WO2019149151A1 - 网络安全准入方法及家庭网络设备 - Google Patents

网络安全准入方法及家庭网络设备 Download PDF

Info

Publication number
WO2019149151A1
WO2019149151A1 PCT/CN2019/073204 CN2019073204W WO2019149151A1 WO 2019149151 A1 WO2019149151 A1 WO 2019149151A1 CN 2019073204 W CN2019073204 W CN 2019073204W WO 2019149151 A1 WO2019149151 A1 WO 2019149151A1
Authority
WO
WIPO (PCT)
Prior art keywords
home network
domain
network device
master node
user
Prior art date
Application number
PCT/CN2019/073204
Other languages
English (en)
French (fr)
Inventor
赖伟权
王顺宝
潘稻
周健
邓力
刘君
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to EP19748132.8A priority Critical patent/EP3739817B1/en
Publication of WO2019149151A1 publication Critical patent/WO2019149151A1/zh
Priority to US16/945,504 priority patent/US20200366514A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2803Home automation networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2803Home automation networks
    • H04L12/2807Exchanging configuration information on appliance services in a home automation network
    • H04L12/2809Exchanging configuration information on appliance services in a home automation network indicating that an appliance service is present in a home automation network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2854Wide area networks, e.g. public data networks
    • H04L12/2856Access arrangements, e.g. Internet access
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0876Aspects of the degree of configuration automation
    • H04L41/0886Fully automatic configuration
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0281Proxies
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0884Network architectures or network communication protocols for network security for authentication of entities by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2803Home automation networks
    • H04L2012/284Home automation networks characterised by the type of medium used
    • H04L2012/2841Wireless
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2803Home automation networks
    • H04L2012/284Home automation networks characterised by the type of medium used
    • H04L2012/2843Mains power line
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2803Home automation networks
    • H04L2012/284Home automation networks characterised by the type of medium used
    • H04L2012/2845Telephone line

Definitions

  • the present application relates to the field of communications technologies, and in particular, to a network security access and home network device.
  • the home network technology refers to the technology of interconnecting network communication in the home.
  • the home network media is relatively rich, and the common ones include a coaxial cable, a twisted pair line, a power line, and the like. Plastic optical fiber, etc.
  • ITU-T G.hn supports coaxial cable, twisted pair, power line and plastic optical fiber
  • IEEE Homeplug supports power line
  • MOCA supports coaxial cable
  • the home network user connects to the user terminal downwards and connects to the Internet (Internet) to provide terminal interconnection and terminal to Internet services in the home network.
  • Internet Internet
  • home network communication devices Most of the home network media are open. In the process of using the power line, coaxial cable and other media for network communication, it is easy to be illegally monitored by malicious devices. In order to prevent malicious devices from being illegally monitored, communication devices that use these media to communicate (hereinafter referred to as home network communication devices) can implement certain security by pairing networking methods, and prevent malicious devices from illegally listening to ensure communication security.
  • a typical implementation of the paired networking is that the home network communication device joins the domain through a secure admission method, which can be understood as a private network formed between the home network devices. The home network device communicates through the home network medium in the domain, which prevents the entry of malicious nodes and ensures the security of communication.
  • Manner 1 The user needs to perform key operation on an EP node in an end point node (EP Node) in the domain, and the EP node receiving the button operation sends a notification message to the domain master (DM).
  • the domain master node opens the pairing window after receiving the notification message sent by the EP Node.
  • the user performs a key operation on the new home network device that needs to join the domain.
  • the new home network device may send a registration request to the domain master node, and the domain master node receives the registration request. Reply to the registration confirmation message to implement the secure access process for new home network devices.
  • Method 2 The user needs to connect the EP Node located in the domain through the TV screen or the computer, and display the status of the EP Node through the screen.
  • the user operates the EP Node located in the domain on the screen to trigger the EP node located in the domain to send a pairing request to the domain master node.
  • the domain master node After receiving the pairing request, the domain master node starts the pairing window and broadcasts the media access plan (medium access plan). , MAP) message.
