_ENC(pkey) based on pkey. If decryption is successful, it generates a second encrypted message encData(pkey) based on pkey and sends encData to control terminal 202. Upon receiving encData, control terminal 202 sends encData to terminal 201, requesting to establish a Bluetooth connection with terminal 201. Upon receiving encData, terminal 201 decrypts encData based on pkey. If decryption is successful, it establishes a Bluetooth connection with control terminal 202; if decryption fails, it refuses to establish a Bluetooth connection with control terminal 202.
[0119] Optionally, such as Figure 7 As shown, after receiving bData, if the cloud platform 203 cannot decrypt AES_ENC(pkey) based on pkey, it returns a verification failure message to the control terminal 202; upon receiving the verification failure message, the control terminal 202 does not send a Bluetooth connection request to the terminal 201.
[0120] In some embodiments, the terminal 201 is further configured to delete the stored dynamic communication key after accessing the target WIFI network, and send a network access success message to the control terminal 202 through the target WIFI network; the control terminal 202 is further configured to delete the stored dynamic communication key upon receiving the network access success message.
[0121] It should be noted that after the terminal 201 connects to the target WIFI network, since the transmission of privacy data such as the WIFI network key via Bluetooth is no longer involved, the terminal 201 can directly delete the stored dynamic communication key. When it is necessary to reconfigure the network or switch networks, it can re-receive the encrypted message carrying the dynamic communication key and obtain the dynamic communication key based on the encrypted message, thereby improving the security of the dynamic communication key.
[0122] Similarly, after terminal 201 connects to the target WIFI network, control terminal 202 can also delete the stored dynamic communication key, and when terminal 201 needs to reconfigure the network or switch networks, it can obtain the dynamic communication key and the encrypted message carrying the dynamic communication key again, so as to ensure that the dynamic communication key in each network configuration process is the latest dynamic communication key, and encrypt and transmit privacy data such as the key of the WIFI network based on the latest dynamic communication key to avoid the leakage of privacy data.
[0123] Optionally, after the terminal 201 connects to the target WIFI network, since it can communicate directly with the control terminal 202 through the network, the terminal 201 can disconnect the Bluetooth connection with the control terminal 202 and then communicate through the target WIFI network to reduce power consumption.
[0124] In some scenarios, considering that there may be multiple terminals 201, and the control terminal 202 may need to configure multiple terminals 201 in a short period of time, in order to avoid frequent acquisition of dynamic communication keys in a short period of time, the control terminal 202 can also periodically delete the stored dynamic communication keys. Within a period, such as within 4 hours, communication with the terminal 201 is achieved through a certain dynamic communication key, so as to reduce the frequency of communication interaction during the configuration process and improve the configuration efficiency of the terminal 201.
[0125] In some embodiments, the first encrypted message and the second encrypted message also carry a target timestamp, which is used to indicate the generation time of the first encrypted message. After receiving the second encrypted message, the terminal 201, upon successfully decrypting the second encrypted message and provided that the difference between the current time of the terminal 201 and the target timestamp in the second encrypted message is less than or equal to a target difference, establishes a Bluetooth connection with the control terminal 202 to access the WIFI network through the control terminal 202.
[0126] Optionally, terminal 201 may send a first encrypted message carrying a target timestamp, and the second encrypted message obtained by control terminal 202 may be an encrypted message generated after successfully decrypting the first encrypted message and re-encrypting the target timestamp based on the terminal's private key.
[0127] The difference between the target timestamp in the second encrypted message and the current time of terminal 201 can be understood as the total time taken from when terminal 201 sends the broadcast message data to when it receives the second encrypted message sent by control terminal 202. When this difference is greater than the target difference, it indicates that the verification time of this Bluetooth connection is too long, and there may be an anomaly, such as the second encrypted message being a replay attack by a malicious third party. In this case, even if terminal 201 can successfully decrypt the second encrypted message based on its private key, it will not establish a Bluetooth connection with control terminal 202.
[0128] It should be noted that a replay attack refers to a situation where, after the second encrypted message sent by the control terminal 202 is intercepted by malware, the malware sends the intercepted second encrypted message to the terminal 201 at a later time to request a Bluetooth connection. Since the encrypted message sent by the control terminal 202 is legitimate, the terminal 201 may consider this Bluetooth connection request from the malware to be a legitimate request from the control terminal 202 and establish a Bluetooth connection with the malware.
