WO2018076369A1 - 通信安全等级切换的方法、系统、家电设备和移动终端 - Google Patents

通信安全等级切换的方法、系统、家电设备和移动终端 Download PDF

Info

Publication number
WO2018076369A1
WO2018076369A1 PCT/CN2016/104118 CN2016104118W WO2018076369A1 WO 2018076369 A1 WO2018076369 A1 WO 2018076369A1 CN 2016104118 W CN2016104118 W CN 2016104118W WO 2018076369 A1 WO2018076369 A1 WO 2018076369A1
Authority
WO
WIPO (PCT)
Prior art keywords
communication mode
mobile terminal
key
home appliance
communication
Prior art date
Application number
PCT/CN2016/104118
Other languages
English (en)
French (fr)
Inventor
邹伟
Original Assignee
美的智慧家居科技有限公司
美的集团股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 美的智慧家居科技有限公司, 美的集团股份有限公司 filed Critical 美的智慧家居科技有限公司
Priority to PCT/CN2016/104118 priority Critical patent/WO2018076369A1/zh
Publication of WO2018076369A1 publication Critical patent/WO2018076369A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method, system, home appliance, and mobile terminal for switching a communication security level.
  • the present invention aims to solve at least one of the technical problems in the related art to some extent.
  • the first object of the present invention is to provide a method for dynamically switching communication security levels, complete the switching of the communication mode, improve the security level of the communication of the household electrical appliance, and improve the communication between the mobile terminal and the household electrical appliance. safety.
  • a second object of the present invention is to provide a method for dynamically switching communication security levels.
  • a third object of the present invention is to provide a WIFI module for a household electrical appliance.
  • a fourth object of the present invention is to provide a mobile terminal.
  • a fifth object of the present invention is to provide a home appliance.
  • a sixth object of the present invention is to provide a system for dynamically switching communication security levels.
  • the first aspect of the present invention provides a method for dynamically switching a communication security level, including the following steps: the home appliance receives a first switching instruction sent by the mobile terminal, and the first switching instruction is used to indicate that Switching the first communication mode to a second communication mode, wherein a security level of the second communication mode is higher than the first communication mode; and the household electrical appliance switches the first communication mode to the second communication mode And broadcasting to the surrounding contains the first cut Transmitting a UDP packet of the success message; the home appliance performs key agreement with the mobile terminal to generate a first key of the second communication mode; and the home appliance passes the first key and the mobile The terminal performs data communication.
  • the home appliance receives the first switching instruction sent by the mobile terminal to switch the first communication mode to the second communication mode, and switches the first communication mode to the second communication mode. And broadcasting the UDP packet including the first handover success message to the surroundings, and then the home appliance performs key agreement with the mobile terminal to generate a first key of the second communication mode, and the home appliance performs the first key with the mobile terminal. data communication. Thereby, the switching of the communication mode is completed, the security level of communication of the home appliance is improved, and the security of communication between the mobile terminal and the home appliance is improved.
  • the household electrical appliance switches the first communication mode to the second communication mode, including:
  • the home appliance determines whether there is a right key of the second communication mode
  • the household appliance performs the step of switching the first communication mode to the second communication mode.
  • the method further includes:
  • the home appliance performs key agreement with the server to acquire the authority key.
  • the home appliance performs key agreement with the mobile terminal to generate the first key of the second communication mode, including:
  • the home appliance performs key agreement with the mobile terminal according to the session token and the authority key to generate the first key.
  • the method further includes:
  • the home appliance acquires a second key of the first communication mode, and switches the second communication mode to the first communication mode;
  • the home appliance broadcasts a UDP packet including a second handover success message to the surroundings;
  • the home device performs data communication with the mobile terminal through the second key.
  • the method further includes:
  • a second aspect of the present invention provides a method for dynamically switching a communication security level, including the following steps: a mobile terminal sends a first switching instruction to a home appliance, where the first switching instruction is used to indicate The home appliance switches a first communication mode to a second communication mode, wherein a security level of the second communication mode is higher than the first communication mode; and the mobile terminal receives the first broadcast included by the home appliance Switching a UDP packet of the success message; the mobile terminal performs key agreement with the home appliance to generate a first key of the second communication mode; and the mobile terminal passes the first key and the mobile The terminal performs data communication.
  • the UDP packet containing the first handover success message is broadcasted, and then the mobile terminal performs key agreement with the home appliance to generate a first key of the second communication mode, and the mobile terminal performs data communication with the mobile terminal by using the first key.
  • the user can enhance the security level of communication of the home appliance by one button of the mobile terminal, improve the security of communication between the mobile terminal and the home appliance, and satisfy the requirement of the user to switch the security level of the communication of the home appliance.
  • the mobile terminal performs key agreement with the home appliance to generate the first key of the second communication mode, including:
  • the mobile terminal acquires, from the server, a session token required when the home appliance is in the second communication mode;
  • the mobile terminal performs key agreement with the home appliance by using the session token to generate a first key of the second communication mode.
  • the method further includes:
  • the mobile terminal sends a second switching instruction to the home appliance, where the second switching instruction is used to instruct the home appliance to switch the second communication mode to the first communication mode switching;
  • the mobile terminal acquires a key corresponding to the first communication mode, and performs data communication with the mobile terminal by using a key corresponding to the first communication mode.
  • the method further includes:
  • the mobile terminal controls the first key to be invalid.
  • a third aspect of the present invention provides a WIFI module of a home appliance, comprising: a receiving submodule, configured to receive a first switching instruction sent by the mobile terminal, where the first switching instruction is used to indicate that The first communication mode is switched to the second communication mode, wherein the second communication mode has a higher security level than the first communication mode; and the first switching submodule is configured to switch the first communication mode to the Second communication mode; broadcast sub-module for weekly Broadcasting a UDP packet including a first handover success message; generating a submodule for performing key agreement with the mobile terminal to generate a first key of the second communication mode; and a first communication submodule for Data communication with the mobile terminal is performed by the first key.
  • the WIFI module of the household electrical appliance receives, by the receiving submodule, a first switching instruction that is sent by the mobile terminal to switch the first communication mode to the second communication mode, and uses the first switching submodule to set the first communication mode. Switching to the second communication mode, and broadcasting the UDP packet including the first handover success message to the surroundings through the broadcast submodule, and then performing key agreement with the mobile terminal by using the generation submodule to generate the first key of the second communication mode And the first communication module performs data communication with the mobile terminal through the first key. Thereby, the switching of the communication mode is completed, the security level of communication of the home appliance is improved, and the security of communication between the mobile terminal and the home appliance is improved.
  • the method further includes:
  • a determining submodule configured to determine whether a permission key of the second communication mode exists
  • the first switching submodule is further configured to switch the first communication mode to the second communication mode when determining that the right key of the second communication mode exists.
  • the method further includes:
  • the obtaining submodule is configured to perform key negotiation with the server to obtain the authority key when determining that the right key of the second communication mode does not exist.
  • the generating submodule is specifically configured to:
  • the method further includes:
  • the first processing submodule acquires the second key of the first communication mode by receiving a second switching instruction sent by the mobile terminal to indicate that the second communication mode is switched to the first communication mode And switching the second communication mode to the first communication mode, and broadcasting a UDP packet including a second handover success message to the surroundings, and performing data communication with the mobile terminal by using the second key.
  • the method further includes:
  • a second processing submodule configured to, after the reconnection with the mobile terminal, control the home appliance to perform key negotiation with the mobile terminal to generate a third key of the second communication mode.
  • a fourth aspect of the present invention provides a mobile terminal, where the mobile terminal includes a sending module, configured to send a first switching instruction to a home appliance, where the first switching instruction is used to indicate The home appliance switches the first communication mode to the second communication mode, wherein the security level of the second communication mode is higher than the first communication mode; and the first receiving module is configured to receive the broadcast of the home appliance a UDP packet of the first handover success message; a negotiation module, configured to perform key negotiation with the home appliance to enable the home appliance to generate a first mode of the second communication mode a second receiving module, configured to receive the first key sent by the home appliance, and a communication module, configured to perform data communication with the mobile terminal by using the first key.
  • the mobile terminal receives the UDP packet including the first handover success message broadcasted by the home appliance, and then The mobile terminal performs key agreement with the home appliance to generate a first key of the second communication mode, and the mobile terminal performs data communication with the mobile terminal by using the first key.
  • the user can enhance the security level of communication of the home appliance by one button of the mobile terminal, improve the security of communication between the mobile terminal and the home appliance, and satisfy the requirement of the user to switch the security level of the communication of the home appliance.
  • the negotiation module is specifically configured to:
  • the method further includes:
  • a first processing module configured to send, to the home appliance, a second switching instruction for instructing the home appliance to switch the second communication mode to the first communication mode, and receive the home appliance broadcast
  • the UDP packet including the second handover success message acquires a key corresponding to the first communication mode, and performs data communication with the mobile terminal by using a key corresponding to the first communication mode.
  • the method further includes:
  • a second processing module configured to control the first key to be invalid when disconnected from the home appliance.
  • a fifth aspect of the present invention provides a household electrical appliance, including a WIFI module of the household electrical appliance of the third aspect of the present invention.
  • the household electrical appliance receives the first switching instruction of the mobile terminal to switch the first communication mode to the second communication mode, and switches the first communication mode to the second communication mode, and broadcasts to the surrounding
  • the UDP packet includes the first handover success message, and then the home appliance performs key agreement with the mobile terminal to generate a first key of the second communication mode, and the home appliance performs data communication with the mobile terminal by using the first key.
  • the switching of the communication mode is completed, the security level of communication of the home appliance is improved, and the security of communication between the mobile terminal and the home appliance is improved.
  • a sixth aspect of the present invention provides a system for dynamically switching a communication security level, including the mobile terminal of the fourth aspect of the present invention and the household electrical appliance of the fifth aspect of the present invention.
  • a system for dynamically switching a communication security level the home appliance receiving a first switching instruction sent by the mobile terminal to switch the first communication mode to the second communication mode, and switching the first communication mode to the second communication mode And broadcasting the UDP packet including the first handover success message to the surroundings, and then the home appliance performs key agreement with the mobile terminal to generate a first key of the second communication mode, and the home appliance performs the first key with the mobile terminal. data communication.
  • the switching of the communication mode is completed, the security level of communication of the household electrical appliance is improved, and the mobile terminal and the household electrical appliance are improved. The security of communication between.
  • FIG. 1 is a flow chart of a method for dynamic switching of communication security levels in accordance with one embodiment of the present invention
  • FIG. 2 is a flow chart of a method for dynamically switching a communication security level according to another embodiment of the present invention.
  • FIG. 3 is a flow chart of a method for dynamically switching a communication security level according to still another embodiment of the present invention.
  • FIG. 4 is a flow chart of a method for dynamically switching a communication security level according to still another embodiment of the present invention.
  • FIG. 5 is a flowchart of a method for dynamically switching a communication security level according to another embodiment of the present invention.
  • FIG. 6 is an interaction flowchart of a method for dynamically switching a communication security level according to an embodiment of the present invention
  • FIG. 7 is a schematic structural diagram of a WIFI module of a household electrical appliance according to an embodiment of the present invention.
  • FIG. 8 is a schematic structural diagram of a WIFI module of a household electrical appliance according to another embodiment of the present invention.
  • FIG. 9 is a schematic structural diagram of a WIFI module of a household electrical appliance according to another embodiment of the present invention.
  • FIG. 10 is a schematic structural diagram of a WIFI module of a household electrical appliance according to still another embodiment of the present invention.
  • FIG. 11 is a schematic structural diagram of a mobile terminal according to an embodiment of the present invention.
  • FIG. 12 is a schematic structural diagram of a mobile terminal according to another embodiment of the present invention.
  • FIG. 1 is a flow chart of a method of dynamic switching of communication security levels in accordance with one embodiment of the present invention.
  • the method for dynamically switching the communication security level includes the following steps:
  • the home appliance receives the first switching instruction sent by the mobile terminal.
