Route connection method and device, computer equipment, storage medium and product

By using a security authentication platform to encrypt and decrypt the service set identifier and verification information of the target router, the security deficiencies of traditional routing connections are resolved, and efficient and secure routing connections are achieved.

CN121126322APending Publication Date: 2025-12-12CHINA MOBILE COMM GRP TERMINAL +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510366260.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Traditional routing connection methods have shortcomings in terms of security and reliability, especially insecure default settings, weak encryption protocols, signal leakage, and inadequate network isolation.

Method used

The target key pair, dynamically issued by the security authentication platform, is used to encrypt the service set identifier and verification information of the target router. The decryption key pair is then used for decryption and matching to ensure the security of communication information and establish a routing connection using short-range wireless communication.

Benefits of technology

It improves the security of data transmission during the routing connection process, ensures the security and reliability of network connections, enhances the efficiency of network access and user experience, and achieves effective optimization of network security and terminal access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121126322A_ABST
    Figure CN121126322A_ABST
Patent Text Reader

Abstract

The invention relates to a route connection method and device, computer equipment, a storage medium and a product, and relates to the technical field of communication. The method comprises the steps that encrypted information reported by a target terminal is received, the encrypted information is obtained after the target terminal encrypts a service set identifier SSID and verification information of a target router through an encryption key in a target key pair, and the target key pair is dynamically issued to the target terminal by a security authentication platform; decrypting the encrypted information through a decryption key in the target key pair to obtain decrypted information; matching the SSID of the target router in the decryption information with the verification information to obtain a matching result; under the condition that the matching result indicates that the matching is successful, establishing routing connection between the target terminal and the target router through short-distance wireless communication; through the method, the data transmission security in the routing connection process can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a routing connection method, apparatus, computer equipment, storage medium, and product. Background Technology

[0002] Traditional routing connections typically use Wi-Fi or Bluetooth. However, these methods have several security shortcomings, such as insecure default settings, weak encryption protocols, signal leakage and interference, and inadequate network isolation. These issues compromise the security and reliability of traditional routing connections. Therefore, a more secure and reliable routing connection method is urgently needed to address the security deficiencies of traditional routing connections. Summary of the Invention

[0003] This application provides a routing connection method, apparatus, computer device, storage medium, and product, which can improve the data transmission security during the routing connection process. The technical solution is as follows.

[0004] On the one hand, a routing connection method is provided, which is executed by a security authentication platform, and the method includes: The system receives encrypted information reported by the target terminal. The encrypted information is obtained by the target terminal encrypting the Service Set Identifier (SSID) of the target router and the verification information using the encryption key in the target key pair. The target key pair is dynamically issued to the target terminal by the security authentication platform. The encrypted information is decrypted using the decryption key in the target key pair to obtain the decrypted information; The SSID of the target router in the decrypted information is matched with the verification information to obtain a matching result; If the matching result indicates a successful match, a routing connection is established between the target terminal and the target router via short-range wireless communication.

[0005] On the other hand, a routing connection method is provided, which is executed by a target terminal, the method comprising: Obtain verification information; The SSID of the target router and the verification information are encrypted using the encryption key in the target key pair issued by the security authentication platform to obtain encrypted information; Report the encrypted information to the security authentication platform; After receiving the routing connection operation from the security authentication platform, a routing connection is established with the target router via short-range wireless communication. The routing connection operation is performed by the security authentication platform after decrypting the encrypted information, matching the SSID of the target router in the decrypted information with the verification information, and the matching result indicates a successful match.

[0006] On the other hand, a routing connection device is provided, which is used in a security authentication platform, and the device includes: The first information receiving module is used to receive encrypted information reported by the target terminal. The encrypted information is obtained by the target terminal encrypting the service set identifier (SSID) of the target router and the verification information using the encryption key in the target key pair. The target key pair is dynamically issued to the target terminal by the security authentication platform. The decryption module is used to decrypt the encrypted information using the decryption key in the target key pair to obtain decrypted information; The matching module is used to match the SSID of the target router in the decryption information with the verification information to obtain a matching result; The first connection establishment module is used to establish a routing connection between the target terminal and the target router via short-range wireless communication when the matching result indicates a successful match.

[0007] In one possible implementation, the device further includes: A request receiving module is used to receive a connection request from a target terminal, wherein the connection request contains terminal information of the target terminal; The second connection establishment module is used to establish a connection between the target terminal and the security authentication platform after the target terminal has been verified based on the connection request. The target key pair is sent to the target terminal.

[0008] In one possible implementation, the first connection establishment module is configured to send authorization information to the target terminal and the target router respectively, so that the target terminal sends a connection request containing the authorization information to the target router, and the target router verifies the received connection request based on the authorization information, and establishes a routing connection between the target terminal and the target router through short-range wireless communication after successful verification.