[0129] Optionally, this target difference can be determined based on actual usage requirements, such as parameters such as the type of terminal 201 and control terminal 202, and network conditions. For example, the target difference could be 60 seconds.
[0130] It should be noted that since terminal 201 continuously sends Bluetooth broadcast data, the target timestamp carried in the first encrypted message in each Bluetooth broadcast data sent by terminal 201 is different, and the target timestamp carried in each first encrypted message indicates the generation time of the first message.
[0131] To differentiate between target timestamps, the first encrypted message may also carry a message sequence number, used to distinguish first encrypted messages generated at different times. The second encrypted message can be an encrypted message generated based on the terminal key, encrypting the message sequence number and the target timestamp, after successfully decrypting the first encrypted message.
[0132] In some embodiments, the signal timing diagram for achieving Bluetooth connection and dynamic communication key synchronization between terminal 201 and control terminal 202 can be as follows: Figure 8 As shown. Combined with Figure 8After powering on, terminal 201 continuously sends Bluetooth broadcast data bData. This bData carries the identifier dId of terminal 201 and a first encrypted message AES_ENC(pkey, timeStamp) generated by encrypting the target timestamp timeStamp based on the terminal's private key pkey. Upon receiving bData, control terminal 202 obtains a second encrypted message encData(pkey, timeStamp) carrying the timeStamp and sends encData(pkey, timeStamp) to terminal 201 to request the establishment of a Bluetooth connection. After receiving encData(pkey, timeStamp), terminal 201 decrypts it based on pkey. If decryption is successful, it checks whether the difference between the current time curTime of terminal 201 and the timeStamp in encData(pkey, timeStamp) meets the target difference, such as whether curTime-timeStamp ≤ 60s. If yes, a Bluetooth connection is established with control terminal 202; otherwise, the establishment of a Bluetooth connection with control terminal 202 is refused.
[0133] In this embodiment, the terminal automatically sends Bluetooth broadcast data upon power-on to establish a Bluetooth connection with the control terminal without requiring active user control, thereby improving the user experience during network configuration. Furthermore, the Bluetooth broadcast message sent by the terminal carries an encrypted first encrypted message, and the terminal only establishes a Bluetooth connection with the control terminal upon receiving a specific second encrypted message. Since the second encrypted message can only be generated by the control terminal specified by the manufacturer using the corresponding cloud platform, only a specific control terminal can recognize and generate the corresponding second encrypted message, thus establishing a Bluetooth connection with the terminal through the second encrypted message. This improves the user experience while preventing malicious software from exploiting continuously sent Bluetooth broadcast data to preempt the Bluetooth connection with the terminal, enhancing the security of establishing a Bluetooth connection between the terminal and the control terminal.
[0134] Furthermore, when establishing a Bluetooth connection between the terminal and the control unit, a timestamp is set to limit the response time of the control unit sending the second encrypted message. If the response time of the control unit to obtain the second encrypted message based on the first encrypted message is too long, even if the second encrypted message meets the requirements for establishing a Bluetooth connection between the control unit and the terminal, the terminal will not establish a Bluetooth connection with the control unit. This is to prevent malicious software from preempting the terminal's Bluetooth connection due to abnormal behaviors such as replay attacks, thereby further improving the security of the Bluetooth connection process.
[0135] Furthermore, the cloud platform can randomly generate dynamic communication keys and send them to the control terminal, as well as send the same dynamic communication key from the control terminal to the terminal via a second encrypted message, thereby synchronizing the dynamic communication keys between the terminal and the control terminal during communication. This has two advantages: First, when the control terminal transmits private data such as Wi-Fi passwords to the terminal, encryption can be achieved using the dynamic communication key. Since this dynamic communication key is neither built into the control terminal nor the terminal, but is randomly generated by the cloud platform, it increases the difficulty for malicious software to obtain it, thus improving the security of private data transmission. Second, when the control terminal transmits the dynamic communication key to the terminal, because this key is transmitted via a second encrypted message, and the key required to decrypt this second encrypted message—the terminal's private key—is not involved in the communication between the terminal and the control terminal, and the control terminal does not record the terminal's corresponding private key, the security of the dynamic communication key during transmission is further enhanced.