  • the first switching instruction is used to indicate that the first communication mode is switched to the second communication mode, wherein the security level of the second communication mode is higher than the first communication mode.
  • the first communication mode refers to communication by means of a fixed key and a symmetric key algorithm.
  • the second communication mode refers to communication by using a dynamic key and a symmetric key algorithm.
  • the mobile terminal may be, for example, a hardware device having various operating systems, such as a mobile phone, a tablet computer, or a personal digital assistant.
  • the home appliance may be, for example, a device such as a smart TV, a refrigerator, or a smart washing machine.
  • the user in the process of controlling the home appliance by the mobile terminal, can view the communication mode between the mobile terminal and the home appliance through the mobile terminal, and can adjust the communication mode of the home appliance according to requirements, wherein the communication mode corresponds to the security The level is different.
  • the mobile terminal in the process of communicating between the mobile terminal and the home appliance in the first communication mode, if the mobile terminal receives an external command to switch the home appliance from the first communication mode to the second communication mode The mobile terminal will send a first switching instruction to the home appliance. Correspondingly, the home appliance receives the first switching instruction sent by the mobile terminal.
  • the home appliance switches the first communication mode to the second communication mode, and broadcasts a UDP packet including the first handover success message to the surroundings.
  • the home appliance informs the mobile terminal that the mobile terminal has switched to the second communication mode by UDP broadcast.
  • the home appliance performs key agreement with the mobile terminal to generate a first key of the second communication mode.
  • the mobile terminal when the mobile terminal determines that the home appliance has switched to the second communication mode, the mobile terminal negotiates with the home appliance according to a preset key agreement protocol, and after the negotiation is passed, the home appliance according to the advance
  • the set key generation rule generates a first key of the second communication mode.
  • the first key is encrypted by the public key used by the mobile terminal to generate encrypted information, and the encrypted information is transmitted to the mobile terminal.
  • the mobile terminal decrypts the encrypted information to obtain the first key.
  • the mobile terminal when the mobile terminal determines that the home appliance has switched to the second communication mode, the mobile terminal sends a key agreement request including the session token to the home appliance, and the home appliance uses its own authority key pair.
  • the privilege token is decrypted to obtain the random number K1, and a random K2 is generated, and the random number K2 is encrypted with the random number K1 to generate a ciphertext, and the ciphertext is sent to the mobile terminal, and the mobile terminal decrypts the ciphertext to Get the random number K2.
  • the mobile terminal generates the first key by using the random number K1 and the random number K2. For example, the mobile terminal takes the exclusive value of the random number K1 and the random number K2 as the first key.
  • the session token in the mobile terminal is obtained from the server, and the session token includes a random number K1.
  • the process of the mobile terminal acquiring the session token from the server is: the mobile terminal sends a query request including the identity information of the mobile terminal and the identity information of the home appliance to the server.
  • the server determines, according to the identification information of the mobile terminal and the identification information of the home appliance, whether the mobile terminal has the right to control the home appliance, and when determining that the mobile terminal has the right to control the corresponding home appliance, the server acquires the session token communicated with the home appliance, and moves to the mobile device.
  • the terminal returns a session token that communicates with the home appliance.
  • the session token is generated by the server according to the authority key sent to the home appliance.
  • the process of generating the session token by the server is: the server randomly generates the random number K1, and encrypts the random number K1 with the authority key sent by the server to the home appliance to form an intermediate quantity K1s, and then, the intermediate quantity K1s and The values of the SHA-256 of the random number K1 are spliced to form a session token.
  • the home appliance performs data communication with the mobile terminal by using the first key.
  • the home appliance receives the first switching instruction sent by the mobile terminal to switch the first communication mode to the second communication mode, and switches the first communication mode to the second communication mode. And broadcasting the UDP packet including the first handover success message to the surroundings, and then the home appliance performs key agreement with the mobile terminal to generate a first key of the second communication mode, and the home appliance performs the first key with the mobile terminal. data communication. Thereby, the switching of the communication mode is completed, the security level of communication of the home appliance is improved, and the security of communication between the mobile terminal and the home appliance is improved.
  • the home appliance after the home appliance communicates with the mobile terminal through the first key, if the home appliance reconnects with the mobile terminal, the home appliance and the mobile terminal are controlled to be re-executed. Key negotiation to generate a third key of the second communication mode.
  • the keys of the second communication mode are generated after the home appliance and the mobile terminal re-key negotiation.
  • the home appliance receives a second switching instruction sent by the mobile terminal, and the second switching instruction is used to instruct to switch the second communication mode to the first communication mode.
  • the home appliance acquires a second key of the first communication mode, and switches the second communication mode to the first communication mode.
  • the home appliance broadcasts a UDP packet including the second handover success message to the surroundings.
  • the home device performs data communication with the mobile terminal by using the second key.
  • the user can further adjust the communication mode of the home appliance and the mobile terminal to the first communication mode through the mobile terminal.
  • FIG. 3 is a flow chart of a method of dynamic switching of communication security levels in accordance with yet another embodiment of the present invention.
  • the method for dynamically switching the communication security level includes the following steps:
  • the home appliance receives the first switching instruction sent by the mobile terminal.
  • the first switching instruction is used to indicate that the first communication mode is switched to the second communication mode, wherein the security level of the second communication mode is higher than the first communication mode.
  • the first communication mode refers to communication by means of a fixed key and a symmetric key algorithm.
  • the second communication mode refers to communication by using a dynamic key and a symmetric key algorithm.
  • the mobile terminal may be, for example, a mobile phone, a tablet computer, a personal digital assistant, or the like having various operating systems. device.
  • the home appliance may be, for example, a device such as a smart TV, a refrigerator, or a smart washing machine.
  • the user in the process of controlling the home appliance by the mobile terminal, can view the communication mode between the mobile terminal and the home appliance through the mobile terminal, and can adjust the communication mode of the home appliance according to requirements, wherein the communication mode corresponds to the security The level is different.
  • the mobile terminal in the process of communicating between the mobile terminal and the home appliance in the first communication mode, if the mobile terminal receives an external command to switch the home appliance from the first communication mode to the second communication mode The mobile terminal will send a first switching instruction to the home appliance. Correspondingly, the home appliance receives the first switching instruction sent by the mobile terminal.
  • step S32 The home appliance determines whether there is a right key of the second communication mode. If not, step S33 is performed, and step S34 is performed; if yes, step S34 is performed.
  • the home appliance performs key negotiation with the server to obtain a permission key.
  • the home appliance switches the first communication mode to the second communication mode.
  • the home appliance broadcasts a UDP packet including the first handover success message to the surroundings.
  • the home appliance receives the key negotiation request sent by the mobile terminal.
  • the key negotiation request includes a session token.
  • the session token is obtained by the mobile terminal from the server.
  • the mobile terminal determines that the home appliance has switched to the second communication mode
  • the mobile terminal sends a query request of the second communication mode to the server.
  • the query request includes the identification information of the mobile terminal and the identification information of the home appliance.
  • the server determines, according to the identification information of the mobile terminal and the identification information of the home appliance, whether the mobile terminal has the right to control the home appliance, and when determining that the mobile terminal has the right to control the corresponding home appliance, the server acquires the session token that communicates with the home appliance. And returning to the mobile terminal a session token that communicates with the home appliance.
  • the session token is generated by the server according to the authority key sent to the home appliance.
  • the process of generating the session token by the server is: the server randomly generates the random number K1, and encrypts the random number K1 with the authority key sent by the server to the home appliance to form an intermediate quantity K1s, and then, the intermediate quantity K1s and The values of the SHA-256 of the random number K1 are spliced to form a session token.
  • the home appliance performs key agreement with the mobile terminal according to the session token and the authority key to generate a first key.
  • the mobile terminal sends a key agreement request including the session token to the home appliance, and the home appliance decrypts the authority token with its own authority key to obtain the random number K1, and generates a random K2, and uses the random number K1
  • the random number K2 is encrypted to generate a ciphertext
  • the ciphertext is sent to the mobile terminal, and the mobile terminal decrypts the ciphertext to obtain the random number K2.
  • the mobile terminal generates the first key by using the random number K1 and the random number K2. For example, the mobile terminal takes the exclusive value of the random number K1 and the random number K2 as the first key.
  • the home appliance performs data communication with the mobile terminal by using the first key.
  • the home appliance receives the first switching instruction sent by the mobile terminal to switch the first communication mode to the second communication mode, and switches the first communication mode to the second communication mode. And broadcasting the UDP packet including the first handover success message to the surroundings, and then the home appliance performs key negotiation according to the session token and the authority key to generate the first key of the second communication mode, and the home appliance passes the first key The key communicates with the mobile terminal. Thereby, the switching of the communication mode is completed, the security level of communication of the home appliance is improved, and the security of communication between the mobile terminal and the home appliance is improved.
  • FIG. 4 is a flow chart of a method of dynamic switching of communication security levels in accordance with yet another embodiment of the present invention. As shown in FIG. 4, the method for dynamically switching the communication security level is described from the mobile terminal side, and the method for dynamically switching the communication security level includes the following steps:
  • the mobile terminal sends a first switching instruction to the home appliance.
  • the first switching instruction is used to instruct the home appliance to switch the first communication mode to the second communication mode.
  • the second communication mode has a higher security level than the first communication mode.
  • the mobile terminal may be, for example, a hardware device having various operating systems, such as a mobile phone, a tablet computer, or a personal digital assistant.
  • the home appliance may be, for example, a device such as a smart TV, a refrigerator, or a smart washing machine.
  • the user in the process of controlling the home appliance by the mobile terminal, can view the communication mode between the mobile terminal and the home appliance through the mobile terminal, and can adjust the communication mode of the home appliance according to requirements, wherein the communication mode corresponds to the security The level is different.
  • the mobile terminal receives the UDP packet that is broadcast by the home appliance and includes the first handover success message.
  • the mobile terminal performs key agreement with the home appliance to generate a first key of the second communication mode.
  • the mobile terminal may acquire a session token required by the home appliance in the second communication mode from the server, and utilize the session.
  • the token performs key agreement with the home appliance to generate a first key of the second communication mode.
  • the session token is obtained by the mobile terminal from the server.
  • the mobile terminal determines that the home appliance has switched to the second communication mode
  • the mobile terminal sends a query request of the second communication mode to the server.
  • the query request includes the identification information of the mobile terminal and the identification information of the home appliance.
  • the server determines, according to the identification information of the mobile terminal and the identification information of the home appliance, whether the mobile terminal has the right to control the home appliance, and when determining that the mobile terminal has the right to control the corresponding home appliance, the server acquires the current communication between the mobile terminal and the home appliance.
  • the session token used and the session token is sent to the mobile terminal.
  • the session token is generated by the server according to the authority key sent to the home appliance.
  • the process of generating the session token by the server is: the server randomly generates the random number K1, and encrypts the random number K1 with the authority key sent by the server to the home appliance to form an intermediate quantity K1s, and then, the intermediate quantity K1s and The values of the SHA-256 of the random number K1 are spliced to form a session token.
  • the mobile terminal After the mobile terminal acquires the session token from the server, the mobile terminal sends a key agreement request including the session token to the home appliance, and the home appliance decrypts the authority token with its own authority key to obtain the random number K1, and A random K2 is generated, and the random number K2 is encrypted with a random number K1 to generate a ciphertext, and the ciphertext is transmitted to the mobile terminal, and the mobile terminal decrypts the ciphertext to obtain the random number K2. Then, the mobile terminal generates the first key by using the random number K1 and the random number K2. For example, the mobile terminal takes the exclusive value of the random number K1 and the random number K2 as the first key.
  • the mobile terminal when the mobile terminal determines that the home appliance has switched to the second communication mode, the mobile terminal negotiates with the home appliance according to a preset key agreement protocol, and after the negotiation is passed, the home appliance is configured according to A preset key generation rule generates a first key of the second communication mode. Then, the first key is encrypted by the public key used by the mobile terminal to generate encrypted information, and the encrypted information is transmitted to the mobile terminal. Correspondingly, the mobile terminal decrypts the encrypted information to obtain the first key.