[0009] On the other hand, a routing connection device is provided, which is applied in a target terminal, the device comprising: The second information acquisition module is used to acquire verification information; The encryption module is used to encrypt the SSID of the target router and the verification information using the encryption key in the target key pair issued by the security authentication platform to obtain encrypted information; The information sending module is used to report the encrypted information to the security authentication platform; The third connection establishment module is used to establish a routing connection with the target router through short-range wireless communication after receiving the routing connection operation from the security authentication platform. The routing connection operation is performed by the security authentication platform after decrypting the encrypted information, matching the SSID of the target router in the decrypted information with the verification information, and the matching result indicating a successful match.

[0010] In one possible implementation, the second acquisition module includes: The receiving submodule is used to receive encrypted account information broadcast by the target router; the encrypted account information is obtained by the security authentication platform encrypting the SSID of the target router using the encryption key in the target key pair and then sending it to the target router. The decryption submodule is used to decrypt the encrypted account information using the decryption key in the target key pair to obtain the SSID of the target router; The acquisition submodule is used to obtain the verification information based on the SSID of the target router.

[0011] In one possible implementation, the third connection establishment module includes: The information receiving submodule is used to receive authorization information sent by the target router; The request sending submodule is used to send a connection request containing the authorization information to the target router, so that the target router can verify the connection request based on the authorization information issued by the security authentication platform, and establish a routing connection between the target terminal and the target router through short-range wireless communication after the verification is successful.

[0012] On the other hand, a computer device is provided, the computer device including a processor and a memory, the memory storing at least one computer program, the at least one computer program being loaded and executed by the processor to implement the above-described routing connection method.

[0013] On the other hand, a computer-readable storage medium is provided, wherein at least one computer program is stored in the computer program, which is loaded and executed by a processor to implement the above-described routing connection method.

[0014] On the other hand, a computer program product is provided, the computer program product including a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a computer, cause the computer to perform to implement the routing connection method provided in the various optional implementations described above.

[0015] The technical solution provided in this application may include the following beneficial effects: The security authentication method provided in this application involves the target terminal using the encryption key in the target key pair dynamically issued by the security authentication platform to encrypt the service set identifier and verification information of the target router, ensuring that the communication information between the target terminal and the security authentication platform is not stolen or tampered with during transmission. The security authentication platform decrypts the encrypted information using the decryption key and matches the decrypted service set identifier and verification information to verify the legitimacy of the target terminal. If the match is successful, a routing connection is established between the target terminal and the target router via short-range wireless communication. By utilizing dynamic key pairs and encryption technology, the security of data transmission during the routing connection process can be improved. Furthermore, through a strict verification process and automated management, the security and reliability of the network connection are ensured, the efficiency of network access and user experience are improved, network security and terminal access are effectively optimized, and the operational security and service quality of the communication network are enhanced.

[0016] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0018] Figure 1 A schematic diagram of a security authentication system provided in an exemplary embodiment of this application is shown; Figure 2 A flowchart illustrating a routing connection method provided in an exemplary embodiment of this application is shown; Figure 3 A flowchart of a routing connection method provided by another exemplary embodiment of this application is shown; Figure 4 This illustration shows an interactive diagram of a security authentication method provided in an exemplary embodiment of this application; Figure 5 A block diagram of a routing connection apparatus provided in an exemplary embodiment of this application is shown; Figure 6 A block diagram of a routing connection apparatus provided in another exemplary embodiment of this application is shown; Figure 7 A structural block diagram of a computer device illustrated in an exemplary embodiment of this application is shown; Figure 8 A structural block diagram of a computer device illustrated in an exemplary embodiment of this application is shown. Detailed Implementation

[0019] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0020] To improve the security of routing connections, embodiments of this application provide a security authentication system. Figure 1 A schematic diagram of a security authentication system provided in an exemplary embodiment of this application is shown, such as... Figure 1 As shown, the security authentication system includes a terminal device 110, a router 120, and a security authentication platform 130.

[0021] In one possible implementation scenario, where a routing connection is established between a terminal and a router via short-range wireless communication, the terminal device 110 can be a StarFlash terminal, i.e., a terminal device supporting StarFlash technology, or it can be a WIFI terminal or a Bluetooth terminal; the router 120 can be a StarFlash router, i.e., a router supporting StarFlash technology. In other words, the short-range wireless communication can be based on StarFlash technology, which can achieve high-speed, low-latency short-range wireless communication and improve network efficiency. In other possible implementation scenarios, the short-range wireless communication can also be based on other short-range wireless communication technologies, and this application does not limit this.

[0022] In one possible implementation, the security authentication platform 130 can be as follows: Figure 1 The security authentication platform is deployed independently of router 120. In this case, the deployment method can be one of the following: cloud platform deployment, local server deployment, or hybrid deployment (i.e., combining cloud platform and local server, with some functions deployed in the cloud and some functions deployed locally), communicating with terminal device 110 via the Internet and router 120. In another possible implementation, the security authentication platform can be configured within the router. Depending on the actual needs, the security authentication platform can have different deployment methods, and this application does not impose any restrictions on this. The following embodiments illustrate the deployment of the security authentication platform independently of the router.