[0136] Those skilled in the art should understand that the above-mentioned terminals, control terminals, and cloud platforms are merely examples. Other existing or future terminals, control terminals, or cloud platforms that are applicable to the embodiments of this application should also be included within the scope of protection of the embodiments of this application, and are hereby incorporated by reference.
[0137] It should be noted that the application scenarios and implementation environments described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the emergence of new application scenarios and the evolution of implementation environments, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0138] Figure 9 This is a flowchart illustrating a terminal network configuration method provided in an embodiment of this application. The method is applied to a terminal network configuration system, which includes a control terminal and terminals. Please refer to... Figure 9 The terminal network configuration method may include the following steps.
[0139] Step 901: After powering on, the terminal continuously sends Bluetooth broadcast data, which carries the first encrypted message.
[0140] Step 902: After receiving the Bluetooth broadcast data, the control terminal obtains the second encrypted message, which is generated in response to the successful decryption of the first encrypted message.
[0141] Step 903: After receiving the second encrypted message, the terminal establishes a Bluetooth connection with the control terminal after successfully decrypting the second encrypted message, so as to access the WIFI network through the control terminal.
[0142] Optionally, the method further includes: the control terminal acquiring and storing a dynamic communication key when acquiring the second encrypted message, the second encrypted message also carrying the dynamic communication key, the dynamic communication key being generated in a random manner; the terminal storing the dynamic communication key when successfully decrypting the second encrypted message; wherein the dynamic communication key is used for communication between the terminal and the control terminal to enable the terminal to access the WIFI network through the control terminal.
[0143] Optionally, the method further includes: when the terminal establishes a Bluetooth connection with the control terminal, obtaining a WIFI list and sending the WIFI list to the control terminal via the Bluetooth connection, the WIFI list includes at least one WIFI identifier, which is used to indicate the WIFI that the terminal can currently identify; after receiving the WIFI list, the control terminal, in response to the user's operation, determines the target WIFI identifier and the target key corresponding to the target WIFI identifier from the at least one WIFI identifier, encrypts the target WIFI identifier and the target key based on a dynamic communication key, generates a network allocation encrypted message, and sends the network allocation encrypted message to the terminal; after receiving the network allocation encrypted message, the terminal decrypts the network allocation encrypted message based on the dynamic communication key, and accesses the target WIFI network corresponding to the target WIFI identifier based on the target WIFI identifier and the target key in the network allocation encrypted message.
[0144] Optionally, the system also includes a cloud platform corresponding to the terminal, and the method further includes: after receiving Bluetooth broadcast data, the control terminal sends the Bluetooth broadcast data to the cloud platform; after receiving the Bluetooth broadcast data, the cloud platform determines the terminal private key corresponding to the terminal from at least one stored private key based on the terminal's identifier, decrypts the first encrypted message based on the terminal private key, generates a dynamic communication key, generates a second encrypted message based on the first encrypted message encrypted and decrypted by the terminal private key and the dynamic communication key, and sends the second encrypted message and the dynamic communication key to the control terminal; the control terminal receives the second encrypted message and the dynamic communication key.
[0145] Optionally, the method further includes: after the terminal accesses the target WIFI network, it deletes the stored dynamic communication key and sends a network access success message to the control terminal through the target WIFI network; upon receiving the network access success message, the control terminal deletes the stored dynamic communication key.
[0146] Optionally, the first encrypted message and the second encrypted message also carry a target timestamp, which is used to indicate the generation time of the first encrypted message; the method further includes: after receiving the second encrypted message, if the terminal successfully decrypts the second encrypted message and the difference between the terminal's current time and the target timestamp in the second encrypted message is less than or equal to the target difference, the terminal establishes a Bluetooth connection with the control terminal to access the WIFI network through the control terminal.