  • the mobile terminal performs data communication with the mobile terminal by using the first key.
  • the first switching instruction sent by the mobile terminal to the home appliance for instructing the home appliance to switch the first communication mode to the second communication mode and then the mobile terminal receives the home appliance Broadcasting a UDP packet containing the first handover success message, after which the mobile terminal performs key agreement with the home appliance to generate a first key of the second communication mode, and the mobile terminal performs data communication with the mobile terminal through the first key .
  • the user can enhance the security level of communication of the home appliance by one button of the mobile terminal, improve the security of communication between the mobile terminal and the home appliance, and satisfy the requirement of the user to switch the security level of the communication of the home appliance.
  • the mobile terminal in order to ensure the security of communication between the mobile terminal and the home appliance, after the mobile terminal performs data communication with the mobile terminal through the first key, if the mobile terminal is disconnected from the home appliance, The mobile terminal controls the first key to fail.
  • the method may further include the following steps:
  • the mobile terminal sends a second switching instruction to the home appliance, where the second switching instruction is used to instruct the home appliance to switch the second communication mode to the first communication mode switching.
  • the mobile terminal receives the UDP packet that is broadcast by the home appliance and includes the second handover success message.
  • the mobile terminal acquires a key corresponding to the first communication mode, and performs data communication with the mobile terminal by using a key corresponding to the first communication mode.
  • FIG. 6 is an interaction flow diagram of a method for dynamically switching a communication security level according to an embodiment of the present invention.
  • the home appliance after the home appliance is powered on for the first time, the home appliance periodically communicates with the mobile terminal and the server by using the first communication mode (fixed key, symmetric key) as an example.
  • the communication security level is as shown in FIG. 6
  • the method of dynamic switching can include:
  • the mobile terminal receives a first switching instruction input by the user to switch the home appliance from the first communication mode to the second communication mode.
  • the mobile terminal sends the first switching instruction to the home appliance.
  • the home appliance sends a first key agreement request to the server.
  • the server performs key negotiation with the home appliance according to the first key negotiation request, and obtains a right key of the second communication mode of the home appliance after determining that the negotiation is passed.
  • the home appliance sends a key negotiation request including the identification information of the home device to the server, and the server performs identity verification on the identification information of the home appliance, and after the verification is passed, the server generates the permission of the second communication mode according to the identification information of the home appliance. The key and return the permission key to the home appliance.
  • the server returns a right key of the second communication mode to the home appliance.
  • the home appliance switches the first communication mode to the second communication mode according to the authority key, and broadcasts a UDP packet including the first handover success message to the surroundings.
  • the mobile terminal sends a query request of the second communication mode to the server.
  • the query request includes the identification information of the mobile terminal and the identification information of the home appliance.
  • the server After determining that the mobile terminal passes the verification, the server generates a session token used by the mobile terminal to communicate with the home appliance.
  • the server sends the session token to the mobile terminal.
  • the server determines, according to the identification information of the mobile terminal and the identification information of the home appliance, whether the mobile terminal has the right to control the home appliance, and when determining that the mobile terminal has the right to control the corresponding home appliance, the server acquires the session token communicated with the home appliance.
  • the session token is generated by the server according to the authority key sent to the home appliance.
  • the process of generating the session token by the server is: the server randomly generates the random number K1, and encrypts the random number K1 with the authority key sent by the server to the home appliance to form an intermediate quantity K1s, and then, the intermediate quantity K1s and The values of the SHA-256 of the random number K1 are spliced to form a session token.
  • the mobile terminal performs key negotiation with the home appliance by using the session token to generate a first key of the second communication mode.
  • the mobile terminal sends a key agreement request including the session token to the home appliance, and the home appliance decrypts the authority token with its own authority key to obtain the random number K1, and generates a random K2, and uses the random number K1
  • the random number K2 is encrypted to generate a ciphertext
  • the ciphertext is sent to the mobile terminal, and the mobile terminal decrypts the ciphertext to obtain a random Number K2.
  • the mobile terminal generates the first key by using the random number K1 and the random number K2. For example, the mobile terminal takes the exclusive value of the random number K1 and the random number K2 as the first key.
  • the data communication is performed between the mobile terminal and the home appliance by using the first key.
  • the home appliance receives the first switching instruction sent by the mobile terminal to switch the first communication mode to the second communication mode, and switches the first communication mode to the second communication mode. And broadcasting the UDP packet including the first handover success message to the surroundings, and then the home appliance performs key negotiation according to the session token and the authority key to generate the first key of the second communication mode, and the home appliance passes the first key The key communicates with the mobile terminal. Thereby, the switching of the communication mode is completed, the security level of communication of the home appliance is improved, and the security of communication between the mobile terminal and the home appliance is improved.
  • the present invention also provides a WIFI module of a household electrical appliance.
  • FIG. 7 is a schematic structural diagram of a WIFI module of a household electrical appliance according to an embodiment of the present invention.
  • the WIFI module of the home appliance includes a receiving submodule 111, a first switching submodule 112, a broadcast submodule 113, a generating submodule 114, and a first communication submodule 115, wherein:
  • the receiving submodule 111 is configured to receive a first switching instruction sent by the mobile terminal.
  • the first switching instruction is used to indicate that the first communication mode is switched to the second communication mode.
  • the second communication mode has a higher security level than the first communication mode.
  • the first switching sub-module 112 is configured to switch the first communication mode to the second communication mode.
  • the broadcast sub-module 113 is configured to broadcast a UDP packet containing the first handover success message to the surroundings.
  • the generating sub-module 114 is configured to perform key agreement with the mobile terminal to generate a first key of the second communication mode.
  • the first communication sub-module 115 is configured to perform data communication with the mobile terminal by using the first key.
  • the WIFI module of the household electrical appliance receives, by the receiving submodule, a first switching instruction that is sent by the mobile terminal to switch the first communication mode to the second communication mode, and uses the first switching submodule to set the first communication mode. Switching to the second communication mode, and broadcasting the UDP packet including the first handover success message to the surroundings through the broadcast submodule, and then performing key agreement with the mobile terminal by using the generation submodule to generate the first key of the second communication mode And the first communication module performs data communication with the mobile terminal through the first key. Thereby, the switching of the communication mode is completed, the security level of communication of the home appliance is improved, and the security of communication between the mobile terminal and the home appliance is improved.
  • the WIFI module of the household electrical appliance may further include a determining sub-module 116, wherein the determining sub- The module 116 is configured to determine whether there is a right key of the second communication mode.
  • the first switching sub-module 112 is further configured to switch the first communication mode to the second communication mode when determining that the right key of the second communication mode exists.
  • the WIFI module of the home appliance may further include an obtaining submodule 117, wherein the obtaining submodule 117 is configured to determine that the second communication mode does not exist. Key, key negotiation with the server to obtain the permission key.
  • the generating sub-module 114 is specifically configured to: receive a key negotiation request that includes a session token sent by the mobile terminal, perform key negotiation with the mobile terminal according to the session token and the authority key, to generate The first key.
  • the WIFI module of the home appliance may further include a first processing sub-module 118, wherein the first processing sub-module 118 is used.
  • the configuration of the first processing sub-module 118 in the WIFI module of the household electrical appliance shown in FIG. 9 may also be included in the apparatus embodiment of FIG. 8 described above, and the present invention is not limited thereto.
  • the WIFI module of the household electrical appliance may further include a second processing sub-module 119, wherein the second processing sub-module 119 is used.
  • the home appliance is controlled to re-key negotiation with the mobile terminal to generate a third key of the second communication mode.
  • the structure of the second processing submodule 119 in the WIFI module of the household electrical appliance shown in FIG. 10 may also be included in the foregoing apparatus embodiments of FIG. 8 and FIG. 9, and the present invention is not limited thereto. .
  • the present invention also proposes a home appliance.
  • a household electrical appliance comprising a WIFI module of the household electrical appliance of the above embodiment of the invention.
  • the household electrical appliance receives the first switching instruction of the mobile terminal to switch the first communication mode to the second communication mode, and switches the first communication mode to the second communication mode, and broadcasts to the surrounding
  • the UDP packet includes the first handover success message, and then the home appliance performs key agreement with the mobile terminal to generate a first key of the second communication mode, and the home appliance performs data communication with the mobile terminal by using the first key.
  • the switching of the communication mode is completed, the security level of communication of the home appliance is improved, and the security of communication between the mobile terminal and the home appliance is improved.
  • the present invention also proposes a mobile terminal.
  • FIG. 11 is a schematic structural diagram of a mobile terminal according to an embodiment of the present invention.
  • the mobile terminal includes a sending module 210, a first receiving module 220, a negotiating module 230, and a communication module 240, where:
  • the sending module 210 is configured to send a first switching instruction to the home appliance.
  • the first switching instruction is used to instruct the home appliance to switch the first communication mode to the second communication mode.
  • the second communication mode has a higher security level than the first communication mode.
  • the first receiving module 220 is configured to receive a UDP packet that is broadcast by the home appliance and includes a first handover success message.
  • the negotiation module 230 is configured to perform key agreement with the home appliance to generate a first key of the second communication mode.
  • the communication module 240 is configured to perform data communication with the mobile terminal by using the first key.
  • the negotiation module 230 is specifically configured to: acquire a session token required by the home appliance in the second communication mode from the server, and perform key negotiation with the home appliance by using the session token, A first key of the second communication mode is generated.
  • the mobile terminal may further include a first processing module 250, where:
  • the first processing module 250 is configured to send, to the home appliance, a second switching instruction for instructing the home appliance to switch the second communication mode to the first communication mode, and receive the UDP packet that is included in the home appliance and includes the second handover success message. Obtaining a key corresponding to the first communication mode, and performing data communication with the mobile terminal by using a key corresponding to the first communication mode.
  • the mobile terminal may further include a second processing module 260, where:
  • the second processing module 260 is configured to control the first key to be invalid when disconnected from the home appliance.
  • the first switching instruction sent by the mobile terminal to the home appliance for instructing the home appliance to switch the first communication mode to the second communication mode and then the mobile terminal receives the first broadcast of the home appliance
  • the mobile terminal performs key agreement with the home appliance to generate a first key of the second communication mode, and the mobile terminal performs data communication with the mobile terminal by using the first key.
  • the present invention also proposes a system for dynamically switching communication security levels.
  • the system for dynamically switching the communication security level may include a mobile terminal and a home appliance.
  • a system for dynamically switching a communication security level the home appliance receiving a first switching instruction sent by the mobile terminal to switch the first communication mode to the second communication mode, and switching the first communication mode to the second communication mode And broadcasting the UDP packet including the first handover success message to the surroundings, and then the home appliance performs key agreement with the mobile terminal to generate a first key of the second communication mode, and the home appliance performs the first key with the mobile terminal. data communication.
  • the switching of the communication mode is completed, the security level of communication of the household electrical appliance is improved, and the security of communication between the mobile terminal and the household electrical appliance is improved.
  • first and second are used for descriptive purposes only and are not to be construed as indicating or implying a relative importance or implicitly indicating the number of technical features indicated.
  • features defining “first” or “second” may include at least one of the features, either explicitly or implicitly.
  • the meaning of "a plurality” is at least two, such as two, three, etc., unless specifically defined otherwise.
  • the terms “installation”, “connected”, “connected”, “fixed” and the like shall be understood broadly, and may be either a fixed connection or a detachable connection, unless explicitly stated and defined otherwise. , or integrated; can be mechanical or electrical connection; can be directly connected, or indirectly connected through an intermediate medium, can be the internal communication of two elements or the interaction of two elements, unless otherwise specified Limited.
  • the specific meanings of the above terms in the present invention can be understood on a case-by-case basis.