[0023] Based on such Figure 1 The security authentication system shown Figure 2 This application illustrates a flowchart of a routing connection method provided in an exemplary embodiment. This method can be executed by a security authentication platform within a security authentication system, such as... Figure 2 As shown, the method may include the following steps.

[0024] Step 210: Receive the encrypted information reported by the target terminal. The encrypted information is obtained by the target terminal encrypting the Service Set Identifier (SSID) of the target router and the verification information using the encryption key in the target key pair. The target key pair is dynamically issued to the target terminal by the security authentication platform.

[0025] The security authentication platform receives encrypted information reported by the target terminal. This encrypted information is generated by the target terminal using the encryption key from the target key pair dynamically issued by the security authentication platform to encrypt the target router's Service Set Identifier (SSID) and authentication information. The target key pair contains the encryption key and its corresponding decryption key. The Service Set Identifier is a unique identifier for the router, used to distinguish different wireless networks. The authentication information is data used for authentication between the target terminal and the target router; it is illustrative and can be any of the following: timestamp, random number, terminal identifier, account password, or one-time pairing code. Furthermore, this target key pair is dynamically issued by the security authentication platform. This means the platform can update the target key pair periodically and issue it to the terminal, ensuring dynamic changes to the target key pair, reducing the security risks associated with using the same key pair for extended periods, and also reducing the risk of key leakage.

[0026] The target terminal transmits information to the security authentication platform in an encrypted manner, which can ensure that the communication information between the target terminal and the target router is not stolen or tampered with during transmission, thereby improving the security of data transmission and preventing man-in-the-middle attacks or information leakage.

[0027] In one possible implementation, the target key pair can be an RSA (Rivest-Shamir-Adleman Encryption Algorithm) cryptographic key. This RSA key set consists of a pair of keys: a public key and a private key. The public key is used to encrypt data or verify digital signatures, and the private key is used to decrypt data or generate digital signatures. Alternatively, the target key pair can also be an ECC (Elliptic Curve Cryptography) cryptographic key. This application does not impose any restrictions on the encryption algorithm used for the target key pair.

[0028] Step 220: Decrypt the encrypted information using the decryption key in the target key pair to obtain the decrypted information.

[0029] The security authentication platform uses the decryption key in the target key pair to decrypt the received encrypted information and restore the original SSID and verification information.

[0030] Step 230: Match the SSID of the target router in the decrypted information with the verification information to obtain the matching result.

[0031] The security authentication platform can maintain the SSID of the target router and the standard verification information corresponding to the SSID. During the matching process, the security authentication platform can query the corresponding standard verification information based on the SSID in the decrypted information. By comparing the verification information with the standard verification information, the legitimacy of the terminal is verified. When the verification information matches the standard verification information, the matching result is determined to be a successful match. When the verification information does not match the standard verification information, the matching result is determined to be a failed match.

[0032] By matching the SSID of the target router with the verification information, the security authentication platform can confirm whether the terminal device connected to the router is a legitimate device, thereby preventing unauthorized terminals from accessing the network and ensuring network security and reliability.

[0033] Step 240: If the matching result indicates a successful match, establish a routing connection between the target terminal and the target router via short-range wireless communication.

[0034] If the matching result indicates a successful match, the security authentication platform can establish a routing connection between the target router and the target terminal via short-range wireless communication by sending an authorization command to both parties, providing network access services to the target terminal while ensuring security. If the matching result indicates a failed match, in one possible implementation, the security authentication platform can send feedback information to the target terminal indicating the failure, instructing the target terminal to update its verification information. If the number of failed matches reaches a target threshold, the target terminal is determined to be an unauthorized access terminal relative to the target router. A log is recorded, and a warning message is sent to the target router. This warning message may contain the target terminal's terminal information, so that when the target terminal connects to the target router, the target router can deny access based on the warning message.

[0035] In summary, the security authentication method provided in this application involves the target terminal using the encryption key in the target key pair dynamically issued by the security authentication platform to encrypt the service set identifier and verification information of the target router, ensuring that the communication information between the target terminal and the security authentication platform is not stolen or tampered with during transmission. The security authentication platform decrypts the encrypted information using the decryption key and matches the decrypted service set identifier and verification information to verify the legitimacy of the target terminal. If the match is successful, a routing connection is established between the target terminal and the target router via short-range wireless communication. By utilizing dynamic key pairs and encryption technology, the security of data transmission during the routing connection process can be improved. Furthermore, through a rigorous verification process and automated management, the security and reliability of the network connection are ensured, the efficiency of network access and user experience are improved, network security and terminal access are effectively optimized, and the operational security and service quality of the communication network are enhanced.

[0036] based on Figure 2 In the embodiment shown, on the target terminal side, Figure 3 A flowchart of a routing connection method provided in another exemplary embodiment of this application is shown. This method can be executed by a terminal device in a security authentication system. The following embodiments are illustrated using a target terminal as an example. Figure 3 As shown, the method may include the following steps.

[0037] Step 310: Obtain verification information.