[0147] In this embodiment, the terminal automatically sends Bluetooth broadcast data upon power-on to establish a Bluetooth connection with the control terminal without requiring active user control, thereby improving the user experience during network configuration. Furthermore, the Bluetooth broadcast message sent by the terminal carries an encrypted first encrypted message, and the terminal only establishes a Bluetooth connection with the control terminal upon receiving a specific second encrypted message. Since the second encrypted message can only be generated by the control terminal specified by the manufacturer using the corresponding cloud platform, only a specific control terminal can recognize and generate the corresponding second encrypted message, thus establishing a Bluetooth connection with the terminal through the second encrypted message. This improves the user experience while preventing malicious software from exploiting continuously sent Bluetooth broadcast data to preempt the Bluetooth connection with the terminal, enhancing the security of establishing a Bluetooth connection between the terminal and the control terminal.
[0148] Furthermore, when establishing a Bluetooth connection between the terminal and the control unit, a timestamp is set to limit the response time of the control unit sending the second encrypted message. If the response time of the control unit to obtain the second encrypted message based on the first encrypted message is too long, even if the second encrypted message meets the requirements for establishing a Bluetooth connection between the control unit and the terminal, the terminal will not establish a Bluetooth connection with the control unit. This is to prevent malicious software from preempting the terminal's Bluetooth connection due to abnormal behaviors such as replay attacks, thereby further improving the security of the Bluetooth connection process.
[0149] Furthermore, the cloud platform can randomly generate dynamic communication keys and send them to the control terminal, as well as send the same dynamic communication key from the control terminal to the terminal via a second encrypted message, thereby synchronizing the dynamic communication keys between the terminal and the control terminal during communication. This has two advantages: First, when the control terminal transmits private data such as Wi-Fi passwords to the terminal, encryption can be achieved using the dynamic communication key. Since this dynamic communication key is neither built into the control terminal nor the terminal, but is randomly generated by the cloud platform, it increases the difficulty for malicious software to obtain it, thus improving the security of private data transmission. Second, when the control terminal transmits the dynamic communication key to the terminal, because this key is transmitted via a second encrypted message, and the key required to decrypt this second encrypted message—the terminal's private key—is not involved in the communication between the terminal and the control terminal, and the control terminal does not record the terminal's corresponding private key, the security of the dynamic communication key during transmission is further enhanced.
[0150] Figure 10 This is a structural block diagram of a terminal 1000 provided in an embodiment of this application. Typically, the terminal 1000 includes a processor 1001 and a memory 1002.
[0151] Processor 1001 may include one or more processing cores, such as a quad-core processor, an octa-core processor, etc. Processor 1001 may be implemented using at least one hardware form selected from DSP (Digital Signal Processing), FPGA (Field Programmable Gate Array), and PLA (Programmable Logic Array). Processor 1001 may also include a main processor and a coprocessor. The main processor, also known as a CPU (Central Processing Unit), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, processor 1001 may integrate a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the screen. In some embodiments, processor 1001 may also include an AI (Artificial Intelligence) processor, which is used to handle computational operations related to machine learning.
[0152] The memory 1002 may include one or more computer-readable storage media, which may be non-transitory. The memory 1002 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices or flash memory devices. In some embodiments, the non-transitory computer-readable storage media in the memory 1002 is used to store at least one instruction, which is executed by the processor 1001 to establish a connection with a control terminal and access a Wi-Fi network via the control terminal.
[0153] In some embodiments, the terminal 1000 may also optionally include a peripheral device interface 1003 and at least one peripheral device. The processor 1001, memory 1002, and peripheral device interface 1003 can be connected via a bus or signal line. Each peripheral device can be connected to the peripheral device interface 1003 via a bus, signal line, or circuit board. Specifically, the peripheral device includes at least one of the following: a radio frequency circuit 1004, a display screen 1005, a camera assembly 1006, an audio circuit 1007, a positioning assembly 1008, and a power supply 1009.
[0154] Peripheral device interface 1003 can be used to connect at least one I / O (Input / Output) related peripheral device to processor 1001 and memory 1002. In some embodiments, processor 1001, memory 1002 and peripheral device interface 1003 are integrated on the same chip or circuit board; in some other embodiments, any one or two of processor 1001, memory 1002 and peripheral device interface 1003 can be implemented on separate chips or circuit boards, which is not limited in this embodiment.