Abstract

本发明公开了一种通信安全等级动态切换的方法、系统、家电设备和移动终端,其中,该方法包括:家电设备接收移动终端发送的第一切换指令,第一切换指令用于指示将第一通信模式切换为第二通信模式,其中,第二通信模式的安全等级高于第一通信模式;家电设备将第一通信模式切换为第二通信模式,并向周围广播包含第一切换成功消息的UDP包;家电设备与移动终端进行密钥协商,以生成第二通信模式的第一密钥;家电设备通过第一密钥与移动终端进行数据通信。本发明实施例提供的通信安全等级动态切换的方法,完成了通信模式的切换,提升了家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性。

Description

通信安全等级切换的方法、系统、家电设备和移动终端 技术领域
本发明涉及通信技术领域,特别涉及一种通信安全等级切换的方法、系统、家电设备和移动终端。
背景技术
在移动互联网、物联网、云计算浪潮的席卷下,智能家居行业被重新定义,其中以智能家电为代表的相关行业得到高速的发展,在快速发展下而产生的安全问题愈来愈凸显。
目前,在通过移动终端对智能家电设备进行控制的过程中,为了保证通信安全,移动终端与智能家电设备之间通常采用固定密钥,使用对称加密算法对通信数据进行加密。然而,在通信过程中,由于每次通信所使用的密钥均是固定的,如果密钥一旦泄漏,容易导致家电设备收到攻击,并且由于家电设备中仅提供一种安全等级的通信方式,使得用户不能根据需求自由选择家电通信的安全等级。
发明内容
本发明旨在至少在一定程度上解决相关技术中的技术问题之一。
为此,本发明的第一个目的在于提出一种通信安全等级动态切换的方法,完成了通信模式的切换,提升了家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性。
本发明的第二个目的在于提出一种通信安全等级动态切换的方法。
本发明的第三个目的在于提出一种家电设备的WIFI模块。
本发明的第四个目的在于提出一种移动终端。
本发明的第五个目的在于提出一种家电设备。
本发明的第六个目的在于提出一种通信安全等级动态切换的系统。
为实现上述目的,本发明第一方面实施例提出了一种通信安全等级动态切换的方法,包括以下步骤:家电设备接收移动终端发送的第一切换指令,所述第一切换指令用于指示将第一通信模式切换为第二通信模式,其中,所述第二通信模式的安全等级高于所述第一通信模式;所述家电设备将所述第一通信模式切换为所述第二通信模式,并向周围广播包含第一切 换成功消息的UDP包;所述家电设备与所述移动终端进行密钥协商,以生成所述第二通信模式的第一密钥;所述家电设备通过所述第一密钥与所述移动终端进行数据通信。
根据本发明实施例的通信安全等级动态切换的方法,家电设备接收移动终端发送的将第一通信模式切换为第二通信模式的第一切换指令,并将第一通信模式切换为第二通信模式,并向周围广播包含第一切换成功消息的UDP包,然后,家电设备与移动终端进行密钥协商,以生成第二通信模式的第一密钥,家电设备通过第一密钥与移动终端进行数据通信。由此,完成了通信模式的切换,提升了家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性。
在本发明的一个实施例中,所述家电设备将所述第一通信模式切换为所述第二通信模式,包括:
所述家电设备判断是否存在所述第二通信模式的权限密钥;
若存在,则所述家电设备执行将所述第一通信模式切换为所述第二通信模式的步骤。
在本发明的一个实施例中,还包括:
若判断出不存在所述第二通信模式的权限密钥,则所述家电设备与服务器进行密钥协商,以获取所述权限密钥。
在本发明的一个实施例中,所述家电设备与所述移动终端进行密钥协商,以生成所述第二通信模式的第一密钥,包括:
所述家电设备接收所述移动终端发送的密钥协商请求,其中,所述密钥协商请求包括会话令牌;
所述家电设备根据所述会话令牌和所述权限密钥与所述移动终端进行密钥协商,以生成所述第一密钥。
在本发明的一个实施例中,在所述家电设备通过所述第一密钥与所述移动终端进行通信之后,还包括:
所述家电设备接收所述移动终端发送的第二切换指令,所述第二切换指令用于指示将所述第二通信模式切换为所述第一通信模式;
所述家电设备获取所述第一通信模式的第二密钥,并将所述第二通信模式切换为所述第一通信模式;
所述家电设备向周围广播包含第二切换成功消息的UDP包;
所述家用设备通过所述第二密钥与所述移动终端进行数据通信。
在本发明的一个实施例中,在所述家电设备通过所述第一密钥与所述移动终端进行通信之后,还包括:
如果所述家电设备与移动终端重连,则控制所述家电设备与所述移动终端重新进行密钥 协商,以生成所述第二通信模式的第三密钥。
为实现上述目的,本发明第二方面实施例提出了一种通信安全等级动态切换的方法,包括以下步骤:移动终端向家电设备发送第一切换指令,其中,所述第一切换指令用于指示所述家电设备将第一通信模式切换为第二通信模式,其中,所述第二通信模式的安全等级高于所述第一通信模式;所述移动终端接收所述家电设备广播的包含第一切换成功消息的UDP包;所述移动终端与所述家电设备进行密钥协商,以生成所述第二通信模式的第一密钥;所述移动终端通过所述第一密钥与所述移动终端进行数据通信。
根据本发明实施例的通信安全等级动态切换的方法,移动终端向家电设备发送的用于指示家电设备将第一通信模式切换为第二通信模式的第一切换指令,然后,移动终端接收家电设备广播的包含第一切换成功消息的UDP包,之后,移动终端与家电设备进行密钥协商,以生成第二通信模式的第一密钥,移动终端通过第一密钥与移动终端进行数据通信。由此,使得用户可通过移动终端一键提升家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性,满足了用户切换家电设备的通信的安全等级的需求。
在本发明的一个实施例中,所述移动终端与所述家电设备进行密钥协商,以生成所述第二通信模式的第一密钥,包括:
所述移动终端从服务器中获取与所述家电设备以所述第二通信模式时所需的会话令牌;
所述移动终端利用所述会话令牌与所述家电设备进行密钥协商,以生成所述第二通信模式的第一密钥。
在本发明的一个实施例中,在所述移动终端通过所述第一密钥与所述移动终端进行数据通信之后,还包括:
所述移动终端向所述家电设备发送第二切换指令,所述第二切换指令用于指示所述家电设备将所述第二通信模式切换为所述第一通信模式切换;
所述移动终端接收所述家电设备广播的包含第二切换成功消息的UDP包;
所述移动终端获取所述第一通信模式对应的密钥,并通过所述第一通信模式对应的密钥与所述移动终端进行数据通信。
在本发明的一个实施例中,在所述移动终端通过所述第一密钥与所述移动终端进行数据通信之后,还包括:
如果所述移动终端与所述家电设备断开连接,则所述移动终端控制所述第一密钥失效。
为实现上述目的,本发明第三方面实施例提出了一种家电设备的WIFI模块,包括:接收子模块,用于接收移动终端发送的第一切换指令,所述第一切换指令用于指示将第一通信模式切换为第二通信模式,其中,所述第二通信模式的安全等级高于所述第一通信模式;第一切换子模块,用于将所述第一通信模式切换为所述第二通信模式;广播子模块,用于向周 围广播包含第一切换成功消息的UDP包;生成子模块,用于与所述移动终端进行密钥协商,以生成所述第二通信模式的第一密钥;第一通信子模块,用于通过所述第一密钥与所述移动终端进行数据通信。
根据本发明实施例的家电设备的WIFI模块,通过接收子模块接收移动终端发送的将第一通信模式切换为第二通信模式的第一切换指令,并通过第一切换子模块将第一通信模式切换为第二通信模式,并通过广播子模块向周围广播包含第一切换成功消息的UDP包,然后,通过生成子模块与移动终端进行密钥协商,以生成第二通信模式的第一密钥,以及第一通信模块通过第一密钥与移动终端进行数据通信。由此,完成了通信模式的切换,提升了家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性。
在本发明的一个实施例中,还包括:
判断子模块,用于判断是否存在所述第二通信模式的权限密钥;
其中,所述第一切换子模块,还用于在判定存在所述第二通信模式的权限密钥时,则将所述第一通信模式切换为所述第二通信模式。
在本发明的一个实施例中,还包括:
获取子模块,用于在判断出不存在所述第二通信模式的权限密钥,与服务器进行密钥协商,以获取所述权限密钥。
在本发明的一个实施例中,所述生成子模块,具体用于:
接收所述移动终端发送的包含会话令牌的密钥协商请求,根据所述会话令牌和所述权限密钥与所述移动终端进行密钥协商,以生成所述第一密钥。
在本发明的一个实施例中,还包括:
第一处理子模块,用接收所述移动终端发送的用于指示将所述第二通信模式切换为所述第一通信模式的第二切换指令,获取所述第一通信模式的第二密钥,并将所述第二通信模式切换为所述第一通信模式,以及向周围广播包含第二切换成功消息的UDP包,通过所述第二密钥与所述移动终端进行数据通信。
在本发明的一个实施例中,还包括:
第二处理子模块,用于在与所述移动终端的重连时,控制所述家电设备与所述移动终端重新进行密钥协商,以生成所述第二通信模式的第三密钥。