[0038] This verification information is used for identity authentication. It can be verification information entered by the user based on the target router's SSID, such as a password or pairing code; or it can be verification information generated by the target terminal based on the SSID of the target router, such as a timestamp, a random number, and a terminal identifier, according to the generation rules between the SSID and the verification information.

[0039] Step 320: Encrypt the SSID and verification information of the target router using the encryption key in the target key pair issued by the security authentication platform to obtain encrypted information.

[0040] The target terminal uses the encryption key in the target key pair currently issued by the security authentication platform to encrypt the SSID and verification information of the target router, generating encrypted information. Meanwhile, the security authentication platform dynamically issues target object pairs to the target terminal to update the target key pairs according to the target period, thereby improving the security of data transmission.

[0041] Step 330: Report the encrypted information to the security authentication platform.

[0042] Step 340: After receiving the routing connection operation from the security authentication platform, a routing connection is established with the target router via short-range wireless communication. The routing connection operation is performed by the security authentication platform after decrypting the encrypted information and matching the SSID of the target router in the decrypted information with the verification information, and the matching result indicates that the match is successful.

[0043] In one possible implementation, if the matching result indicates a matching failure, the target terminal will receive an indication message from the security authentication platform indicating the matching failure. Based on this indication message, the target terminal can obtain updated verification information to re-initiate verification with the security authentication platform.

[0044] In summary, the security authentication method provided in this application involves the target terminal using the encryption key in the target key pair dynamically issued by the security authentication platform to encrypt the service set identifier and verification information of the target router, ensuring that the communication information between the target terminal and the security authentication platform is not stolen or tampered with during transmission. The security authentication platform decrypts the encrypted information using the decryption key and matches the decrypted service set identifier and verification information to verify the legitimacy of the target terminal. If the match is successful, a routing connection is established between the target terminal and the target router via short-range wireless communication. By utilizing dynamic key pairs and encryption technology, the security of data transmission during the routing connection process can be improved. Furthermore, through a rigorous verification process and automated management, the security and reliability of the network connection are ensured, the efficiency of network access and user experience are improved, network security and terminal access are effectively optimized, and the operational security and service quality of the communication network are enhanced.

[0045] Figure 4 This illustration shows an interactive diagram of a security authentication method provided in an exemplary embodiment of this application. The method can be interactively executed by the security authentication platform, the target router, and the target terminal within the security authentication system, such as... Figure 4 As shown, the method may include the following steps.

[0046] Step 401: The target terminal initiates a connection request to the security authentication platform, and the security authentication platform receives the connection request from the target terminal.

[0047] The connection request contains the target terminal's terminal information, which is used to identify and verify the target terminal's identity. Schematic, the target terminal's terminal information may include the target terminal's MAC address (Media Access Control Address), certificate, IP address (Internet Protocol Address), device identifier, etc.

[0048] By parsing the connection request of the target terminal, the security authentication platform can obtain the terminal information of the target terminal, and then authenticate the target terminal to determine whether to allow the target terminal to access the security authentication platform.

[0049] In one possible implementation, the security authentication platform may maintain a database of authorized terminals and / or a blacklist. The database of authorized terminals may store terminal information of authorized terminals that are allowed to access the network. When verifying a target terminal, the security authentication platform may compare the terminal information of the target terminal with the terminal information in the database of authorized terminals. If it is determined that all the terminal information of the target terminal exists in the database of authorized terminals and does not exist in the blacklist, then the target terminal is determined to have passed verification. If it is determined that the terminal information of the target terminal contains terminal information that does not exist in the database of authorized terminals, or that the terminal information of the target terminal exists in the blacklist, then the target terminal is determined to have failed verification.

[0050] Step 402: After the security authentication platform verifies the target terminal based on the connection request, it establishes a connection between the target terminal and the security authentication platform.

[0051] After the target terminal is verified, the security authentication platform sends a connection confirmation message to the target terminal to establish a connection between the target terminal and the security authentication platform.

[0052] Step 403: The security authentication platform sends the target key pair to the target terminal, and the target terminal receives the target key pair accordingly.

[0053] In this embodiment, the target key pair may be time-sensitive, and the security authentication platform enhances security by periodically updating the target key pair. In one possible implementation, to further improve security, the security authentication platform can distribute the target key pair to the target terminal through a secure channel, such as via TLS (Transport Layer Security) or SSL (Secure Sockets Layer) protocols. Furthermore, all information interaction between the security authentication platform and the target terminal can be conducted through the aforementioned secure channel to ensure the overall security of information interaction.

[0054] After receiving the target key pair, the target terminal can store the target key pair in the target terminal's secure area to prevent password leakage.

[0055] Step 404: The target router broadcasts encrypted account information, and the target terminal receives the encrypted account information broadcast by the target router.

[0056] The encrypted account information is obtained by the security authentication platform encrypting the target router's SSID using the encryption key in the target key pair and then sending it to the target router.