  • the new home network device that needs to join the domain sends a registration request to the domain master node after receiving the MAP message.
  • the domain master node replies to the new home network device with a registration confirmation message, and closes the pairing window after the pairing window expires, and sends a pairing response to the EP node located in the domain, where the pairing response includes the media connection of the new home network device that sends the registration request.
  • Media access control (MAC) address or other information After receiving the pairing response, the EP Node located in the domain can display the MAC address or other information of the new home network device on the screen. The user selects a registration request through the new home network device based on the MAC or other information on the screen. The EP Node located in the domain sends a pairing request to the domain master node.
  • MAC Media access control
  • the domain master node After receiving the pairing request, the domain master node broadcasts a MAP message and carries the MAC address of the new home network device that the user has authorized to join the domain. After receiving the MAP message, the new home network device detects that it carries its own MAC address and initiates a registration request to implement the pairing operation process of the new home network device.
  • the embodiment of the present application provides a network security access method and a home network device to improve the security of security access.
  • the first aspect provides a method for network security access.
  • the domain master node sends a prompt message to the user, where the prompt information is used to indicate that there is a home network device that needs to join the domain for pairing.
  • the domain master node receives the authorization operation of the user, and the authorization operation is used to indicate that the home network device is allowed to join the domain for pairing operation, and the user operates according to the prompt information.
  • the domain master node determines that the user's authorization operation is received, the pairing window is opened, and the indication information is sent during the validity period of the pairing window, and the indication information is used to indicate that the home network device is allowed to join the domain for pairing.
  • the user performs the authorization operation by using the prompt information, and the user does not need to use the television, the computer, and other devices to cooperate, so that the matching network of the home network is more friendly to the user and the operation is more convenient;
  • the authorization operation triggers the domain master node to open the pairing window, so that the new device is authorized to join the domain before the domain master node opens the pairing window, thereby avoiding the situation that new devices without authorization are added to the domain after the pairing window is opened, thereby avoiding waste of resources and improving security standards.
  • Security or paired networking.
  • the validity period of the pairing window can be set relatively short compared with the prior art, thereby further reducing the chance of illegal entry of the malicious device and improving the security of the security access.
  • the network security admission method can be applied to a domain master node or a domain terminal node in a home network, and can also be applied to a chip in a domain master node or a domain terminal node.
  • the domain master node is used to manage transmission resource allocation between the home network and any node of the home network.
  • the home network is a network that communicates through a home network medium
  • the home network medium includes at least one of a power line, a twisted pair, a plastic optical fiber, and a coaxial cable.
  • the domain master node manages the home network device that is the domain terminal node to access the home network.
  • receives the notification message sent by the home network device for notifying that there is a home network device that needs to access the home network performing the following steps: sending a prompt message to the user, where the prompt information is used to indicate that there is a need
  • a home network device that accesses the home network Receiving an authorization operation of the user, the authorization operation is used to indicate that the home network device is allowed to access the home network, and the user operates according to the prompt information.
  • the pairing window is opened, and the indication information is sent during the validity period of the pairing window, and the indication information is used to indicate that the home network device is allowed to access the home network. In this mode, the user only needs to perform a simple authorization operation according to the prompt information sent by the domain master node, so that the home network device can automatically access the home network and perform data transmission, and the operation is convenient and concise.
  • the prompt information may be displayed locally on the domain master node, for example, may be a domain master node flashing prompt.
  • the user's authorization operation may be the user's operation on the domain master node, for example, may be a key operation on the domain master node.
  • the user can perform the authorization operation on the domain master node through the prompt information, and does not need to perform bilateral docking operations on other home network devices and domain master nodes that access the home network.
  • the operation process is user-friendly and easy to understand, and the operation is simple and convenient. And enable home network devices to quickly access the home network.
  • the proxy node displays the prompt information to the user as the device of the user interface, and directly receives the authorization operation of the user.
  • the domain master node notifies the proxy node to prompt the user to flash.
  • the authorization operation of the user may also be that the user performs a key operation on the proxy node, and the proxy node notifies the user of the domain master node of the key authorization operation.