[0155] The radio frequency (RF) circuit 1004 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The RF circuit 1004 communicates with communication networks and other communication devices via electromagnetic signals. The RF circuit 1004 converts electrical signals into electromagnetic signals for transmission, or converts received electromagnetic signals back into electrical signals. Optionally, the RF circuit 1004 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a user identity module card, etc. The RF circuit 1004 can communicate with other terminals via at least one wireless communication protocol. This wireless communication protocol includes, but is not limited to: the World Wide Web, metropolitan area networks, intranets, various generations of mobile communication networks (2G, 3G, 4G, and 5G), wireless local area networks, and / or WiFi (Wireless Fidelity) networks. In some embodiments, the RF circuit 1004 may also include circuitry related to NFC (Near Field Communication), which is not limited in this application embodiment.
[0156] Display screen 1005 is used to display a UI (User Interface). The UI may include graphics, text, icons, videos, and any combination thereof. When display screen 1005 is a touch display screen, it also has the ability to collect touch signals on or above its surface. These touch signals can be input as control signals to processor 1001 for processing. In this case, display screen 1005 can also be used to provide virtual buttons and / or a virtual keyboard, also known as soft buttons and / or a soft keyboard. In some embodiments, there may be one display screen 1005, serving as the front panel of terminal 1000; in other embodiments, there may be at least two display screens, respectively disposed on different surfaces of terminal 1000 or in a folded design; in still other embodiments, display screen 1005 may be a flexible display screen, disposed on a curved or folded surface of terminal 1000. Furthermore, display screen 1005 may also be configured as a non-rectangular, irregular shape, i.e., a non-rectangular screen. The display screen 1005 can be made of materials such as LCD (Liquid Crystal Display) and OLED (Organic Light-Emitting Diode).
[0157] The camera assembly 1006 is used to acquire images or videos. Optionally, the camera assembly 1006 includes a front-facing camera and a rear-facing camera. Typically, the front-facing camera is located on the front panel of the terminal, and the rear-facing camera is located on the back of the terminal. In some embodiments, there are at least two rear-facing cameras, which are any one of a main camera, a depth-sensing camera, a wide-angle camera, and a telephoto camera, to achieve background blurring by fusion of the main camera and the depth-sensing camera, panoramic shooting by fusion of the main camera and the wide-angle camera, VR (Virtual Reality) shooting, or other fusion shooting functions. In some embodiments, the camera assembly 1006 may also include a flash. The flash can be a single-color temperature flash or a dual-color temperature flash. A dual-color temperature flash refers to a combination of a warm-light flash and a cool-light flash, which can be used for light compensation at different color temperatures.
[0158] The audio circuit 1007 may include a microphone and a speaker. The microphone is used to collect sound waves from the user and the environment, converting the sound waves into electrical signals that are input to the processor 1001 for processing, or input to the radio frequency circuit 1004 for voice communication. For stereo sound acquisition or noise reduction purposes, multiple microphones may be used, each positioned at a different location on the terminal 1000. The microphone may also be an array microphone or an omnidirectional microphone. The speaker is used to convert electrical signals from the processor 1001 or the radio frequency circuit 1004 into sound waves. The speaker may be a conventional diaphragm speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can convert electrical signals not only into audible sound waves but also into inaudible sound waves for purposes such as distance measurement. In some embodiments, the audio circuit 1007 may also include a headphone jack.
[0159] The positioning component 1008 is used to determine the current geographical location of the terminal 1000 in order to enable navigation or LBS (Location Based Service). The positioning component 1008 can be a positioning component of GPS (Global Positioning System), BeiDou system, or Galileo system.
[0160] Power supply 1009 is used to power the various components in terminal 1000. Power supply 1009 can be AC power, DC power, a disposable battery, or a rechargeable battery. When power supply 1009 includes a rechargeable battery, the rechargeable battery can be a wired rechargeable battery or a wireless rechargeable battery. A wired rechargeable battery is a battery that is charged via a wired line, and a wireless rechargeable battery is a battery that is charged via a wireless coil. The rechargeable battery can also be used to support fast charging technology.
[0161] In some embodiments, the terminal 1000 further includes one or more sensors 1010. The one or more sensors 1010 include, but are not limited to: an accelerometer 1011, a gyroscope 1012, a pressure sensor 1013, a fingerprint sensor 1014, an optical sensor 1015, and a proximity sensor 1016.
