A method, apparatus, equipment, medium, and product for network distribution.
By using point-to-point connection and identity authentication in offline configuration mode, combined with dynamic tokens and public key information, the problem of configuration of smart home devices in offline environments is solved, realizing secure and reliable device configuration and synchronization, and improving user experience.
Patent Information
- Application Number
- CN202511564932.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-30
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2045-10-30
AI Technical Summary
Existing smart home device pairing methods cannot complete device binding and configuration in unstable or offline environments, resulting in a poor user experience and a lack of security authentication mechanisms, posing a risk of devices being maliciously bound.
The system adopts a network-free configuration mode, which receives the target device's dynamic token through a point-to-point connection and performs identity authentication by combining it with the pre-acquired public key information. After successful identity authentication, the system sends network configuration information, enabling the device to establish a connection with the cloud server when the current network is available. The system uses temporary session keys to ensure communication security and employs a local cache queue and incremental synchronization mechanism to synchronize configuration information.
Enables device network configuration in offline environments, improves user experience, reduces the risk of devices being maliciously bound, and ensures the ultimate consistency and security of configuration information.
Smart Images

Figure CN121037150B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of smart home technology, and in particular to a method, apparatus, equipment, medium, and product for device network configuration. Background Technology
[0002] With the development of smart home technology, smart home devices are being used more and more widely. When using smart home devices for the first time, it is usually necessary to configure the network for the smart home devices.
[0003] In existing technologies, configuring smart home devices typically relies on cloud servers. In environments with unstable or offline networks, device binding and configuration cannot be completed, resulting in a poor user experience. Furthermore, existing configuration methods lack security authentication mechanisms, posing a risk of devices being maliciously bound. Summary of the Invention
[0004] In view of the above problems, a method, apparatus, equipment, medium, and product for equipment distribution networks are proposed to overcome or at least partially solve the above problems, including:
[0005] A method for network configuration of devices, applied to terminal devices, the method comprising:
[0006] In offline distribution mode, a point-to-point connection is established with the target device;
[0007] Through a peer-to-peer connection, the system receives a dynamic token sent by the target device and, in combination with the dynamic token and pre-acquired public key information, authenticates the target device.
[0008] After successful identity authentication, network configuration information is sent to the target device so that the target device can apply the network configuration information and establish a connection with the cloud server when the current network is available.
[0009] Optionally, after successful authentication, network configuration information is sent to the target device to enable the target device to apply the network configuration information and establish a connection with the cloud server when the current network is available, including:
[0010] After successful identity authentication, a temporary session key is negotiated and established with the target device;
[0011] Based on the temporary session key, network configuration information is sent to the target device so that the target device can apply the network configuration information and establish a connection with the cloud server when the current network is available.
[0012] Optionally, in the offline distribution mode, a point-to-point connection is established with the target device, including:
[0013] In the offline network configuration mode, the beacon frame broadcast by the target device is received, and the identifier of the target device is added to the list of network-configurable devices of the terminal device according to the beacon frame;
[0014] In response to the user's selection of the identifier of the target device in the configurable network devices, a point-to-point connection is established with the target device.
[0015] Optionally, the beacon frame includes one or more of the following: the identifier of the target device, the capability set of the target device, and a dynamic token.
[0016] Optionally, the public key information is obtained by scanning the device QR code of the target device.
[0017] Optionally, after successful authentication, network configuration information is sent to the target device so that the target device applies the network configuration information and establishes a connection with the cloud server when the current network is available, the method further includes:
[0018] The network configuration information is stored in a local cache queue, and when the network is available, the changes in the local cache queue are sent to the cloud server through incremental synchronization.
[0019] Optionally, in the offline network configuration mode, before establishing a point-to-point connection with the target device, the following steps are also included:
[0020] Detect the current network status and, if there is no network, enter the no-network configuration mode.
[0021] Optionally, the target device is a smart home device.
[0022] A device for network distribution, applied to terminal equipment, the device comprising:
[0023] The point-to-point connection establishment module is used to establish a point-to-point connection with the target device in the offline network configuration mode.
[0024] The identity authentication module is used to receive a dynamic token sent by the target device through a peer-to-peer connection, and to authenticate the target device by combining the dynamic token with pre-acquired public key information.
[0025] The device configuration module is used to send network configuration information to the target device after successful identity authentication, so that the target device can apply the network configuration information and establish a connection with the cloud server when the current network is available.
[0026] An electronic device includes a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, implements the method described above.
[0027] A computer-readable storage medium on which a computer program is stored, which, when executed by a processor, implements the method described above.
[0028] A computer program product includes a computer program that, when executed by a processor, implements the method described above.