  • the proxy node can be any domain terminal node.
  • the prompt information sent by the domain master node is sent by the domain master node to a terminal used by the user, such as a mobile phone, and displayed on the terminal.
  • a terminal used by the user such as a mobile phone
  • it may be a push message that is sent by the domain master node to the terminal used by the user and displayed on the terminal.
  • the application used by the user is installed on the terminal used by the user.
  • the user's authorized operation can be triggered by the user's operation on the application installed on the terminal.
  • the user can perform one-click authorization operation on the terminal used by using the prompt information, and does not need to perform bilateral docking operation on other home network devices and domain master nodes that access the home network, and the operation is simple and convenient, and can enable the family. Network devices quickly access the home network.
  • the domain master node may receive, according to the notification message, a notification message sent by the home network device to notify the home network device that needs to join the domain for pairing.
  • the notification message is sent to the user.
  • the home network device that needs to join the domain for pairing sends a notification message, triggering the domain master node to perform the pairing operation, and does not need to be triggered by other home network devices accessing the home network, and the processing procedure is relatively simple.
  • the notification message may include an identifier of the home network device that sends the notification message.
  • the indication information sent by the domain master node also includes the identifier of the home network device that sends the notification message.
  • the identifier of the home network device that sends the notification message is included in the notification message, and the indication information sent by the domain master node also includes the identifier of the home network device that sends the notification message, so that the family corresponding to the identifier can be made.
  • the network device accesses the home network to prevent other home network devices from accessing and improving security.
  • the domain master node receives the authorization operation of the user, and sends the domain name configuration information of the domain master node, where the authorization operation may be directly related to the domain master node.
  • the key operation may also be a key operation on the proxy node, and the proxy node notifies the key operation of the domain primary node user, or may operate through the application of the smart terminal.
  • the domain master node receives the domain name configuration confirmation message sent by the home network device, where the domain name configuration confirmation message is used to indicate that the home network device uses the domain name included in the domain name configuration information of the domain master node as the domain name of the home network device.
  • the home network device can configure the domain name according to the domain name configuration information of the domain master node, and the pre-configured manner is adopted to make the domain name configuration flexibility of the home network device larger.
  • a network security access method in which a home network device determines that a domain needs to be joined to perform pairing, and sends a notification message to the domain master node, where the notification message is used to notify the domain master node that the domain needs to be joined. Paired home network devices.
  • the home network device that needs to join the domain for pairing can be understood as a home network device that is a domain terminal node. Pairing a home network device into a domain can also be understood as a home network device being allowed to access the home network as a domain terminal node.
  • the home network device that needs to join the domain for pairing sends a notification message, triggering the domain master node to perform the pairing operation, and does not need to be triggered by other home network devices that have accessed the home network, and the processing procedure is relatively simple.
  • the home network device When the home network device detects power-on or detects the presence of a new domain, it may determine that the domain needs to be joined for pairing.
  • the notification message sent by the home network device that needs to join the domain for pairing includes the identifier of the home network device that sends the notification message, so that the home network device corresponding to the identifier can access the home network to prevent other home network devices from accessing. Improve security.
  • the home network device as the domain terminal node in the home network may receive the domain name configuration information of the domain master node sent by the domain master node, and include the domain name included in the domain name configuration information of the domain master node.
  • a domain name of the home network device as the domain terminal node in the home network a domain name configuration confirmation message is sent to the domain master node.
  • the home network device that is the domain terminal node in the home network can be configured according to the domain name configuration information of the domain master node, and the pre-configured manner is adopted to make the domain name configuration flexibility of the home network device larger.
  • a network security access device having the functions involved in implementing the network security admission method in the domain master node of any of the first aspect or the first aspect.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more units corresponding to the functions described above.
  • the network security access device comprises a transmitting unit, a receiving unit and a processing unit.
  • the sending unit is configured to send a prompt message to the user.
  • the receiving unit is configured to receive an authorized operation of the user.
  • the processing unit is configured to determine that the pairing window is opened when the authorization operation of the user is received.