[0057] In other words, the security authentication platform uses the encryption key in the target key pair to encrypt the SSID of the target router, obtains the encrypted account information of the target router, and sends the encrypted account information to the target router. The target router then broadcasts the encrypted account information so that the target terminal can receive the encrypted account information broadcast by the target router when it is within the broadcast range of the target router.

[0058] Step 405: The target terminal decrypts the encrypted account information using the decryption key in the target key pair to obtain the SSID of the target router.

[0059] In one possible implementation, when encrypting the SSID of the target router, the security authentication platform can use its private key to sign the SSID and send the signature along with the encrypted account information to the target terminal. Correspondingly, after successful decryption, the target terminal can use the public key of the security authentication platform to verify the signature, ensuring the integrity of the decrypted data. That is, if the verification passes, the data is considered complete; if the verification fails, data is considered missing, and the process of obtaining and decrypting the encrypted account information is repeated. Alternatively, in another possible implementation, when encrypting the SSID of the target router, the security authentication platform can calculate the hash value of the SSID and send this hash value along with the encrypted data to the target terminal. Correspondingly, after successful decryption, the target terminal recalculates the hash value of the SSID and compares it with the received hash value to ensure the integrity of the decrypted data. That is, if the hash values ​​match, the data is considered complete; if the hash values ​​do not match, data is considered missing, and the process of obtaining and decrypting the encrypted account information is repeated.

[0060] In one possible scenario, if the target terminal fails to decrypt the encrypted account information, it may be because the current key pair has been updated, causing the target key pair to become invalid. The target terminal can then obtain the encrypted account information and the updated target key pair again, and decrypt it once more to obtain the target router's SSID.

[0061] Step 406: The target terminal obtains verification information based on the target router's SSID.

[0062] Step 407: The target terminal uses the encryption key in the target key pair issued by the security authentication platform to encrypt the SSID of the target router and the verification information to obtain encrypted information.

[0063] Step 408: The target terminal reports encrypted information to the security authentication platform, and the security authentication platform receives the encrypted information reported by the target terminal.

[0064] The encrypted information is obtained by the target terminal encrypting the target router's Service Set Identifier (SSID) and authentication information using the encryption key in the target key pair. The target key pair is dynamically issued to the target terminal by the security authentication platform.

[0065] Step 409: The security authentication platform decrypts the encrypted information using the decryption key in the target key pair to obtain the decrypted information.

[0066] Step 410: The security authentication platform matches the SSID of the target router in the decrypted information with the verification information to obtain the matching result.

[0067] Step 411: If the matching result indicates a successful match, the security authentication platform establishes a routing connection between the target terminal and the target router via short-range wireless communication.

[0068] This process can be implemented as follows: the security authentication platform performs routing connection operations on the target terminal and the target router. On the target terminal side, after receiving the routing connection operation from the security authentication platform, the target terminal establishes a routing connection with the target router through short-range wireless communication.

[0069] Furthermore, the process by which the security authentication platform establishes a routing connection between the target terminal and the target router can be implemented as follows: Authorization information is sent to both the target terminal and the target router; so that the target terminal sends a connection request containing authorization information to the target router, and the target router verifies the received connection request based on the authorization information, and establishes a routing connection between the target terminal and the target router through short-range wireless communication after successful verification.

[0070] In one possible implementation, the authorization information is time-sensitive, and its validity period can be dynamically adjusted based on security policies; this application does not impose any restrictions on this. The authorization information includes at least one of the following: a security token, a security certificate, and a security key. The security token is a dynamically generated, time-sensitive string or number. The security certificate is a digital certificate based on Public Key Infrastructure (PKI) issued by the CA system deployed in the security authentication platform. The security key is a key in a symmetric or asymmetric encryption algorithm. In this embodiment, it can also be sent as authorization information to terminal devices and routers for authentication.

[0071] Correspondingly, on the target terminal side, the process of establishing a routing connection between the target terminal and the target router can be implemented as follows: Receive authorization information sent by the target router; A connection request containing authorization information is sent to the target router, so that the target router can verify the connection request based on the authorization information issued by the security authentication platform. After successful verification, a routing connection between the target terminal and the target router is established through short-range wireless communication.

[0072] In other words, after obtaining the authorization information, the target terminal sends a connection request to the target router based on the authorization information. The target router compares the authorization information provided by the target terminal with the authorization information it has obtained and confirms the validity period of the authorization information. If they match and the authorization information is within the valid period, the verification is successful and a routing connection is established through short-range wireless communication. If they do not match or the authorization information has expired, the verification is failed and the connection is rejected.

[0073] In one possible implementation, the security authentication platform signs the authorization information while generating it, and then sends the authorization information and signature to the target terminal and the target router. The target terminal sends a connection request to the target router based on the authorization information and signature. The target router verifies the authorization information and signature, and establishes a routing connection between the target terminal and the target router after successful verification.

[0074] Furthermore, the target router can determine whether the source of the authorization information is trustworthy based on the received signature. If the source of the authorization information is trustworthy, the received authorization information is consistent with its own authorization information, and it is within the valid time, then the verification is successful and a routing connection is established through short-range wireless communication. Otherwise, the verification is deemed to have failed and the routing connection is rejected.