[0029] The embodiments of the present invention have the following advantages:
[0030] In this embodiment of the invention, a point-to-point connection is established with the target device in a network-free configuration mode. Through the point-to-point connection, a dynamic token sent by the target device is received. The target device is then authenticated by combining the dynamic token with pre-acquired public key information. After successful authentication, network configuration information is sent to the target device so that the target device can apply the network configuration information and establish a connection with the cloud server when the current network is available. This enables network configuration of devices in a network-free environment, improves the user experience, and allows for device authentication, reducing the risk of malicious binding of devices. Attached Figure Description
[0031] To more clearly illustrate the technical solution of the present invention, the accompanying drawings used in the description of the present invention will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0032] Figure 1 This is a flowchart of the steps of a device network distribution method provided in some embodiments of the present invention;
[0033] Figure 2 This is a flowchart of the steps of a second method for equipment network distribution provided in some embodiments of the present invention;
[0034] Figure 3 This is a flowchart of the steps of a third method for equipment network distribution provided in some embodiments of the present invention;
[0035] Figure 4 This is a flowchart of the steps of a device network distribution method according to some embodiments of the present invention;
[0036] Figure 5 This is a flowchart of the steps in a method for equipment network distribution provided in some embodiments of the present invention;
[0037] Figure 6 This is a flowchart of the steps of a device network distribution method according to some embodiments of the present invention;
[0038] Figure 7 This is a structural block diagram of a device for equipment distribution network provided in some embodiments of the present invention. Detailed Implementation
[0039] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.
[0040] In this embodiment of the invention, a network-free configuration mechanism is proposed. By adopting two-factor authentication with a pre-set device key and a dynamic token, device binding and configuration can be completed completely offline. Network configuration can be completed without an internet connection, reducing dependence on the network environment and improving the user experience in environments with no or weak network.
[0041] Furthermore, an automatic cloud synchronization mechanism is proposed. By designing a local configuration cache queue, an automatic synchronization strategy that is aware of network status is implemented. A differential synchronization algorithm is used to reduce the amount of data transmission, achieving a seamless experience of "going offline first and then connecting to the network", ensuring the final consistency of configuration information and reducing the load on cloud servers.
[0042] like Figure 1 In offline environments, binding is completed via device broadcast and local key authentication, and automatically synchronized to the cloud in online environments, achieving a "first offline, then online" network configuration experience, as detailed below:
[0043] 1. The device to be configured periodically broadcasts a Beacon frame containing the device ID, capability set and dynamic token at intervals T0. The terminal device APP scans and discovers the surrounding devices that can be configured via Bluetooth or Wi-Fi, selects the corresponding device and establishes a temporary P2P (Peer-to-Peer) connection.
[0044] 2. The terminal device APP scans and obtains the pre-set public key in the QR code of the device to be configured. The device to be configured generates a one-time dynamic token and transmits it in encrypted form. The terminal device APP uses the pre-set public key to verify the device identity. Both parties negotiate to establish a temporary session key to ensure communication security.
[0045] 3. The terminal device APP transmits network configuration information to the device to be configured via a secure channel. The device to be configured applies the configuration and returns the result to the terminal device APP. The terminal device APP stores the network configuration information in a local cache queue. In some examples, configurations that have not been synchronized for a maximum of 7 days are retained, and the LRU (Least Recently Used Algorithm) algorithm is used to automatically clean up old data.
[0046] 4. The device to be configured periodically checks its network connectivity, sends lightweight requests to the cloud server, measures round-trip latency, and determines its network connectivity status. When network availability is detected, it automatically establishes a secure connection with the cloud server. In some examples, an incremental approach is used to synchronize network configuration changes during offline periods, selecting the network configuration information with the latest timestamp to update the cloud status.
[0047] 5. The cloud server synchronously records the final binding status of the device, and the device to be configured on the network periodically synchronizes its status information. In some examples, based on the dynamic changes in network quality between 30 and 300 seconds, three consecutive heartbeat timeouts are considered offline, achieving consistency in configuration across multiple terminals.
[0048] Reference Figure 2 The diagram illustrates a flowchart of a device network configuration method according to some embodiments of the present invention. This method is applied to a terminal device, which can be a mobile phone, tablet computer, smart wearable device, or other device with data processing and communication capabilities. The terminal device can be deployed with an application (APP) for managing smart home devices, through which network configuration of smart home devices can be realized.
[0049] Specifically, it may include the following steps:
[0050] Step 201: In the offline network distribution mode, establish a point-to-point connection with the target device.
[0051] As an example, the target device is a smart home device, such as a smart socket or smart air conditioner. The target device can be a complete product connected to a gateway with network connectivity.
[0052] In practical applications, terminal devices can be set to a network-free configuration mode. The terminal device can enter the network-free configuration mode according to the current network status, and then establish a point-to-point connection with the target device to be configured.
[0053] In some embodiments of the present invention, establishing a point-to-point connection with a target device in a network-free configuration mode includes: receiving a beacon frame broadcast by the target device in the network-free configuration mode, and adding the identifier of the target device to the list of network-configurable devices of the terminal device according to the beacon frame; and establishing a point-to-point connection with the target device in response to the user's selection operation of the identifier of the target device in the network-configurable devices.
[0054] In practical applications, the device to be configured periodically broadcasts a Beacon frame containing the device ID, capability set, and dynamic token at intervals T0. The terminal device APP scans and discovers the surrounding devices that can be configured via Bluetooth or Wi-Fi, selects the corresponding device, and establishes a temporary P2P connection.
[0055] Specifically, the target device can continuously broadcast beacon frames containing its own device identifier, capability set, and dynamic token at preset time intervals. As an example, a beacon frame is a key management frame in IEEE 802.11 wireless local area networks (WLANs), periodically broadcast by devices in an access point (AP) or independent basic service set (IBSS) to announce the existence of the network and provide synchronization and configuration information.