为实现上述目的,本发明第四方面实施例提出了一种移动终端,所述移动终端包括发送模块,用于向家电设备发送第一切换指令,其中,所述第一切换指令用于指示所述家电设备将第一通信模式切换为第二通信模式,其中,所述第二通信模式的安全等级高于所述第一通信模式;第一接收模块,用于接收所述家电设备广播的包含第一切换成功消息的UDP包;协商模块,用于与所述家电设备进行密钥协商,以使所述家电设备生成第二通信模式的第一 密钥;第二接收模块,用于接收所述家电设备发送的所述第一密钥;通信模块,用于通过所述第一密钥与所述移动终端进行数据通信。
移动终端向家电设备发送的用于指示家电设备将第一通信模式切换为第二通信模式的第一切换指令,然后,移动终端接收家电设备广播的包含第一切换成功消息的UDP包,之后,移动终端与家电设备进行密钥协商,以生成第二通信模式的第一密钥,移动终端通过第一密钥与移动终端进行数据通信。由此,使得用户可通过移动终端一键提升家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性,满足了用户切换家电设备的通信的安全等级的需求。
在本发明的一个实施例中,所述协商模块,具体用于:
从服务器中获取与所述家电设备以所述第二通信模式时所需的会话令牌,并利用所述会话令牌与所述家电设备进行密钥协商。
在本发明的一个实施例中,还包括:
第一处理模块,用于向所述家电设备发送的用于指示所述家电设备将所述第二通信模式切换为所述第一通信模式切换的第二切换指令,接收所述家电设备广播的包含第二切换成功消息的UDP包,获取所述第一通信模式对应的密钥,并通过所述第一通信模式对应的密钥与所述移动终端进行数据通信。
在本发明的一个实施例中,还包括:
第二处理模块,用于在与所述家电设备断开连接时,控制所述第一密钥失效。
为实现上述目的,本发明第五方面实施例提出了一种家电设备,包括本发明第三方面实施例的家电设备的WIFI模。
根据本发明实施例的家电设备,家电设备接收移动终端发送的将第一通信模式切换为第二通信模式的第一切换指令,并将第一通信模式切换为第二通信模式,并向周围广播包含第一切换成功消息的UDP包,然后,家电设备与移动终端进行密钥协商,以生成第二通信模式的第一密钥,家电设备通过第一密钥与移动终端进行数据通信。由此,完成了通信模式的切换,提升了家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性。
为实现上述目的,本发明第六方面实施例提出了一种通信安全等级动态切换的系统,包括本发明第四方面实施例的移动终端和本发明第五方面实施例的家电设备。
根据本发明实施例的通信安全等级动态切换的系统,家电设备接收移动终端发送的将第一通信模式切换为第二通信模式的第一切换指令,并将第一通信模式切换为第二通信模式,并向周围广播包含第一切换成功消息的UDP包,然后,家电设备与移动终端进行密钥协商,以生成第二通信模式的第一密钥,家电设备通过第一密钥与移动终端进行数据通信。由此,完成了通信模式的切换,提升了家电设备的通信的安全等级,提高了移动终端与家电设备之 间通信的安全性。
本发明附加的方面的优点将在下面的描述中部分给出,部分将从下面的描述中变得明显,或通过本发明的实践了解到。
附图说明
图1是根据本发明一个实施例的通信安全等级动态切换的方法的流程图;
图2是根据本发明另一个实施例的通信安全等级动态切换的方法的流程图;
图3是根据本发明又一个实施例的通信安全等级动态切换的方法的流程图;
图4是根据本发明再一个实施例的通信安全等级动态切换的方法的流程图;
图5是根据本发明另一个实施例的通信安全等级动态切换的方法的流程图;
图6是本发明一个实施例的通信安全等级动态切换的方法的交互流程图;
图7是根据本发明一个实施例的家电设备的WIFI模块的结构示意图;
图8是根据本发明另一个实施例的家电设备的WIFI模块的结构示意图;
图9是根据本发明另一个实施例的家电设备的WIFI模块的结构示意图;
图10是根据本发明再一个实施例的家电设备的WIFI模块的结构示意图;
图11是根据本发明一个实施例的移动终端的结构示意图;
图12是根据本发明另一个实施例的移动终端的结构示意图。
具体实施方式
下面详细描述本发明的实施例,所述实施例的示例在附图中示出,其中自始至终相同或类似的标号表示相同或类似的元件或具有相同或类似功能的元件。下面通过参考附图描述的实施例是示例性的,旨在用于解释本发明,而不能理解为对本发明的限制。
下面参照附图来描述根据本发明实施例提出的通信安全等级动态切换的方法、系统、家电设备的WIFI模块、家电设备和移动终端。
图1是根据本发明一个实施例的通信安全等级动态切换的方法的流程图。
如图1所示,该通信安全等级动态切换的方法包括以下步骤:
S11,家电设备接收移动终端发送的第一切换指令。
其中,第一切换指令用于指示将第一通信模式切换为第二通信模式,其中,第二通信模式的安全等级高于第一通信模式。
其中,第一通信模式是指通过固定密钥和对称密钥算法的通信方式进行通信。
其中,第二通信模式是指通过动态密钥和对称密钥算法的通信方式进行通信。
其中,移动终端可以例如是手机、平板电脑、个人数字助理等具有各种操作系统的硬件设备。
其中,家电设备可以例如是智能电视、电冰箱或智能洗衣机等设备。
具体地,在通过移动终端控制家电设备的过程中,用户可通过移动终端查看移动终端与家电设备之间的通信模式,并可根据需求调整家电设备的通信模式,其中,不同通信模式对应的安全等级不同。
在本发明的一个实施例中,在移动终端与家电设备之间以第一通信模式进行通信的过程中,如果移动终端接收到将家电设备由第一通信模式切换为第二通信模式的外部指令,移动终端将向家电设备发送第一切换指令。对应地,家电设备接收移动终端发送的第一切换指令。
S12,家电设备将第一通信模式切换为第二通信模式,并向周围广播包含第一切换成功消息的UDP包。
具体地,在家电设备将第一通信模式切换为第二通信模式后,为了使得与家电设备配对的移动终端获取切换结果,家电设备通过UDP广播告知移动终端自己已切换成第二通信模式。
S13,家电设备与移动终端进行密钥协商,以生成第二通信模式的第一密钥。
作为一种示例性的实施方式,在移动终端确定家电设备已切换至第二通信模式时,移动终端与家电设备根据预先设置的密钥协商协议进行协商,并在协商通过后,家电设备根据预先设定的密钥生成规则,生成第二通信模式的第一密钥。然后,通过移动终端所使用的公钥对第一密钥进行加密,以生成加密信息,并将加密信息发送至移动终端。对应地,移动终端解密加密信息,以获取第一密钥。
作为另一种示例性的实施方式,在移动终端确定家电设备已切换至第二通信模式时,移动终端向家电设备发送包含会话令牌的密钥协商请求,家电设备用自己的权限密钥对权限令牌进行解密,以得到随机数K1,并生成随机K2,并用随机数K1对随机数K2进行加密,以生成密文,并将密文发送给移动终端,移动终端对密文解密,以获取随机数K2。然后,移动终端利用随机数K1和随机数K2生成第一密钥,例如,移动终端将随机数K1和随机数K2的异或值作为第一密钥。
其中,移动终端中的会话令牌是从服务器中获取的,会话令牌中包含随机数K1。
其中,移动终端从服务器获取会话令牌的过程为:移动终端向服务器发送包含自身的标识信息和家电设备的标识信息的查询请求。服务器根据移动终端的标识信息和家电设备的标识信息确定移动终端是否有权限控制家电设备,在确定移动终端有权限控制对应的家电设备时,服务器获取与家电设备通信的会话令牌,并向移动终端返回与家电设备通信的会话令牌。
其中,会话令牌是服务器是根据下发给家电设备的权限密钥生成的。
其中,服务器生成会话令牌的过程为:服务器随机生成随机数K1,并用服务器下发给家电设备的权限密钥对随机数K1进行加密,以形成中间量K1s,然后,再将中间量K1s和随机数K1的SHA-256的值进行拼接,以形成会话令牌。
S14,家电设备通过第一密钥与移动终端进行数据通信。
根据本发明实施例的通信安全等级动态切换的方法,家电设备接收移动终端发送的将第一通信模式切换为第二通信模式的第一切换指令,并将第一通信模式切换为第二通信模式,并向周围广播包含第一切换成功消息的UDP包,然后,家电设备与移动终端进行密钥协商,以生成第二通信模式的第一密钥,家电设备通过第一密钥与移动终端进行数据通信。由此,完成了通信模式的切换,提升了家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性。
基于上述实施例的基础上,在本发明的一个实施例中,在家电设备通过第一密钥与移动终端进行通信之后,如果家电设备与移动终端重连,则控制家电设备与移动终端重新进行密钥协商,以生成第二通信模式的第三密钥。
也就是说,在每次家电设备以第二通信模式与移动终端建立通信时,第二通信模式的密钥均是家电设备与移动终端重新进行密钥协商之后生成的。
基于上述实施例的基础上,在本发明的一个实施例中,在家电设备通过第一密钥与移动终端进行通信之后,如图2所示,还可以包括以下步骤:
S21,家电设备接收移动终端发送的第二切换指令,第二切换指令用于指示将第二通信模式切换为第一通信模式。
S22,家电设备获取第一通信模式的第二密钥,并将第二通信模式切换为第一通信模式。
S23,家电设备向周围广播包含第二切换成功消息的UDP包。
S24,家用设备通过第二密钥与移动终端进行数据通信。
综上可以看出,在家电设备与移动终端之间以第二通信模式进行数据通信之后,用户还可以通过移动终端再次将家电设备与移动终端的通信模式调整为第一通信模式。
图3是根据本发明又一个实施例的通信安全等级动态切换的方法的流程图。
如图3所示,该通信安全等级动态切换的方法包括以下步骤:
S31,家电设备接收移动终端发送的第一切换指令。
其中,第一切换指令用于指示将第一通信模式切换为第二通信模式,其中,第二通信模式的安全等级高于第一通信模式。