[0162] Accelerometer 1011 can detect the magnitude of acceleration along the three coordinate axes of a coordinate system established by terminal 1000. For example, accelerometer 1011 can be used to detect the components of gravitational acceleration along the three coordinate axes. Processor 1001 can control touchscreen 1005 to display the user interface in landscape or portrait view based on the gravitational acceleration signal acquired by accelerometer 1011. Accelerometer 1011 can also be used for games or for acquiring user motion data.
[0163] The gyroscope sensor 1012 can detect the orientation and rotation angle of the terminal 1000. The gyroscope sensor 1012, in conjunction with the accelerometer sensor 1011, can collect 3D motion data from the user on the terminal 1000. Based on the data collected by the gyroscope sensor 1012, the processor 1001 can perform the following functions: motion sensing (e.g., changing the UI based on the user's tilt), image stabilization during shooting, game control, and inertial navigation.
[0164] The pressure sensor 1013 can be disposed on the side bezel of the terminal 1000 and / or on the lower layer of the touch display screen 1005. When the pressure sensor 1013 is disposed on the side bezel of the terminal 1000, it can detect the user's grip signal on the terminal 1000, and the processor 1001 can perform left / right hand recognition or quick operation based on the grip signal collected by the pressure sensor 1013. When the pressure sensor 1013 is disposed on the lower layer of the touch display screen 1005, the processor 1001 can control the operable controls on the UI interface based on the user's pressure operation on the touch display screen 1005. The operable controls include at least one of button controls, scroll bar controls, icon controls, and menu controls.
[0165] The fingerprint sensor 1014 is used to collect a user's fingerprint. The processor 1001 identifies the user based on the fingerprint collected by the fingerprint sensor 1014, or vice versa. When the user's identity is identified as trusted, the processor 1001 authorizes the user to perform relevant sensitive operations, including unlocking the screen, viewing encrypted information, downloading software, making payments, and changing settings. The fingerprint sensor 1014 can be located on the front, back, or side of the terminal 1000. When the terminal 1000 has physical buttons or a manufacturer's logo, the fingerprint sensor 1014 can be integrated with the physical buttons or manufacturer's logo.
[0166] An optical sensor 1015 is used to collect ambient light intensity. In one embodiment, the processor 1001 can control the display brightness of the touch screen 1005 based on the ambient light intensity collected by the optical sensor 1015. Specifically, when the ambient light intensity is high, the display brightness of the touch screen 1005 is increased; when the ambient light intensity is low, the display brightness of the touch screen 1005 is decreased. In another embodiment, the processor 1001 can also dynamically adjust the shooting parameters of the camera assembly 1006 based on the ambient light intensity collected by the optical sensor 1015.
[0167] The proximity sensor 1016, also known as a distance sensor, is typically mounted on the front panel of the terminal 1000. The proximity sensor 1016 is used to detect the distance between the user and the front of the terminal 1000. In one embodiment, when the proximity sensor 1016 detects that the distance between the user and the front of the terminal 1000 is gradually decreasing, the processor 1001 controls the touchscreen display 1005 to switch from a screen-on state to a screen-off state; when the proximity sensor 1016 detects that the distance between the user and the front of the terminal 1000 is gradually increasing, the processor 1001 controls the touchscreen display 1005 to switch from a screen-off state to a screen-on state.
[0168] Those skilled in the art will understand that Figure 10 The structure shown does not constitute a limitation on terminal 1000 and may include more or fewer components than shown, or combine certain components, or use different component arrangements.
[0169] Figure 11 This is a schematic diagram of the structure of a cloud platform provided in an embodiment of this application. The cloud platform 1100 includes a central processing unit (CPU) 1101, a system memory 1104 including random access memory (RAM) 1102 and read-only memory (ROM) 1103, and a system bus 1105 connecting the system memory 1104 and the central processing unit 1101. The cloud platform 1100 also includes a basic input / output system (I / O system) 1106 that facilitates the transmission of information between various devices within the computer, and a mass storage device 1107 for storing the operating system 1113, application programs 1114, and other program modules 1115.