[0056] In offline network configuration mode, the terminal device will activate the corresponding scanning function to receive these beacon frames. Upon receiving a beacon frame, the terminal device will parse the device identifier within it and add the target device's identifier to its own list of configurable devices, allowing users to intuitively see the configurable devices. Users can select the identifier of the target device from the list of configurable devices according to their needs. After receiving the user's selection, the terminal device will establish a point-to-point connection with the target device.
[0057] In some embodiments of the present invention, the beacon frame includes any one or more of the following: the identifier of the target device, the capability set of the target device, and a dynamic token.
[0058] As an example, a capability set includes a list or bitmap of the network functions, supported communication protocols, security features, and service types of the target device.
[0059] In some embodiments of the present invention, before establishing a point-to-point connection with the target device, the method further includes:
[0060] Detect the current network status and, if there is no network, enter the no-network configuration mode.
[0061] In practical applications, terminal devices monitor the current network status in real time to determine if a network connection is available. This might involve attempting to connect to a known Wi-Fi network, checking the availability of a mobile data network, or using other network status detection mechanisms. When a terminal device determines that it is currently in a network-free state, it will automatically enter a network-free configuration mode to facilitate subsequent device network configuration operations.
[0062] In some examples, "no network" refers to a state where internet access is unavailable through conventional network connections such as Wi-Fi or mobile data networks. In this case, traditional network configuration methods that rely on cloud servers will not function properly.
[0063] In some examples, when a network is available, a standard cloud-based network configuration mode can be used. In this mode, the terminal device obtains the target device's configuration information from the cloud server and directly sends the configuration information to the target device, enabling it to access the network. When there is no network, the system switches to a network-free configuration mode, performing a point-to-point connection with the target device and subsequent network configuration procedures.
[0064] Step 202: Receive the dynamic token sent by the target device via a peer-to-peer connection, and authenticate the target device by combining the dynamic token with pre-acquired public key information.
[0065] The public key information can be obtained by scanning the device's QR code.
[0066] In practical applications, the terminal device APP scans and obtains the pre-set public key in the QR code of the device to be configured on the network. The device to be configured generates a one-time dynamic token and transmits it in encrypted form. The terminal device APP uses the pre-set public key to verify the device's identity, reducing the risk of the device being maliciously bound.
[0067] Specifically, after successfully establishing a peer-to-peer connection with the target device, the terminal device can receive a dynamic token sent by the target device through this connection. This dynamic token is temporarily generated and encrypted by the target device and is used to verify the device's identity. Furthermore, the terminal device can use public key information obtained beforehand, such as scanning the target device's QR code, to decrypt and verify the received dynamic token, thereby confirming whether the target device with which it has established the connection is legitimate and effectively preventing the access of malicious devices.
[0068] During the authentication process, if the dynamic token verification is successful, it indicates that the target device's identity has been confirmed, and the terminal device can continue to execute the subsequent network configuration process. If the verification fails, the terminal device terminates the connection with the target device and prompts the user that the authentication has failed, requiring the network configuration operation to be performed again.
[0069] Step 203: After successful identity authentication, send network configuration information to the target device so that the target device can apply the network configuration information and establish a connection with the cloud server when the current network is available.
[0070] For example, network configuration information includes Wi-Fi password, server address, certificate, and operating parameters.
[0071] In practical applications, the terminal device (APP) transmits network configuration information to the device to be configured via a secure channel. The device then applies this configuration and returns the result to the terminal device (APP). The device periodically checks its network connectivity, sends lightweight requests to the cloud server, measures round-trip latency, and determines its network connectivity status. When network availability is detected, it automatically establishes a secure connection with the cloud server.
[0072] Specifically, after verifying the identity of the target device, the terminal device can send pre-set or user-inputted network configuration information (such as Wi-Fi name and password) to the target device through an established peer-to-peer connection. Upon receiving this information, the target device can attempt to connect to the local network using these configurations. Furthermore, the target device continuously monitors the network connection status, and once a network is detected as available, it automatically establishes a secure connection with the cloud server, completing the network configuration process.
[0073] In some examples, the cloud server synchronously records the final binding status of the device, and the device to be configured on the network periodically synchronizes its status information. In other examples, based on the dynamic changes in network quality between 30 and 300 seconds, three consecutive heartbeat timeouts are considered offline, ensuring consistency in multi-terminal configuration. During this "uncertain period," the terminal device app may locally believe that the target device is still online and attempt to operate the device.
[0074] For example, a user may operate the same device using both phone A and phone B at the same time. Phone A may still show that the device is not bound due to network latency, while phone B has initiated a binding request. In this case, the final binding status of the device in the cloud server can be used as the basis for judgment to avoid conflicts.
[0075] In some embodiments of the present invention, after successful authentication, network configuration information is sent to the target device so that the target device applies the network configuration information and establishes a connection with the cloud server when the current network is available, including:
[0076] After successful identity authentication, a temporary session key is negotiated and established with the target device; based on the temporary session key, network configuration information is sent to the target device so that the target device can apply the network configuration information and establish a connection with the cloud server when the current network is available.