其中,第一通信模式是指通过固定密钥和对称密钥算法的通信方式进行通信。
其中,第二通信模式是指通过动态密钥和对称密钥算法的通信方式进行通信。
其中,移动终端可以例如是手机、平板电脑、个人数字助理等具有各种操作系统的硬件 设备。
其中,家电设备可以例如是智能电视、电冰箱或智能洗衣机等设备。
具体地,在通过移动终端控制家电设备的过程中,用户可通过移动终端查看移动终端与家电设备之间的通信模式,并可根据需求调整家电设备的通信模式,其中,不同通信模式对应的安全等级不同。
在本发明的一个实施例中,在移动终端与家电设备之间以第一通信模式进行通信的过程中,如果移动终端接收到将家电设备由第一通信模式切换为第二通信模式的外部指令,移动终端将向家电设备发送第一切换指令。对应地,家电设备接收移动终端发送的第一切换指令。
S32,家电设备判断是否存在第二通信模式的权限密钥,若不存在,执行步骤S33,并执行步骤S34;若存在,则执行步骤S34。
S33,家电设备与服务器进行密钥协商,以获取权限密钥。
S34,家电设备将第一通信模式切换为第二通信模式。
S35,家电设备向周围广播包含第一切换成功消息的UDP包。
S36,家电设备接收移动终端发送的密钥协商请求。
其中,密钥协商请求包括会话令牌。
其中,会话令牌是移动终端从服务器中获取的。
具体地,移动终端在确定家电设备已切换至第二通信模式时,移动终端向服务器发送第二通信模式的查询请求。
其中,查询请求包括移动终端的标识信息和家电设备的标识信息。
对应地,服务器根据移动终端的标识信息和家电设备的标识信息确定移动终端是否有权限控制家电设备,在确定移动终端有权限控制对应的家电设备时,服务器获取与家电设备通信的会话令牌,并向移动终端返回与家电设备通信的会话令牌。
其中,会话令牌是服务器是根据下发给家电设备的权限密钥生成的。
其中,服务器生成会话令牌的过程为:服务器随机生成随机数K1,并用服务器下发给家电设备的权限密钥对随机数K1进行加密,以形成中间量K1s,然后,再将中间量K1s和随机数K1的SHA-256的值进行拼接,以形成会话令牌。
S37,家电设备根据会话令牌和权限密钥与移动终端进行密钥协商,以生成第一密钥。
具体地,移动终端向家电设备发送包含会话令牌的密钥协商请求,家电设备用自己的权限密钥对权限令牌进行解密,以得到随机数K1,并生成随机K2,并用随机数K1对随机数K2进行加密,以生成密文,并将密文发送给移动终端,移动终端对密文解密,以获取随机数K2。然后,移动终端利用随机数K1和随机数K2生成第一密钥,例如,移动终端将随机数K1和随机数K2的异或值作为第一密钥。
S38,家电设备通过第一密钥与移动终端进行数据通信。
根据本发明实施例的通信安全等级动态切换的方法,家电设备接收移动终端发送的将第一通信模式切换为第二通信模式的第一切换指令,并将第一通信模式切换为第二通信模式,并向周围广播包含第一切换成功消息的UDP包,然后,家电设备根据会话令牌和权限密钥进行密钥协商,以生成第二通信模式的第一密钥,家电设备通过第一密钥与移动终端进行数据通信。由此,完成了通信模式的切换,提升了家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性。
图4是根据本发明再一个实施例的通信安全等级动态切换的方法的流程图。如图4所示,该通信安全等级动态切换的方法从移动终端侧进行描述,该通信安全等级动态切换的方法包括以下步骤:
S41,移动终端向家电设备发送第一切换指令。
其中,第一切换指令用于指示家电设备将第一通信模式切换为第二通信模式。
其中,第二通信模式的安全等级高于第一通信模式。
其中,移动终端可以例如是手机、平板电脑、个人数字助理等具有各种操作系统的硬件设备。
其中,家电设备可以例如是智能电视、电冰箱或智能洗衣机等设备。
具体地,在通过移动终端控制家电设备的过程中,用户可通过移动终端查看移动终端与家电设备之间的通信模式,并可根据需求调整家电设备的通信模式,其中,不同通信模式对应的安全等级不同。
S42,移动终端接收家电设备广播的包含第一切换成功消息的UDP包。
S43,移动终端与家电设备进行密钥协商,以生成第二通信模式的第一密钥。
在本发明的一个实施例中,移动终端在确定家电设备已切换至第二通信模式后,移动终端可从服务器中获取与家电设备以第二通信模式时所需的会话令牌,并利用会话令牌与家电设备进行密钥协商,以生成所述第二通信模式的第一密钥。
其中,会话令牌是移动终端从服务器中获取的。
具体地,移动终端在确定家电设备已切换至第二通信模式时,移动终端向服务器发送第二通信模式的查询请求。
其中,查询请求包括移动终端的标识信息和家电设备的标识信息。
对应地,服务器根据移动终端的标识信息和家电设备的标识信息确定移动终端是否有权限控制家电设备,在确定移动终端有权限控制对应的家电设备时,服务器获取移动终端与家电设备本次通信所使用的会话令牌,并将会话令牌发送至移动终端。
其中,会话令牌是服务器是根据下发给家电设备的权限密钥生成的。
其中,服务器生成会话令牌的过程为:服务器随机生成随机数K1,并用服务器下发给家电设备的权限密钥对随机数K1进行加密,以形成中间量K1s,然后,再将中间量K1s和随机数K1的SHA-256的值进行拼接,以形成会话令牌。
在移动终端从服务器中获取会话令牌后,移动终端向家电设备发送包含会话令牌的密钥协商请求,家电设备用自己的权限密钥对权限令牌进行解密,以得到随机数K1,并生成随机K2,并用随机数K1对随机数K2进行加密,以生成密文,并将密文发送给移动终端,移动终端对密文解密,以获取随机数K2。然后,移动终端利用随机数K1和随机数K2生成第一密钥,例如,移动终端将随机数K1和随机数K2的异或值作为第一密钥。
作为另一种示例性的实施方式,在移动终端确定家电设备已切换至第二通信模式时,移动终端与家电设备根据预先设置的密钥协商协议进行协商,并在协商通过后,家电设备根据预先设定的密钥生成规则,生成第二通信模式的第一密钥。然后,通过移动终端所使用的公钥对第一密钥进行加密,以生成加密信息,并将加密信息发送至移动终端。对应地,移动终端解密加密信息,以获取第一密钥。
S44,移动终端通过第一密钥与移动终端进行数据通信。
根据本发明实施例的通信安全等级动态切换的方法,移动终端向家电设备发送的用于指示家电设备将第一通信模式切换为第二通信模式的第一切换指令,然后,移动终端接收家电设备广播的包含第一切换成功消息的UDP包,之后,移动终端与家电设备进行密钥协商,以生成第二通信模式的第一密钥,以及移动终端通过第一密钥与移动终端进行数据通信。由此,使得用户可通过移动终端一键提升家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性,满足了用户切换家电设备的通信的安全等级的需求。
基于上述实施例的基础上,为了保证移动终端与家电设备之间的通信的安全性,在移动终端通过第一密钥与移动终端进行数据通信之后,如果移动终端与家电设备断开连接,则移动终端控制第一密钥失效。
在本发明的一个实施实施例中,如图5所示,在移动终端通过第一密钥与移动终端进行数据通信之后,该方法还可以包括以下步骤:
S51,移动终端向家电设备发送第二切换指令,第二切换指令用于指示家电设备将第二通信模式切换为第一通信模式切换。
S52,移动终端接收家电设备广播的包含第二切换成功消息的UDP包。
S53,移动终端获取第一通信模式对应的密钥,并通过第一通信模式对应的密钥与移动终端进行数据通信。
图6是本发明一个实施例的通信安全等级动态切换的方法的交互流程图。
该实施例以家电设备初次上电后,家电设备默认以第一通信模式(固定密钥,对称密钥)与移动终端和服务器进行通信为例进行描述,如图6所示,该通信安全等级动态切换的方法可以包括:
S61,移动终端接收用户输入的将家电设备由第一通信模式切换至第二通信模式的第一切换指令。
S62,移动终端将第一切换指令发送至家电设备。
S63,家电设备向服务器发送第一密钥协商请求。
S64,服务器根据第一密钥协商请求与家电设备进行密钥协商,并在确定协商通过后,获取家电设备的第二通信模式的权限密钥。
具体地,家电设备向服务器发送包含自身的标识信息的密钥协商请求,服务器对家电设备的标识信息进行身份验证,并在验证通过后,服务器根据家电设备的标识信息生成第二通信模式的权限密钥,并向家电设备返回权限密钥。
S65,服务器向家电设备返回第二通信模式的权限密钥。
S66,家电设备根据权限密钥将第一通信模式切换为第二通信模式,并向周围广播包含第一切换成功消息的UDP包。
S67,移动终端向服务器发送第二通信模式的查询请求。
其中,查询请求包括移动终端的标识信息和家电设备的标识信息。
S68,服务器在确定移动终端通过验证后,服务器生成移动终端与家电设备本次通信所使用的会话令牌。
S69,服务器将会话令牌发送至移动终端。
具体地,服务器根据移动终端的标识信息和家电设备的标识信息确定移动终端是否有权限控制家电设备,在确定移动终端有权限控制对应的家电设备时,服务器获取与家电设备通信的会话令牌。
其中,会话令牌是服务器是根据下发给家电设备的权限密钥生成的。
其中,服务器生成会话令牌的过程为:服务器随机生成随机数K1,并用服务器下发给家电设备的权限密钥对随机数K1进行加密,以形成中间量K1s,然后,再将中间量K1s和随机数K1的SHA-256的值进行拼接,以形成会话令牌。
S70,移动终端利用会话令牌与家电设备进行密钥协商,以生成第二通信模式的第一密钥。