[0075] In one possible implementation, after a routing connection is established between the target terminal and the target router, encrypted communication can be performed based on authorization information. Schematic example, taking a security certificate as the authorization information, after the routing connection is established, the target terminal and the target router can exchange keys using the public key in the security certificate and determine a shared key, so that encrypted transmission can be performed based on the shared key in subsequent communication processes.

[0076] In one possible implementation, besides establishing routing connections between terminal devices and routers, the security authentication platform can also perform security monitoring and maintenance on the communication interactions between terminal devices and routers. This includes real-time monitoring of communication between terminal devices and routers, such as collecting communication traffic, analyzing communication behavior, identifying anomalies, and issuing alerts and notifying relevant personnel when anomalies are detected; recording security events in a log database for auditing and investigation; conducting regular security audits and risk assessments, such as using automated tools to scan network devices and configurations, and assessing risk levels based on risk matrices or quantitative models; establishing an emergency response mechanism to handle security events, such as classifying events according to type and severity and developing corresponding handling measures for each type of security event to respond promptly; and establishing a recovery plan to ensure timely service restoration after an attack, such as regularly backing up and storing critical data and configuration information, and restoring services by retrieving backed-up data after an attack. Depending on actual needs, the security authentication platform can be configured with more functions, which this application does not limit.

[0077] In summary, the security authentication method provided in this application involves the target terminal using the encryption key in the target key pair dynamically issued by the security authentication platform to encrypt the service set identifier and verification information of the target router, ensuring that the communication information between the target terminal and the security authentication platform is not stolen or tampered with during transmission. The security authentication platform decrypts the encrypted information using the decryption key and matches the decrypted service set identifier and verification information to verify the legitimacy of the target terminal. If the match is successful, a routing connection is established between the target terminal and the target router via short-range wireless communication. By utilizing dynamic key pairs and encryption technology, the security of data transmission during the routing connection process can be improved. Furthermore, through a rigorous verification process and automated management, the security and reliability of the network connection are ensured, the efficiency of network access and user experience are improved, network security and terminal access are effectively optimized, and the operational security and service quality of the communication network are enhanced.

[0078] The security authentication system and method provided in this application embodiment can be applied in conjunction with short-range wireless communication technology. Indicatively, this short-range wireless communication technology can be StarSignal technology. When applied in conjunction with StarSignal technology, interaction between the security authentication platform, StarSignal terminal, and StarSignal router can be achieved based on StarSignal technology. The security authentication method provided in this application embodiment is executed to establish a routing connection between the StarSignal terminal and the StarSignal router, thereby enabling data transmission. This process can be implemented as follows: the StarSignal terminal establishes a connection with the security authentication platform; the security authentication platform verifies the StarSignal terminal; if the verification passes, a connection is established with the StarSignal terminal. The StarSpark terminal obtains the unique StarSpark identifier (SSID) encrypted and issued by the StarSpark router. It then encrypts the SSID and verification information using the encryption key from the target key pair dynamically issued by the security authentication platform, obtaining encrypted information, which is then reported to the security authentication center platform. The security authentication platform decrypts the encrypted information and uses the SSID and verification information from the decrypted information to verify the StarSpark terminal. If the verification is successful, corresponding authorization information is generated and sent back to the StarSpark terminal. The StarSpark terminal initiates authorization information authentication with the StarSpark router. The StarSpark router verifies the authorization information; if the verification is successful, a data connection is established between the StarSpark terminal and the StarSpark router.

[0079] Figure 5 This application shows a block diagram of a routing connection apparatus provided in an exemplary embodiment, which can perform the following: Figure 2 or Figure 4 The illustrated embodiments correspond to all or part of the steps of the security authentication platform, such as... Figure 5 As shown, the device may include the following modules.

[0080] The first information receiving module 510 is used to receive encrypted information reported by the target terminal. The encrypted information is obtained by the target terminal encrypting the service set identifier (SSID) of the target router and the verification information using the encryption key in the target key pair. The target key pair is dynamically issued to the target terminal by the security authentication platform. Decryption module 520 is used to decrypt the encrypted information using the decryption key in the target key pair to obtain decrypted information; The matching module 530 is used to match the SSID of the target router in the decryption information with the verification information to obtain a matching result; The first connection establishment module 540 is used to establish a routing connection between the target terminal and the target router via short-range wireless communication when the matching result indicates a successful match.

[0081] In one possible implementation, the device further includes: A request receiving module is used to receive a connection request from a target terminal, wherein the connection request contains terminal information of the target terminal; The second connection establishment module is used to establish a connection between the target terminal and the security authentication platform after the target terminal has been verified based on the connection request. The target key pair is sent to the target terminal.

[0082] In one possible implementation, the first connection establishment module 540 is configured to send authorization information to the target terminal and the target router respectively, so that the target terminal sends a connection request containing the authorization information to the target router, and the target router verifies the received connection request based on the authorization information, and establishes a routing connection between the target terminal and the target router through short-range wireless communication after successful verification.