[0077] After successful identity authentication, both parties negotiate and establish a temporary session key to ensure secure communication.
[0078] Specifically, to ensure the security of network configuration information transmission, the terminal device can negotiate and establish a temporary session key with the target device. In some examples, the temporary session key is jointly generated by both parties based on a certain key exchange protocol (such as Diffie-Hellman key exchange), and only the communicating parties can know it, thereby effectively preventing information from being stolen or tampered with during transmission.
[0079] Based on a temporary session key, the terminal device encrypts network configuration information and sends it to the target device. The target device uses the same temporary session key to decrypt the received encrypted information, thereby obtaining the network configuration information. The use of temporary session keys greatly enhances the security of information transmission, while the target device's continuous monitoring of the network connection status ensures the timeliness and effectiveness of network configuration.
[0080] In some embodiments of the present invention, after successful authentication, network configuration information is sent to the target device so that the target device applies the network configuration information and establishes a connection with the cloud server when the current network is available, the method further includes:
[0081] The network configuration information is stored in a local cache queue, and when the network is available, the changes in the local cache queue are sent to the cloud server through incremental synchronization.
[0082] In practical applications, the terminal device app stores network configuration information in a local cache queue. In some examples, configurations that have not been synchronized for a maximum of 7 days are retained, and the LRU (Least Recently Used Algorithm) algorithm is used to automatically clean up old data.
[0083] Specifically, after the terminal device's APP sends the network configuration information to the device to be configured, it can store the network configuration information in a local cache queue to ensure that this configuration information can be synchronized in a timely manner when the network is restored. The local cache queue serves as a temporary storage mechanism.
[0084] When a terminal device detects that the network is available, it does not immediately send all cached network configuration information to the cloud server at once. Instead, it uses incremental synchronization, transmitting only the data that has changed since the last synchronization, rather than the entire dataset. This significantly reduces data transmission volume, improves synchronization efficiency, and reduces the load on the cloud server. During incremental synchronization, the terminal device checks each piece of network configuration information in its local cache queue and compares it with the existing configuration information on the cloud server. If it finds that a piece of configuration information has been updated locally but there is no corresponding update record in the cloud, the terminal device will send this change to the cloud server for updating.
[0085] In this way, terminal devices can ensure that when the network is restored, the network configuration information of all devices to be configured is synchronized to the cloud server in a timely and accurate manner, thus achieving a seamless network configuration experience of "offline first, then online". At the same time, the incremental synchronization method also ensures the eventual consistency of configuration information, so that users can obtain consistent device network configuration services whether they are offline or online.
[0086] In some examples, when the current network becomes available again, the terminal device or target device can synchronize the following information to the cloud server:
[0087] 1. Device list and topology: During offline periods, users may add new sub-devices or remove certain devices, as well as certain groups, scenes, etc. This configuration information needs to be synchronized to the cloud while offline.
[0088] 2. Device Status: The latest status of all devices. For example, while offline, a user turns on a light via a local switch; the light's power status is "on" and its brightness is 80%. These status changes must be immediately synchronized to the cloud so that the device status seen by the user on the app is accurate.
[0089] 3. Local Automation and Scene Configuration: Users may create or modify local automation rules (such as "turn on hallway lights if the human sensor detects movement") and scenes while offline. This logical configuration information needs to be fully reported to the cloud so that the cloud can back it up and restore or analyze it when needed.
[0090] 4. Target device information: device local time, operating status, local logs (recording important events that occurred during offline periods), firmware version, etc. This helps with cloud-based problem diagnosis and device management.
[0091] 5. Local Execution History: For some important operations or events, even those occurring offline, the device will first store them locally. After the network is restored, these historical records need to be reported to the cloud for permanent storage and analysis. Simply put, the device synchronizes all "changes" that occurred during the offline period, with the aim of keeping the cloud database and the gateway's local database consistent.
[0092] In this embodiment of the invention, a point-to-point connection is established with the target device in a network-free configuration mode. Through the point-to-point connection, a dynamic token sent by the target device is received. The target device is then authenticated by combining the dynamic token with pre-acquired public key information. After successful authentication, network configuration information is sent to the target device so that the target device can apply the network configuration information and establish a connection with the cloud server when the current network is available. This enables network configuration of devices in a network-free environment, improves the user experience, and allows for device authentication, reducing the risk of malicious binding of devices.
[0093] Reference Figure 3 This diagram illustrates a flowchart of another device network configuration method provided by some embodiments of the present invention, applied to terminal devices, and specifically includes the following steps:
[0094] Step 301: In the offline network distribution mode, establish a point-to-point connection with the target device.
[0095] In practical applications, terminal devices can be set to a network-free configuration mode. The terminal device can enter the network-free configuration mode according to the current network status, and then establish a point-to-point connection with the target device to be configured.
[0096] Step 302: Receive the dynamic token sent by the target device via a peer-to-peer connection, and authenticate the target device by combining the dynamic token with pre-acquired public key information.
[0097] In practical applications, the terminal device APP scans and obtains the pre-set public key in the QR code of the device to be configured on the network. The device to be configured generates a one-time dynamic token and transmits it in encrypted form. The terminal device APP uses the pre-set public key to verify the device's identity, reducing the risk of the device being maliciously bound.