[0170] The basic input / output system 1106 includes a display 1108 for displaying information and an input device 1109 for user input, such as a mouse or keyboard. Both the display 1108 and the input device 1109 are connected to the central processing unit 1101 via an input / output controller 1110 connected to the system bus 1105. The basic input / output system 1106 may also include the input / output controller 1110 for receiving and processing input from multiple other devices such as a keyboard, mouse, or electronic stylus. Similarly, the input / output controller 1110 also provides output to a display screen, printer, or other types of output devices.
[0171] Mass storage device 1107 is connected to central processing unit 1101 via a mass storage controller (not shown) connected to system bus 1105. Mass storage device 1107 and its associated computer-readable media provide non-volatile storage for cloud platform 1100. That is, mass storage device 1107 may include computer-readable media (not shown) such as hard disk or CD-ROM drive.
[0172] Without loss of generality, computer-readable media can include computer storage media and communication media. Computer storage media include volatile and non-volatile, removable and non-removable media implemented using any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer storage media include RAM, ROM, EPROM, EEPROM, flash memory or other solid-state storage technologies, CD-ROM, DVD or other optical storage, magnetic tape cassettes, magnetic tape, disk storage, or other magnetic storage devices. Of course, those skilled in the art will recognize that computer storage media are not limited to the above-mentioned types. The system memory 1104 and mass storage device 1107 described above can be collectively referred to as memory.
[0173] According to various embodiments of this application, the cloud platform 1100 can also be connected to a remote computer on a network, such as the Internet. That is, the cloud platform 1100 can be connected to the network 1112 via the network interface unit 1111 connected to the system bus 1105, or the network interface unit 1111 can be used to connect to other types of networks or remote computer systems (not shown).
[0174] The aforementioned memory also includes one or more programs, which are stored in the memory and configured to be executed by the CPU.
[0175] It should be understood that "at least one" as mentioned herein refers to one or more, and "multiple" refers to two or more. In the description of the embodiments of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B; "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. In addition, in order to clearly describe the technical solutions of the embodiments of this application, the terms "first," "second," etc., are used in the embodiments of this application to distinguish identical or similar items with substantially the same function and effect. Those skilled in the art will understand that the terms "first," "second," etc., do not limit the quantity or execution order, and the terms "first," "second," etc., are not necessarily different.
[0176] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, data stored, data displayed, etc.) and signals involved in the embodiments of this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0177] The above descriptions are embodiments provided in this application and are not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A terminal distribution network system, characterized in that, The system includes a terminal and a control terminal; The terminal is configured to continuously send Bluetooth broadcast data after power-on, the Bluetooth broadcast data carrying a first encrypted message; The control terminal is used to obtain a second encrypted message after receiving the Bluetooth broadcast data. The second encrypted message is generated in response to the successful decryption of the first encrypted message. The terminal is further configured to establish a Bluetooth connection with the control terminal after receiving the second encrypted message and successfully decrypting the second encrypted message, so as to access the WIFI network through the control terminal.
2. The system as described in claim 1, characterized in that, The control terminal is also used to acquire and store a dynamic communication key when acquiring the second encrypted message. The second encrypted message also carries the dynamic communication key, which is generated in a random manner. The terminal is also used to store the dynamic communication key if the second encrypted message is successfully decrypted; The dynamic communication key is used for communication between the terminal and the control terminal, so as to enable the terminal to access the WIFI network through the control terminal.
3. The system as described in claim 2, characterized in that, The terminal is also used to obtain a WIFI list when a Bluetooth connection is established with the control terminal, and send the WIFI list to the control terminal via the Bluetooth connection. The WIFI list includes at least one WIFI identifier, which is used to indicate the WIFI that the terminal can currently identify. The control terminal is further configured to, after receiving the WIFI list, respond to the user's operation, determine the target WIFI identifier and the target key corresponding to the target WIFI identifier from the at least one WIFI identifier, encrypt the target WIFI identifier and the target key based on the dynamic communication key, generate a network configuration encryption message, and send the network configuration encryption message to the terminal; The terminal is further configured to, upon receiving the network encryption message, decrypt the network encryption message based on the dynamic communication key, and access the target WIFI network corresponding to the target WIFI identifier based on the target WIFI identifier and the target key in the network encryption message.