[0083] In summary, the security authentication device provided in this application enables the security authentication platform to decrypt the encrypted information reported by the target terminal using a decryption key after receiving the encrypted information, and then match the decrypted service set identifier with the verification information to verify the legitimacy of the target terminal. If the match is successful, a routing connection is established between the target terminal and the target router via short-range wireless communication. Through the above device, dynamic key pairs and encryption technology can improve the data transmission security during the routing connection process. In addition, through a strict verification process and automated management, the security and reliability of the network connection are ensured, the efficiency of network access and user experience are improved, network security and terminal access are effectively optimized, and the operational security and service quality of the communication network are enhanced.

[0084] Figure 6 A block diagram of a routing connection apparatus provided in another exemplary embodiment of this application is shown, which can perform functions such as Figure 3 or Figure 4 The steps corresponding to the target terminal in the illustrated embodiments are as follows: Figure 6 As shown, the device may include the following modules.

[0085] The second information acquisition module 610 is used to acquire verification information; The encryption module 620 is used to encrypt the SSID of the target router and the verification information using the encryption key in the target key pair issued by the security authentication platform to obtain encrypted information; The information sending module 630 is used to report the encrypted information to the security authentication platform; The third connection establishment module 640 is used to establish a routing connection with the target router via short-range wireless communication after receiving the routing connection operation from the security authentication platform. The routing connection operation is performed by the security authentication platform after decrypting the encrypted information, matching the SSID of the target router in the decrypted information with the verification information, and the matching result indicating a successful match.

[0086] In one possible implementation, the second acquisition module 610 includes: The receiving submodule is used to receive encrypted account information broadcast by the target router; the encrypted account information is obtained by the security authentication platform encrypting the SSID of the target router using the encryption key in the target key pair and then sending it to the target router. The decryption submodule is used to decrypt the encrypted account information using the decryption key in the target key pair to obtain the SSID of the target router; The acquisition submodule is used to obtain the verification information based on the SSID of the target router.

[0087] In one possible implementation, the third connection establishment module 640 includes: The information receiving submodule is used to receive authorization information sent by the target router; The request sending submodule is used to send a connection request containing the authorization information to the target router, so that the target router can verify the connection request based on the authorization information issued by the security authentication platform, and establish a routing connection between the target terminal and the target router through short-range wireless communication after the verification is successful.

[0088] In summary, the security authentication device provided in this application enables the target terminal to encrypt the service set identifier and verification information of the target router using the encryption key in the target key pair dynamically issued by the security authentication platform. This ensures that the communication information between the target terminal and the security authentication platform is not stolen or tampered with during transmission. The encrypted information is then reported to the security authentication platform, which decrypts the information using the decryption key and matches the decrypted service set identifier and verification information to verify the legitimacy of the target terminal. Upon receiving a routing connection operation from the security authentication platform, a routing connection is established between the target terminal and the target router via short-range wireless communication. This method, utilizing dynamic key pairs and encryption technology, improves the security of data transmission during the routing connection process. Furthermore, through a rigorous verification process and automated management, the security and reliability of the network connection are ensured, improving network access efficiency and user experience. This effectively optimizes network security and terminal access, enhancing the operational security and service quality of the communication network.

[0089] Figure 7 A structural block diagram of a computer device 700 illustrated in an exemplary embodiment of this application is shown. This computer device can be implemented as the security authentication platform described above in this application. The computer device 700 includes a Central Processing Unit (CPU) 701, a system memory 704 including Random Access Memory (RAM) 702 and Read-Only Memory (ROM) 703, and a system bus 705 connecting the system memory 704 and the CPU 701. The computer device 700 also includes a mass storage device 706 for storing an operating system 709, application programs 710, and other program modules 711. The system memory 704 and the mass storage device 706 can be collectively referred to as memory.

[0090] According to various embodiments of this application, the computer device 700 can also be connected to a remote computer on a network, such as the Internet. That is, the computer device 700 can be connected to a network 708 via a network interface unit 707 connected to the system bus 705, or the network interface unit 707 can be used to connect to other types of networks or remote computer systems (not shown).

[0091] The memory further includes at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, at least one program, code set, or instruction set is stored in the memory, and the central processing unit 701 performs the following functions by executing the at least one instruction, at least one program, code set, or instruction set: Figure 2 or Figure 4 All or some of the steps in the routing connection method shown in the embodiments.

[0092] Figure 8 A structural block diagram of a computer device 800 illustrating an exemplary embodiment of this application is shown. The computer device 800 can be implemented as the aforementioned terminal device, such as a smartphone, tablet computer, laptop computer, desktop computer, etc. The computer device 800 may also be referred to as user equipment, portable terminal, laptop terminal, desktop terminal, or other names.

[0093] Typically, computer device 800 includes a processor 801 and a memory 802.