具体地,移动终端向家电设备发送包含会话令牌的密钥协商请求,家电设备用自己的权限密钥对权限令牌进行解密,以得到随机数K1,并生成随机K2,并用随机数K1对随机数K2进行加密,以生成密文,并将密文发送给移动终端,移动终端对密文解密,以获取随机 数K2。然后,移动终端利用随机数K1和随机数K2生成第一密钥,例如,移动终端将随机数K1和随机数K2的异或值作为第一密钥。
S71,移动终端与家电设备之间以第一密钥进行数据通信。
根据本发明实施例的通信安全等级动态切换的方法,家电设备接收移动终端发送的将第一通信模式切换为第二通信模式的第一切换指令,并将第一通信模式切换为第二通信模式,并向周围广播包含第一切换成功消息的UDP包,然后,家电设备根据会话令牌和权限密钥进行密钥协商,以生成第二通信模式的第一密钥,家电设备通过第一密钥与移动终端进行数据通信。由此,完成了通信模式的切换,提升了家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性。
为了实现上述实施例,本发明还提出一种家电设备的WIFI模块。
图7是根据本发明一个实施例的家电设备的WIFI模块的结构示意图。
如图7所示,该家电设备的WIFI模块包括接收子模块111、第一切换子模块112、广播子模块113、生成子模块114和第一通信子模块115,其中:
接收子模块111用于接收移动终端发送的第一切换指令。
其中,第一切换指令用于指示将第一通信模式切换为第二通信模式。
其中,第二通信模式的安全等级高于第一通信模式。
第一切换子模块112用于将第一通信模式切换为第二通信模式。
广播子模块113用于向周围广播包含第一切换成功消息的UDP包。
生成子模块114用于与移动终端进行密钥协商,以生成第二通信模式的第一密钥。
第一通信子模块115用于通过第一密钥与移动终端进行数据通信。
其中,需要说明的是,前述对通信安全等级动态切换的方法实施例的解释说明也适用于该实施例的家电设备的WIFI模块,其实现原理类似,此处不再赘述。
根据本发明实施例的家电设备的WIFI模块,通过接收子模块接收移动终端发送的将第一通信模式切换为第二通信模式的第一切换指令,并通过第一切换子模块将第一通信模式切换为第二通信模式,并通过广播子模块向周围广播包含第一切换成功消息的UDP包,然后,通过生成子模块与移动终端进行密钥协商,以生成第二通信模式的第一密钥,以及第一通信模块通过第一密钥与移动终端进行数据通信。由此,完成了通信模式的切换,提升了家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性。
基于上述实施例的基础上,在本发明的一个实施例中,在图7所示的基础上,如图8所示,该家电设备的WIFI模块还可以包括判断子模块116,其中,判断子模块116用于判断是否存在第二通信模式的权限密钥。
其中,第一切换子模块112还用于在判定存在第二通信模式的权限密钥时,则将第一通信模式切换为第二通信模式。
在本发明的一个实施例中,如图8所示,该家电设备的WIFI模块还可以包括获取子模块117,其中,该获取子模块117用于在判断出不存在第二通信模式的权限密钥,与服务器进行密钥协商,以获取权限密钥。
在本发明的一个实施例中,生成子模块114具体用于:接收移动终端发送的包含会话令牌的密钥协商请求,根据会话令牌和权限密钥与移动终端进行密钥协商,以生成第一密钥。
在本发明的一个实施例中,在图7所示的基础上,如图9所示,该家电设备的WIFI模块还可以包括第一处理子模块118,其中,该第一处理子模块118用接收移动终端发送的用于指示将第二通信模式切换为第一通信模式的第二切换指令,获取第一通信模式的第二密钥,并将第二通信模式切换为第一通信模式,以及向周围广播包含第二切换成功消息的UDP包,通过第二密钥与移动终端进行数据通信。
其中,需要说明的是,图9所示的家电设备的WIFI模块中的第一处理子模块118的结构也可以包含在前述图8的装置实施例中,对此本发明不进行限制。
在本发明的一个实施例中,在图7所示的基础上,如图10所示,家电设备的WIFI模块还可以包括第二处理子模块119,其中,该第二处理子模块119用于在与移动终端的重连时,控制家电设备与移动终端重新进行密钥协商,以生成第二通信模式的第三密钥。
其中,需要说明的是,图10所示的家电设备的WIFI模块中的第二处理子模块119的结构也可以包含在前述图8和图9的装置实施例中,对此本发明不进行限制。
为了实现上述实施例,本发明还提出一种家电设备。
一种家电设备,包括本发明上述实施例的家电设备的WIFI模块。
根据本发明实施例的家电设备,家电设备接收移动终端发送的将第一通信模式切换为第二通信模式的第一切换指令,并将第一通信模式切换为第二通信模式,并向周围广播包含第一切换成功消息的UDP包,然后,家电设备与移动终端进行密钥协商,以生成第二通信模式的第一密钥,家电设备通过第一密钥与移动终端进行数据通信。由此,完成了通信模式的切换,提升了家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性。
为了实现上述实施例,本发明还提出一种移动终端。
图11是根据本发明一个实施例的移动终端的结构示意图。
如图11所示,该移动终端包括发送模块210、第一接收模块220、协商模块230和通信模块240,其中:
发送模块210用于向家电设备发送第一切换指令。
其中,第一切换指令用于指示家电设备将第一通信模式切换为第二通信模式。
其中,第二通信模式的安全等级高于第一通信模式。
第一接收模块220用于接收家电设备广播的包含第一切换成功消息的UDP包。
协商模块230用于与家电设备进行密钥协商,以生成第二通信模式的第一密钥。
通信模块240用于通过第一密钥与移动终端进行数据通信。
在本发明的一个实施例中,协商模块230具体用于:从服务器中获取与家电设备以第二通信模式时所需的会话令牌,并利用会话令牌与家电设备进行密钥协商,以生成第二通信模式的第一密钥。
在本发明的一个实施例中,在图11所示的基础上,如图12所示,该移动终端还可以包括第一处理模块250,其中:
第一处理模块250用于向家电设备发送的用于指示家电设备将第二通信模式切换为第一通信模式切换的第二切换指令,接收家电设备广播的包含第二切换成功消息的UDP包,获取第一通信模式对应的密钥,并通过第一通信模式对应的密钥与移动终端进行数据通信。
在本发明的一个实施例中,如图12所示,该移动终端还可以包括第二处理模块260,其中:
第二处理模块260用于在与家电设备断开连接时,控制第一密钥失效。
其中,需要说明的是,前述对通信安全等级动态切换的方法实施例的解释说明也适用于该实施例的移动终端,其实现原理类似,此处不再赘述。
根据本发明实施例的移动终端,移动终端向家电设备发送的用于指示家电设备将第一通信模式切换为第二通信模式的第一切换指令,然后,移动终端接收家电设备广播的包含第一切换成功消息的UDP包,之后,移动终端与家电设备进行密钥协商,以生成第二通信模式的第一密钥,移动终端通过第一密钥与移动终端进行数据通信。由此,使得用户可通过移动终端一键提升家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性,满足了用户切换家电设备的通信的安全等级的需求。
为了实现上述实施例,本发明还提出一种通信安全等级动态切换的系统。
该通信安全等级动态切换的系统可以包括移动终端和家电设备。
其中,前述移动终端和家电设备的解释说明也适用于该实施例中,此处不再赘述。
根据本发明实施例的通信安全等级动态切换的系统,家电设备接收移动终端发送的将第一通信模式切换为第二通信模式的第一切换指令,并将第一通信模式切换为第二通信模式,并向周围广播包含第一切换成功消息的UDP包,然后,家电设备与移动终端进行密钥协商,以生成第二通信模式的第一密钥,家电设备通过第一密钥与移动终端进行数据通信。由此, 完成了通信模式的切换,提升了家电设备的通信的安全等级,提高了移动终端与家电设备之间通信的安全性。
此外,术语“第一”、“第二”仅用于描述目的,而不能理解为指示或暗示相对重要性或者隐含指明所指示的技术特征的数量。由此,限定有“第一”、“第二”的特征可以明示或者隐含地包括至少一个该特征。在本发明的描述中,“多个”的含义是至少两个,例如两个,三个等,除非另有明确具体的限定。
在本发明中,除非另有明确的规定和限定,术语“安装”、“相连”、“连接”、“固定”等术语应做广义理解,例如,可以是固定连接,也可以是可拆卸连接,或成一体;可以是机械连接,也可以是电连接;可以是直接相连,也可以通过中间媒介间接相连,可以是两个元件内部的连通或两个元件的相互作用关系,除非另有明确的限定。对于本领域的普通技术人员而言,可以根据具体情况理解上述术语在本发明中的具体含义。
在本说明书的描述中,参考术语“一个实施例”、“一些实施例”、“示例”、“具体示例”、或“一些示例”等的描述意指结合该实施例或示例描述的具体特征、结构、材料或者特点包含于本发明的至少一个实施例或示例中。在本说明书中,对上述术语的示意性表述不必须针对的是相同的实施例或示例。而且,描述的具体特征、结构、材料或者特点可以在任一个或多个实施例或示例中以合适的方式结合。此外,在不相互矛盾的情况下,本领域的技术人员可以将本说明书中描述的不同实施例或示例以及不同实施例或示例的特征进行结合和组合。
尽管上面已经示出和描述了本发明的实施例,可以理解的是,上述实施例是示例性的,不能理解为对本发明的限制,本领域的普通技术人员在本发明的范围内可以对上述实施例进行变化、修改、替换和变型。