[0098] Specifically, after successfully establishing a peer-to-peer connection with the target device, the terminal device can receive a dynamic token sent by the target device through this connection. This dynamic token is temporarily generated and encrypted by the target device and is used to verify the device's identity. Furthermore, the terminal device can use public key information obtained beforehand, such as scanning the target device's QR code, to decrypt and verify the received dynamic token, thereby confirming whether the target device with which it has established the connection is legitimate and effectively preventing the access of malicious devices.
[0099] During the authentication process, if the dynamic token verification is successful, it indicates that the target device's identity has been confirmed, and the terminal device can continue to execute the subsequent network configuration process. If the verification fails, the terminal device terminates the connection with the target device and prompts the user that the authentication has failed, requiring the network configuration operation to be performed again.
[0100] Step 303: After successful identity authentication, negotiate and establish a temporary session key with the target device.
[0101] Step 304: Based on the temporary session key, send network configuration information to the target device so that the target device applies the network configuration information and establishes a connection with the cloud server when the current network is available.
[0102] After successful identity authentication, both parties negotiate and establish a temporary session key to ensure secure communication.
[0103] Specifically, to ensure the security of network configuration information transmission, the terminal device can negotiate and establish a temporary session key with the target device. In some examples, the temporary session key is jointly generated by both parties based on a certain key exchange protocol (such as Diffie-Hellman key exchange), and only the communicating parties can know it, thereby effectively preventing information from being stolen or tampered with during transmission.
[0104] Based on a temporary session key, the terminal device encrypts network configuration information and sends it to the target device. The target device uses the same temporary session key to decrypt the received encrypted information, thereby obtaining the network configuration information. The use of temporary session keys greatly enhances the security of information transmission, while the target device's continuous monitoring of the network connection status ensures the timeliness and effectiveness of network configuration.
[0105] In practical applications, the terminal device (APP) transmits network configuration information to the device to be configured via a secure channel. The device then applies this configuration and returns the result to the terminal device (APP). The device periodically checks its network connectivity, sends lightweight requests to the cloud server, measures round-trip latency, and determines its network connectivity status. When network availability is detected, it automatically establishes a secure connection with the cloud server.
[0106] Specifically, after verifying the identity of the target device, the terminal device can send pre-set or user-inputted network configuration information (such as Wi-Fi name and password) to the target device through an established peer-to-peer connection. Upon receiving this information, the target device can attempt to connect to the local network using these configurations. Furthermore, the target device continuously monitors the network connection status, and once a network is detected as available, it automatically establishes a secure connection with the cloud server, completing the network configuration process.
[0107] Reference Figure 4 This diagram illustrates a flowchart of another device network configuration method provided by some embodiments of the present invention, applied to terminal devices, and specifically includes the following steps:
[0108] Step 401: In the offline network configuration mode, receive the beacon frame broadcast by the target device, and add the identifier of the target device to the list of network-configurable devices of the terminal device according to the beacon frame.
[0109] In practical applications, the device to be configured periodically broadcasts a Beacon frame containing the device ID, capability set, and dynamic token at intervals T0. The terminal device APP scans and discovers the surrounding devices that can be configured via Bluetooth or Wi-Fi, selects the corresponding device, and establishes a temporary P2P connection.
[0110] Specifically, the target device can continuously broadcast beacon frames containing its own device identifier, capability set, and dynamic token at preset time intervals. As an example, a beacon frame is a key management frame in IEEE 802.11 wireless local area networks (WLANs), which is periodically broadcast by access points or devices in an independent basic service set to announce the existence of the network and provide synchronization and configuration information.
[0111] In offline network configuration mode, the terminal device will activate the corresponding scanning function to receive these beacon frames. Upon receiving a beacon frame, the terminal device will parse the device identifier within it and add the identifier of the target device to its own list of configurable devices, so that users can intuitively see the configurable devices.
[0112] Step 402: In response to the user's selection operation of the identifier of the target device in the configurable network devices, establish a point-to-point connection with the target device.
[0113] Users can select the identifier of the target device from the list of configurable network devices according to their needs. After receiving the user's selection, the terminal device will establish a point-to-point connection with the target device.
[0114] Step 403: Receive the dynamic token sent by the target device via a peer-to-peer connection, and authenticate the target device by combining the dynamic token with the pre-acquired public key information.
[0115] In practical applications, the terminal device APP scans and obtains the pre-set public key in the QR code of the device to be configured on the network. The device to be configured generates a one-time dynamic token and transmits it in encrypted form. The terminal device APP uses the pre-set public key to verify the device's identity, reducing the risk of the device being maliciously bound.
[0116] Specifically, after successfully establishing a peer-to-peer connection with the target device, the terminal device can receive a dynamic token sent by the target device through this connection. This dynamic token is temporarily generated and encrypted by the target device and is used to verify the device's identity. Furthermore, the terminal device can use public key information obtained beforehand, such as scanning the target device's QR code, to decrypt and verify the received dynamic token, thereby confirming whether the target device with which it has established the connection is legitimate and effectively preventing the access of malicious devices.