[0094] In some embodiments, the computer device 800 may also optionally include a peripheral device interface 803 and at least one peripheral device. The processor 801, memory 802, and peripheral device interface 803 can be connected via a bus or signal line. Each peripheral device can be connected to the peripheral device interface 803 via a bus, signal line, or circuit board. Specifically, the peripheral device includes at least one of the following: a radio frequency circuit 804, a display screen 805, a camera assembly 806, an audio circuit 807, and a power supply 808.

[0095] In some embodiments, the computer device 800 further includes one or more sensors 809. The one or more sensors 809 include, but are not limited to, an accelerometer 810, a gyroscope 811, a pressure sensor 812, an optical sensor 813, and a proximity sensor 814.

[0096] Those skilled in the art will understand that Figure 8 The structure shown does not constitute a limitation on the computer device 800, and may include more or fewer components than shown, or combine certain components, or use different component arrangements.

[0097] In one exemplary embodiment, a computer-readable storage medium is also provided, which stores at least one computer program that is loaded and executed by a processor to implement all or part of the steps in the routing connection method described above. For example, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, or optical data storage device, etc.

[0098] In one exemplary embodiment, a computer program product is also provided, comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a computer, cause the computer to perform the above-described actions. Figure 2 , Figure 3 or Figure 4 All or part of the steps of the routing connection method shown in the embodiments.

[0099] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the claims.

[0100] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A routing connection method, characterized in that, The method is executed by a security authentication platform, and the method includes: The system receives encrypted information reported by the target terminal. The encrypted information is obtained by the target terminal encrypting the Service Set Identifier (SSID) of the target router and the verification information using the encryption key in the target key pair. The target key pair is dynamically issued to the target terminal by the security authentication platform. The encrypted information is decrypted using the decryption key in the target key pair to obtain the decrypted information; The SSID of the target router in the decrypted information is matched with the verification information to obtain a matching result; If the matching result indicates a successful match, a routing connection is established between the target terminal and the target router via short-range wireless communication.

2. The method according to claim 1, characterized in that, Before receiving the encrypted information reported by the target terminal, the method further includes: Receive a connection request from a target terminal, wherein the connection request contains terminal information of the target terminal; After the target terminal is verified based on the connection request, a connection is established between the target terminal and the security authentication platform. The target key pair is sent to the target terminal.

3. The method according to claim 1 or 2, characterized in that, The step of establishing a routing connection between the target terminal and the target router via short-range wireless communication includes: Authorization information is sent to both the target terminal and the target router; so that the target terminal sends a connection request containing the authorization information to the target router; and so that the target router verifies the received connection request based on the authorization information, and establishes a routing connection between the target terminal and the target router through short-range wireless communication after successful verification.

4. A routing connection method, characterized in that, The method is executed by the target terminal, and the method includes: Obtain verification information; The SSID of the target router and the verification information are encrypted using the encryption key in the target key pair issued by the security authentication platform to obtain encrypted information; Report the encrypted information to the security authentication platform; After receiving the routing connection operation from the security authentication platform, a routing connection is established with the target router via short-range wireless communication. The routing connection operation is performed by the security authentication platform after decrypting the encrypted information, matching the SSID of the target router in the decrypted information with the verification information, and the matching result indicates a successful match.

5. The method according to claim 4, characterized in that, The acquisition of verification information includes: The system receives encrypted account information broadcast by the target router; the encrypted account information is generated by the security authentication platform encrypting the SSID of the target router using the encryption key in the target key pair and then sending it to the target router. The encrypted account information is decrypted using the decryption key in the target key pair to obtain the SSID of the target router; The verification information is obtained based on the SSID of the target router.

6. The method according to claim 4, characterized in that, The establishment of a routing connection with the target router via short-range wireless communication includes: Receive authorization information sent by the target router; A connection request containing the authorization information is sent to the target router, so that the target router verifies the connection request based on the authorization information issued by the security authentication platform, and establishes a routing connection between the target terminal and the target router through short-range wireless communication after successful verification.

7. A routing connection device, characterized in that, The device is used in a security authentication platform, and the device includes: The first information receiving module is used to receive encrypted information reported by the target terminal. The encrypted information is obtained by the target terminal encrypting the service set identifier (SSID) of the target router and the verification information using the encryption key in the target key pair. The target key pair is dynamically issued to the target terminal by the security authentication platform. The decryption module is used to decrypt the encrypted information using the decryption key in the target key pair to obtain decrypted information; The matching module is used to match the SSID of the target router in the decryption information with the verification information to obtain a matching result; The first connection establishment module is used to establish a routing connection between the target terminal and the target router via short-range wireless communication when the matching result indicates a successful match.

8. A computer device, characterized in that, The computer device includes a processor and a memory, the memory storing at least one computer program, which is loaded and executed by the processor to implement the routing connection method as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one computer program, which is loaded and executed by a processor to implement the routing connection method as described in any one of claims 1 to 6.

10. A computer program product, characterized in that, The computer program product includes a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a computer device, cause the computer device to perform the routing connection method as described in any one of claims 1 to 6.