4. The system as described in claim 2, characterized in that, The system also includes a cloud platform corresponding to the control terminal; The control terminal is used to send the Bluetooth broadcast data to the cloud platform after receiving the Bluetooth broadcast data; The cloud platform is configured to, upon receiving the Bluetooth broadcast data, determine the terminal private key corresponding to the terminal from at least one stored private key based on the terminal's identifier, decrypt the first encrypted message based on the terminal private key, generate the dynamic communication key, encrypt the decrypted first encrypted message and the dynamic communication key based on the terminal private key, generate the second encrypted message, and send the second encrypted message and the dynamic communication key to the control terminal. The control terminal is also used to receive the second encrypted message and the dynamic communication key.
5. The system as described in claim 2, characterized in that, The terminal is also used to delete the stored dynamic communication key after accessing the target WIFI network, and send a network access success message to the control terminal through the target WIFI network; The control terminal is also used to delete the stored dynamic communication key upon receiving the network access success message.
6. The system according to any one of claims 1-5, characterized in that, The first encrypted message and the second encrypted message also carry a target timestamp, which is used to indicate the generation time of the first encrypted message; The terminal is configured to establish a Bluetooth connection with the control terminal after receiving the second encrypted message, and if the second encrypted message is successfully decrypted and the difference between the current time of the terminal and the target timestamp in the second encrypted message is less than or equal to the target difference, so as to access the WIFI network through the control terminal.
7. A terminal network configuration method, characterized in that, The method is applied to a terminal distribution network system, the terminal distribution network system including a control terminal and terminals, and the method includes: The terminal continuously sends Bluetooth broadcast data after power-on, and the Bluetooth broadcast data carries a first encrypted message; After receiving the Bluetooth broadcast data, the control terminal obtains the second encrypted message, which is generated in response to the successful decryption of the first encrypted message. After receiving the second encrypted message, the terminal establishes a Bluetooth connection with the control terminal after successfully decrypting the second encrypted message, so as to access the WIFI network through the control terminal.
8. The method as described in claim 7, characterized in that, The method further includes: When the control terminal obtains the second encrypted message, it acquires and stores the dynamic communication key. The second encrypted message also carries the dynamic communication key, which is generated based on a random method. If the terminal successfully decrypts the second encrypted message, it stores the dynamic communication key. The dynamic communication key is used for communication between the terminal and the control terminal, so as to enable the terminal to access the WIFI network through the control terminal.
9. The method as described in claim 8, characterized in that, The method further includes: When the terminal establishes a Bluetooth connection with the control terminal, it obtains a WIFI list and sends the WIFI list to the control terminal via the Bluetooth connection. The WIFI list includes at least one WIFI identifier, which is used to indicate the WIFI that the terminal can currently recognize. After receiving the WIFI list, the control terminal responds to the user's operation by determining the target WIFI identifier and the target key corresponding to the target WIFI identifier from the at least one WIFI identifier, encrypting the target WIFI identifier and the target key based on the dynamic communication key, generating a network configuration encryption message, and sending the network configuration encryption message to the terminal. After receiving the encrypted distribution network message, the terminal decrypts the encrypted distribution network message based on the dynamic communication key, and accesses the target WIFI network corresponding to the target WIFI identifier based on the target WIFI identifier and the target key in the encrypted distribution network message.
10. The method as described in claim 8, characterized in that, The system also includes a cloud platform corresponding to the terminal, and the method further includes: After receiving the Bluetooth broadcast data, the control terminal sends the Bluetooth broadcast data to the cloud platform; After receiving the Bluetooth broadcast data, the cloud platform determines the terminal private key corresponding to the terminal from at least one stored private key based on the terminal's identifier, decrypts the first encrypted message based on the terminal private key, generates the dynamic communication key, encrypts the decrypted first encrypted message and the dynamic communication key based on the terminal private key, generates the second encrypted message, and sends the second encrypted message and the dynamic communication key to the control terminal. The control terminal receives the second encrypted message and the dynamic communication key.
Citation Information
Patent Citations
Bluetooth network and networking method
CN107231627A
Network matching method of wireless MESH network
CN108391238A
Double-platform adaptive method based on Bluetooth multilink
CN114745679A
Bluetooth low energy (BLE) advertising packet security
US20220408266A1
Access authentication method for bluetooth device, electronic device, and storage medium
WO2022027364A1