[0117] During the authentication process, if the dynamic token verification is successful, it indicates that the target device's identity has been confirmed, and the terminal device can continue to execute the subsequent network configuration process. If the verification fails, the terminal device terminates the connection with the target device and prompts the user that the authentication has failed, requiring the network configuration operation to be performed again.
[0118] Step 404: After successful identity authentication, send network configuration information to the target device so that the target device can apply the network configuration information and establish a connection with the cloud server when the current network is available.
[0119] In practical applications, the terminal device (APP) transmits network configuration information to the device to be configured via a secure channel. The device then applies this configuration and returns the result to the terminal device (APP). The device periodically checks its network connectivity, sends lightweight requests to the cloud server, measures round-trip latency, and determines its network connectivity status. When network availability is detected, it automatically establishes a secure connection with the cloud server.
[0120] Specifically, after verifying the identity of the target device, the terminal device can send pre-set or user-inputted network configuration information (such as Wi-Fi name and password) to the target device through an established peer-to-peer connection. Upon receiving this information, the target device can attempt to connect to the local network using these configurations. Furthermore, the target device continuously monitors the network connection status, and once a network is detected as available, it automatically establishes a secure connection with the cloud server, completing the network configuration process.
[0121] Reference Figure 5 This diagram illustrates a flowchart of another device network configuration method provided by some embodiments of the present invention, applied to terminal devices, and specifically includes the following steps:
[0122] Step 501: Detect the current network status, and if there is no network, enter the no-network configuration mode.
[0123] In practical applications, terminal devices monitor the current network status in real time to determine if a network connection is available. This might involve attempting to connect to a known Wi-Fi network, checking the availability of a mobile data network, or using other network status detection mechanisms. When a terminal device determines that it is currently in a network-free state, it will automatically enter a network-free configuration mode to facilitate subsequent device network configuration operations.
[0124] Step 502: In the no-network configuration mode, receive the beacon frame broadcast by the target device, and add the identifier of the target device to the list of network-configurable devices of the terminal device according to the beacon frame.
[0125] Step 503: In response to the user's selection operation of the identifier of the target device in the configurable network devices, establish a point-to-point connection with the target device.
[0126] In practical applications, the device to be configured periodically broadcasts a Beacon frame containing the device ID, capability set, and dynamic token at intervals T0. The terminal device APP scans and discovers the surrounding devices that can be configured via Bluetooth or Wi-Fi, selects the corresponding device, and establishes a temporary P2P connection.
[0127] Specifically, the target device can continuously broadcast beacon frames containing its own device identifier, capability set, and dynamic token at preset time intervals. As an example, a beacon frame is a key management frame in IEEE 802.11 wireless local area networks (WLANs), which is periodically broadcast by access points or devices in an independent basic service set to announce the existence of the network and provide synchronization and configuration information.
[0128] In offline network configuration mode, the terminal device will activate the corresponding scanning function to receive these beacon frames. Upon receiving a beacon frame, the terminal device will parse the device identifier within it and add the target device's identifier to its own list of configurable devices, allowing users to intuitively see the configurable devices. Users can select the identifier of the target device from the list of configurable devices according to their needs. After receiving the user's selection, the terminal device will establish a point-to-point connection with the target device.
[0129] Step 504: Receive the dynamic token sent by the target device via a peer-to-peer connection, and authenticate the target device by combining the dynamic token with pre-acquired public key information.
[0130] In practical applications, the terminal device APP scans and obtains the pre-set public key in the QR code of the device to be configured on the network. The device to be configured generates a one-time dynamic token and transmits it in encrypted form. The terminal device APP uses the pre-set public key to verify the device's identity, reducing the risk of the device being maliciously bound.
[0131] Specifically, after successfully establishing a peer-to-peer connection with the target device, the terminal device can receive a dynamic token sent by the target device through this connection. This dynamic token is temporarily generated and encrypted by the target device and is used to verify the device's identity. Furthermore, the terminal device can use public key information obtained beforehand, such as scanning the target device's QR code, to decrypt and verify the received dynamic token, thereby confirming whether the target device with which it has established the connection is legitimate and effectively preventing the access of malicious devices.
[0132] During the authentication process, if the dynamic token verification is successful, it indicates that the target device's identity has been confirmed, and the terminal device can continue to execute the subsequent network configuration process. If the verification fails, the terminal device terminates the connection with the target device and prompts the user that the authentication has failed, requiring the network configuration operation to be performed again.
[0133] Step 505: After successful identity authentication, negotiate and establish a temporary session key with the target device.
[0134] After successful identity authentication, both parties negotiate and establish a temporary session key to ensure secure communication.
[0135] Specifically, to ensure the security of network configuration information transmission, the terminal device can negotiate and establish a temporary session key with the target device. In some examples, the temporary session key is jointly generated by both parties based on a certain key exchange protocol (such as Diffie-Hellman key exchange), and only the communicating parties can know it, thereby effectively preventing information from being stolen or tampered with during transmission.
[0136] Based on a temporary session key, the terminal device encrypts network configuration information and sends it to the target device. The target device uses the same temporary session key to decrypt the received encrypted information, thereby obtaining the network configuration information. The use of temporary session keys greatly enhances the security of information transmission, while the target device's continuous monitoring of the network connection status ensures the timeliness and effectiveness of network configuration.