Claims (22)

  1. 一种通信安全等级动态切换的方法,其特征在于,包括以下步骤:
    家电设备接收移动终端发送的第一切换指令,所述第一切换指令用于指示将第一通信模式切换为第二通信模式,其中,所述第二通信模式的安全等级高于所述第一通信模式;
    所述家电设备将所述第一通信模式切换为所述第二通信模式,并向周围广播包含第一切换成功消息的UDP包;
    所述家电设备与所述移动终端进行密钥协商,以生成所述第二通信模式的第一密钥;
    所述家电设备通过所述第一密钥与所述移动终端进行数据通信。
  2. 如权利要求1所述的方法,其特征在于,所述家电设备将所述第一通信模式切换为所述第二通信模式,包括:
    所述家电设备判断是否存在所述第二通信模式的权限密钥;
    若存在,则执行所述家电设备将所述第一通信模式切换为所述第二通信模式的步骤。
  3. 如权利要求2所述的方法,其特征在于,还包括:
    若判断出不存在所述第二通信模式的权限密钥,则所述家电设备与服务器进行密钥协商,以获取所述权限密钥。
  4. 如权利要求2或3所述的方法,其特征在于,所述家电设备与所述移动终端进行密钥协商,以生成所述第二通信模式的第一密钥,包括:
    所述家电设备接收所述移动终端发送的密钥协商请求,其中,所述密钥协商请求包括会话令牌;
    所述家电设备根据所述会话令牌和所述权限密钥与所述移动终端进行密钥协商,以生成所述第一密钥。
  5. 如权利要求1-4中任一项所述的方法,其特征在于,在所述家电设备通过所述第一密钥与所述移动终端进行通信之后,还包括:
    所述家电设备接收所述移动终端发送的第二切换指令,所述第二切换指令用于指示将所述第二通信模式切换为所述第一通信模式;
    所述家电设备获取所述第一通信模式的第二密钥,并将所述第二通信模式切换为所述第一通信模式;
    所述家电设备向周围广播包含第二切换成功消息的UDP包;
    所述家用设备通过所述第二密钥与所述移动终端进行数据通信。
  6. 如权利要求1-4中任一项所述的方法,其特征在于,在所述家电设备通过所述第一密钥与所述移动终端进行通信之后,还包括:
    如果所述家电设备与移动终端重连,则控制所述家电设备与所述移动终端重新进行密钥协商,以生成所述第二通信模式的第三密钥。
  7. 一种通信安全等级动态切换的方法,其特征在于,包括以下步骤:
    移动终端向家电设备发送第一切换指令,其中,所述第一切换指令用于指示所述家电设备将第一通信模式切换为第二通信模式,其中,所述第二通信模式的安全等级高于所述第一通信模式;
    所述移动终端接收所述家电设备广播的包含第一切换成功消息的UDP包;
    所述移动终端与所述家电设备进行密钥协商,以生成所述第二通信模式的第一密钥;
    所述移动终端通过所述第一密钥与所述移动终端进行数据通信。
  8. 如权利要求7所述的方法,其特征在于,所述移动终端与所述家电设备进行密钥协商,以生成所述第二通信模式的第一密钥,包括:
    所述移动终端从服务器中获取与所述家电设备以所述第二通信模式时所需的会话令牌;
    所述移动终端利用所述会话令牌与所述家电设备进行密钥协商,以生成所述第二通信模式的第一密钥。
  9. 如权利要求7或8所述的方法,其特征在于,在所述移动终端通过所述第一密钥与所述移动终端进行数据通信之后,还包括:
    所述移动终端向所述家电设备发送第二切换指令,所述第二切换指令用于指示所述家电设备将所述第二通信模式切换为所述第一通信模式切换;
    所述移动终端接收所述家电设备广播的包含第二切换成功消息的UDP包;
    所述移动终端获取所述第一通信模式对应的密钥,并通过所述第一通信模式对应的密钥与所述移动终端进行数据通信。
  10. 如权利要求7-9中任一项所述的方法,其特征在于,在所述移动终端通过所述第一密钥与所述移动终端进行数据通信之后,还包括:
    如果所述移动终端与所述家电设备断开连接,则所述移动终端控制所述第一密钥失效。
  11. 一种家电设备的WIFI模块,其特征在于,包括:
    接收子模块,用于接收移动终端发送的第一切换指令,所述第一切换指令用于指示将第一通信模式切换为第二通信模式,其中,所述第二通信模式的安全等级高于所述第一通信模式;
    第一切换子模块,用于将所述第一通信模式切换为所述第二通信模式;
    广播子模块,用于向周围广播包含第一切换成功消息的UDP包;
    生成子模块,用于与所述移动终端进行密钥协商,以生成所述第二通信模式的第一密钥;
    第一通信子模块,用于通过所述第一密钥与所述移动终端进行数据通信。
  12. 如权利要求11所述的家电设备的WIFI模块,其特征在于,还包括:
    判断子模块,用于判断是否存在所述第二通信模式的权限密钥;
    其中,所述第一切换子模块,还用于在判定存在所述第二通信模式的权限密钥时,则将所述第一通信模式切换为所述第二通信模式。
  13. 如权利要求12所述的家电设备的WIFI模块,其特征在于,还包括:
    获取子模块,用于在判断出不存在所述第二通信模式的权限密钥,与服务器进行密钥协商,以获取所述权限密钥。
  14. 如权利要求12或13所述的家电设备的WIFI模块,其特征在于,所述生成子模块,具体用于:
    接收所述移动终端发送的包含会话令牌的密钥协商请求,根据所述会话令牌和所述权限密钥与所述移动终端进行密钥协商,以生成所述第一密钥。
  15. 如权利要求11-14中任一项所述的家电设备的WIFI模块,其特征在于,还包括:
    第一处理子模块,用接收所述移动终端发送的用于指示将所述第二通信模式切换为所述第一通信模式的第二切换指令,获取所述第一通信模式的第二密钥,并将所述第二通信模式切换为所述第一通信模式,以及向周围广播包含第二切换成功消息的UDP包,通过所述第二密钥与所述移动终端进行数据通信。
  16. 如权利要求11-15中任一项所述的家电设备的WIFI模块,其特征在于,还包括:
    第二处理子模块,用于在与所述移动终端的重连时,控制所述家电设备与所述移动终端重新进行密钥协商,以生成所述第二通信模式的第三密钥。
  17. 一种移动终端,其特征在于,包括:
    发送模块,用于向家电设备发送第一切换指令,其中,所述第一切换指令用于指示所述家电设备将第一通信模式切换为第二通信模式,其中,所述第二通信模式的安全等级高于所述第一通信模式;
    接收模块,用于接收所述家电设备广播的包含第一切换成功消息的UDP包;
    协商模块,用于与所述家电设备进行密钥协商,以生成所述第二通信模式的第一密钥;
    通信模块,用于通过所述第一密钥与所述移动终端进行数据通信。
  18. 如权利要求17所述的移动终端,其特征在于,所述协商模块,具体用于:
    从服务器中获取与所述家电设备以所述第二通信模式时所需的会话令牌,并利用所述会话令牌与所述家电设备进行密钥协商,以生成所述第二通信模式的第一密钥。
  19. 如权利要求17或18所述的移动终端,其特征在于,还包括:
    第一处理模块,用于向所述家电设备发送的用于指示所述家电设备将所述第二通信模式切换为所述第一通信模式切换的第二切换指令,接收所述家电设备广播的包含第二切换成功 消息的UDP包,获取所述第一通信模式对应的密钥,并通过所述第一通信模式对应的密钥与所述移动终端进行数据通信。
  20. 如权利要求17-19中任一项所述的移动终端,其特征在于,还包括:
    第二处理模块,用于在与所述家电设备断开连接时,控制所述第一密钥失效。
  21. 一种家电设备,其特征在于,包括:如权利要求11至16中任一项所述的家电设备的WIFI模块。
  22. 一种通信安全等级动态切换的系统,其特征在于,包括:
    如权利要求17至20中任一项所述的移动终端;
    如权利要求21所述的家电设备。
PCT/CN2016/104118 2016-10-31 2016-10-31 通信安全等级切换的方法、系统、家电设备和移动终端 WO2018076369A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/CN2016/104118 WO2018076369A1 (zh) 2016-10-31 2016-10-31 通信安全等级切换的方法、系统、家电设备和移动终端

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2016/104118 WO2018076369A1 (zh) 2016-10-31 2016-10-31 通信安全等级切换的方法、系统、家电设备和移动终端

Publications (1)

Publication Number Publication Date
WO2018076369A1 true WO2018076369A1 (zh) 2018-05-03

Family

ID=62023009

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/104118 WO2018076369A1 (zh) 2016-10-31 2016-10-31 通信安全等级切换的方法、系统、家电设备和移动终端

Country Status (1)

Country Link
WO (1) WO2018076369A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110609480A (zh) * 2018-06-15 2019-12-24 青岛海尔洗衣机有限公司 家用电器的安全控制方法和系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101162992A (zh) * 2007-09-29 2008-04-16 中国人民解放军信息工程大学 容忍入侵的密码协议安全运行防护方法和系统
CN204695013U (zh) * 2015-06-02 2015-10-07 慧锐通智能科技股份有限公司 一种具有密钥生成功能的智能家居系统
CN105610783A (zh) * 2015-11-05 2016-05-25 珠海格力电器股份有限公司 一种数据传输方法及物联网系统
CN106549966A (zh) * 2016-10-31 2017-03-29 美的智慧家居科技有限公司 通信安全等级切换的方法、系统、家电设备和移动终端

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101162992A (zh) * 2007-09-29 2008-04-16 中国人民解放军信息工程大学 容忍入侵的密码协议安全运行防护方法和系统
CN204695013U (zh) * 2015-06-02 2015-10-07 慧锐通智能科技股份有限公司 一种具有密钥生成功能的智能家居系统
CN105610783A (zh) * 2015-11-05 2016-05-25 珠海格力电器股份有限公司 一种数据传输方法及物联网系统
CN106549966A (zh) * 2016-10-31 2017-03-29 美的智慧家居科技有限公司 通信安全等级切换的方法、系统、家电设备和移动终端

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110609480A (zh) * 2018-06-15 2019-12-24 青岛海尔洗衣机有限公司 家用电器的安全控制方法和系统

Similar Documents

Publication Publication Date Title
EP3627794B1 (en) Discovery method and apparatus based on service-oriented architecture
US11765172B2 (en) Network system for secure communication
WO2019120091A1 (zh) 身份认证方法、系统及计算设备
US20160269176A1 (en) Key Configuration Method, System, and Apparatus
EP2938112B1 (en) Portable authorization device
US9668230B2 (en) Security integration between a wireless and a wired network using a wireless gateway proxy
KR101413376B1 (ko) 지그비 네트워크에서의 링크키를 공유하는 방법 및 그 통신시스템
CN110912880B (zh) 配网方法及装置、电子设备及存储介质
CN111050322B (zh) 基于gba的客户端注册和密钥共享方法、装置及系统
US20060161774A1 (en) Authentication method and system between device with small computational resources and device using public key
CN108476140B (zh) 一种安全控制智能家居的方法及终端设备
US10680835B2 (en) Secure authentication of remote equipment
CN112737774B (zh) 网络会议中的数据传输方法、装置及存储介质
KR20120047972A (ko) 암호화 정보를 교섭하기 위한 방법, 장치 및 네트워크 시스템
CN110099427A (zh) 一种待配网设备接入网络热点设备的方法和系统
WO2018113337A1 (zh) 一种可穿戴设备的安全通信环境的建立方法及系统
CN114125832B (zh) 一种网络连接方法及终端、待配网设备、存储介质
US20200162916A1 (en) Timestamp based onboarding process for wireless devices
JP2020533853A (ja) デジタル証明書を管理するための方法および装置
EP2890083B1 (en) Key distribution system and method
JP2018509009A (ja) ルーティング情報転送方法、装置、プログラム及び記録媒体
CN114222298A (zh) 终端接入方法、装置、网络设备、终端和介质
CN106549966B (zh) 通信安全等级切换的方法、系统、家电设备和移动终端
KR20230008167A (ko) 통신 방법 및 통신 장치
WO2018076369A1 (zh) 通信安全等级切换的方法、系统、家电设备和移动终端

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16919593

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 07.10.2019)

122 Ep: pct application non-entry in european phase

Ref document number: 16919593

Country of ref document: EP

Kind code of ref document: A1