[0137] Step 506: Based on the temporary session key, send network configuration information to the target device so that the target device applies the network configuration information and establishes a connection with the cloud server when the current network is available.
[0138] In practical applications, the terminal device (APP) transmits network configuration information to the device to be configured via a secure channel. The device then applies this configuration and returns the result to the terminal device (APP). The device periodically checks its network connectivity, sends lightweight requests to the cloud server, measures round-trip latency, and determines its network connectivity status. When network availability is detected, it automatically establishes a secure connection with the cloud server.
[0139] Specifically, after verifying the identity of the target device, the terminal device can send pre-set or user-inputted network configuration information (such as Wi-Fi name and password) to the target device through an established peer-to-peer connection. Upon receiving this information, the target device can attempt to connect to the local network using these configurations. Furthermore, the target device continuously monitors the network connection status, and once a network is detected as available, it automatically establishes a secure connection with the cloud server, completing the network configuration process.
[0140] Reference Figure 6 This diagram illustrates a flowchart of another device network configuration method provided by some embodiments of the present invention, applied to terminal devices, and specifically includes the following steps:
[0141] Step 601: In the offline network distribution mode, establish a point-to-point connection with the target device.
[0142] Step 602: Receive the dynamic token sent by the target device via a peer-to-peer connection, and authenticate the target device by combining the dynamic token with pre-acquired public key information.
[0143] Step 603: After successful identity authentication, send network configuration information to the target device so that the target device can apply the network configuration information and establish a connection with the cloud server when the current network is available.
[0144] Step 604: Store the network configuration information in a local cache queue, and when the current network is available, send the changed content in the local cache queue to the cloud server through incremental synchronization.
[0145] In practical applications, the terminal device app stores network configuration information in a local cache queue. In some examples, unsynchronized configurations are retained for a maximum of 7 days, and the LRU algorithm is used to automatically clean up old data.
[0146] Specifically, after the terminal device's APP sends the network configuration information to the device to be configured, it can store the network configuration information in a local cache queue to ensure that this configuration information can be synchronized in a timely manner when the network is restored. The local cache queue serves as a temporary storage mechanism.
[0147] When a terminal device detects that the network is available, it does not immediately send all cached network configuration information to the cloud server at once. Instead, it uses incremental synchronization, transmitting only the data that has changed since the last synchronization, rather than the entire dataset. This significantly reduces data transmission volume, improves synchronization efficiency, and reduces the load on the cloud server. During incremental synchronization, the terminal device checks each piece of network configuration information in its local cache queue and compares it with the existing configuration information on the cloud server. If it finds that a piece of configuration information has been updated locally but there is no corresponding update record in the cloud, the terminal device will send this change to the cloud server for updating.
[0148] In this way, terminal devices can ensure that when the network is restored, the network configuration information of all devices to be configured is synchronized to the cloud server in a timely and accurate manner, thus achieving a seamless network configuration experience of "offline first, then online". At the same time, the incremental synchronization method also ensures the eventual consistency of configuration information, so that users can obtain consistent device network configuration services whether they are offline or online.
[0149] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.
[0150] Reference Figure 7 The diagram illustrates a structural schematic of a device for network distribution according to some embodiments of the present invention, which is applied to terminal equipment and may specifically include the following modules:
[0151] The point-to-point connection establishment module 701 is used to establish a point-to-point connection with the target device in the offline network distribution mode;
[0152] The identity authentication module 702 is used to receive a dynamic token sent by the target device through a peer-to-peer connection, and to perform identity authentication on the target device by combining the dynamic token with pre-acquired public key information.
[0153] The device configuration module 703 is used to send network configuration information to the target device after successful identity authentication, so that the target device can apply the network configuration information and establish a connection with the cloud server when the current network is available.
[0154] Optionally, after successful authentication, network configuration information is sent to the target device to enable the target device to apply the network configuration information and establish a connection with the cloud server when the current network is available, including:
[0155] After successful identity authentication, a temporary session key is negotiated and established with the target device;
[0156] Based on the temporary session key, network configuration information is sent to the target device so that the target device can apply the network configuration information and establish a connection with the cloud server when the current network is available.
[0157] Optionally, in the offline distribution mode, a point-to-point connection is established with the target device, including:
[0158] In the offline network configuration mode, the beacon frame broadcast by the target device is received, and the identifier of the target device is added to the list of network-configurable devices of the terminal device according to the beacon frame;
[0159] In response to the user's selection of the identifier of the target device in the configurable network devices, a point-to-point connection is established with the target device.
[0160] Optionally, the beacon frame includes one or more of the following: the identifier of the target device, the capability set of the target device, and a dynamic token.
[0161] Optionally, the public key information is obtained by scanning the device QR code of the target device.
[0162] Optionally, after successful authentication, network configuration information is sent to the target device so that the target device applies the network configuration information and establishes a connection with the cloud server when the current network is available, the method further includes:
[0163] The incremental synchronization module is used to store the network configuration information in a local cache queue, and when the current network is available, send the changed content in the local cache queue to the cloud server through incremental synchronization.
[0164] In this embodiment of the invention, a point-to-point connection is established with the target device in a network-free configuration mode. Through the point-to-point connection, a dynamic token sent by the target device is received. The target device is then authenticated by combining the dynamic token with pre-acquired public key information. After successful authentication, network configuration information is sent to the target device so that the target device can apply the network configuration information and establish a connection with the cloud server when the current network is available. This enables network configuration of devices in a network-free environment, improves the user experience, and allows for device authentication, reducing the risk of malicious binding of devices.
[0165] Some embodiments of the present invention also provide an electronic device, including a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, implements the method described above.
[0166] Some embodiments of the present invention also provide a computer-readable storage medium on which a computer program is stored, and which, when executed by a processor, implements the method described above.
[0167] Some embodiments of the present invention also provide a computer program product, including a computer program that, when executed by a processor, implements the method described above.
[0168] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.
[0169] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0170] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0171] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0172] Embodiments of the present invention are described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0173] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0174] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0175] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the present invention.
[0176] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes the aforementioned element.
[0177] The above provides a detailed description of the method, apparatus, equipment, medium, and product for network distribution. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A method for device commissioning, the method comprising: The method is applied to a terminal device and comprises the following steps: In a network-free network configuration mode, a point-to-point connection is established with a target device; Through the point-to-point connection, a dynamic token sent by the target device is received, and the target device is authenticated by combining the dynamic token with pre-acquired public key information; After the authentication is passed, network configuration information is sent to the target device, so that the target device applies the network configuration information and establishes a connection with a cloud server when a current network is available; After the authentication is passed, network configuration information is sent to the target device, so that the target device applies the network configuration information and establishes a connection with a cloud server when a current network is available; After the authentication is passed, a temporary session key is negotiated with the target device; Based on the temporary session key, network configuration information is sent to the target device, so that the target device applies the network configuration information and establishes a connection with a cloud server when a current network is available; In the network-free network configuration mode, a point-to-point connection is established with a target device, which comprises the following steps: In the network-free network configuration mode, a beacon frame broadcasted by a target device is received, and based on the beacon frame, an identifier of the target device is added to a list of network-configurable devices of the terminal device; In response to a selection operation of a user on the identifier of the target device in the list of network-configurable devices, a point-to-point connection is established with the target device; The beacon frame comprises any one or more of the following: the identifier of the target device, a capability set of the target device, and a dynamic token.
2. The method of claim 1, wherein, The public key information is acquired by scanning a device two-dimensional code of the target device.
3. The method of claim 1, wherein, After the authentication is passed, network configuration information is sent to the target device, so that the target device applies the network configuration information and establishes a connection with a cloud server when a current network is available, and the method further comprises the following steps: The network configuration information is stored in a local cache queue, and when a current network is available, the changed content in the local cache queue is sent to a cloud server in an incremental synchronization manner.
4. The method according to any one of claims 1 to 3, characterized in that, Before the point-to-point connection is established with the target device in the network-free network configuration mode, the following step is further included: A current network state is detected, and when there is no network, the network-free network configuration mode is entered.
5. The method of claim 1, wherein, The target device is a smart home device.
6. An apparatus for device provisioning, the apparatus comprising: The device is applied to a terminal device and comprises the following modules: A point-to-point connection establishment module is configured to establish a point-to-point connection with a target device in a network-free network configuration mode; An authentication module is configured to receive a dynamic token sent by the target device through the point-to-point connection, and authenticate the target device by combining the dynamic token with pre-acquired public key information; A device network configuration module is configured to send network configuration information to the target device after the authentication is passed, so that the target device applies the network configuration information and establishes a connection with a cloud server when a current network is available; After the authentication is passed, network configuration information is sent to the target device, so that the target device applies the network configuration information and establishes a connection with a cloud server when a current network is available; negotiate with the target device to establish a temporary session key after identity authentication is passed; based on the temporary session key, send network configuration information to the target device, so that the target device applies the network configuration information and establishes a connection with the cloud server when the current network is available; wherein, in the network-free configuration mode, establishing a point-to-point connection with the target device comprises: in the network-free configuration mode, receiving a beacon frame broadcasted by the target device, and adding an identifier of the target device in a list of configurable network devices of the terminal device according to the beacon frame; in response to a selection operation of a user on the identifier of the target device in the list of configurable network devices, establishing a point-to-point connection with the target device; the beacon frame comprises any one or more of the following: the identifier of the target device, a capability set of the target device, a dynamic token.
7. An electronic device, comprising: a computer program product comprising a processor, a memory, and a computer program stored on the memory and capable of running on the processor, the computer program being executed by the processor to implement the method of any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, a computer program product comprising a processor, a memory, and a computer program stored on the memory and capable of running on the processor, the computer program being executed by the processor to implement the method of any one of claims 1 to 5.
9. A computer program product, characterised in that, a computer program product comprising a processor, a memory, and a computer program stored on the memory and capable of running on the processor, the computer program being executed by the processor to implement the method of any one of claims 1 to 5.
Citation Information
Patent Citations
Network distribution method, device and system of equipment, electronic equipment and storage medium
CN116939769A
Internet of Things authentication method and electronic equipment
CN120710710A