  • the sending unit is configured to send indication information during a validity period of the pairing window, where the indication information is used to indicate that the home network device is allowed to join the domain for pairing.
  • the domain master node is triggered to enable the pairing window by the user's authorized operation, so that the new device is authorized to join the domain before the domain master node opens the pairing window, thereby avoiding the unauthorized new device joining the domain after the pairing window is opened.
  • the validity period of the pairing window can be set relatively short compared with the prior art, thereby further reducing the chance of illegal entry of the malicious device and improving the security of the security access.
  • the network security access device comprises a transmitting unit and a receiving unit.
  • the receiving unit is configured to receive an authorization operation of the user.
  • the sending unit is configured to send domain name configuration information of the domain master node.
  • the receiving unit is configured to receive a domain name configuration confirmation message sent by the home network device, where the domain name configuration confirmation message is used to indicate that the home network device uses the domain name included in the domain name configuration information of the domain master node as the home network device. domain name.
  • the network security access device may also include a processing unit, configured to open the pairing window after the receiving unit receives the domain name configuration confirmation message sent by the home network device.
  • the sending unit is further configured to send indication information during a validity period of the pairing window, where the indication information is used to indicate that the home network device is allowed to join the domain for pairing.
  • the home network device by sending the domain name configuration information of the domain master node, the home network device can perform domain name configuration according to the domain name configuration information of the domain master node, and the pre-configured manner is adopted to make the domain name configuration flexibility of the home network device more flexible. Big.
  • the sending unit sends the prompting information to the user, and the authorized operation received by the receiving unit is operated according to the prompting information sent by the sending unit to the user, where the prompting information is used to prompt the home network device that needs to join the domain for pairing.
  • the prompt information sent by the sending unit is displayed locally on the domain master node or displayed on the proxy node, and the authorization operation received by the receiving unit is an operation of the user on the domain master node or the proxy node.
  • the prompt information displayed locally on the domain master node or displayed on the proxy node is a flashing prompt
  • the user's operation on the domain master node or the proxy node is a button operation.
  • the prompt information sent by the sending unit is sent by the domain master node or the proxy node to the terminal used by the user and displayed on the terminal, for example, may be a domain master node or a terminal sent by the proxy node to the user and used on the terminal.
  • An application for the user to perform an authorization operation is installed on the terminal, and the authorization operation received by the receiving unit is triggered by the user operating the application.
  • the user can perform one-click authorization operation on the domain master node or the used terminal by using the prompt information, and does not need to perform bilateral docking operation on other home network devices and domain master nodes that access the home network, and the operation is simple and convenient. It also enables home network devices to quickly access the home network.
  • the receiving unit is further configured to receive a notification message sent by the home network device, where the notification message is used to notify the home network device that needs to join the domain for pairing.
  • the sending unit sends the prompt information to the user to the domain master node in the following manner: according to the notification message, the prompt information is sent to the user.
  • the notification message received by the receiving unit includes an identifier of the home network device that sends the notification message.
  • the indication information sent by the sending unit includes the identifier of the home network device that sends the notification message.
  • the identifier of the home network device that sends the notification message is included in the notification message, and the identifier of the home network device that sends the notification message is also included in the indication information, so that the home network device corresponding to the identifier can be connected to the home.
  • the network prevents other home network devices from accessing and improves security.
  • the network security access device provided by the third aspect of the embodiment of the present application may be a domain master node, or may be a chip in the domain master node.
  • the domain master node or the chip has the functionality involved in implementing the network security admission method in any of the possible aspects of the first aspect or the first aspect.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more units corresponding to the functions described above.
  • the domain master node includes a transmitting unit, a receiving unit, and a processing unit, and the sending unit may be a transmitter, and the receiving unit may be a receiver, and the receiver and the transmitter may include a radio frequency circuit.
  • the processing unit can be, for example, a processor.
  • the domain master node may further include a storage unit, and the storage unit may be, for example, a memory.
  • the storage unit is configured to store a computer execution instruction
  • the processing unit is coupled to the storage unit, and the processing unit executes a computer execution instruction stored by the storage unit to enable
  • the domain master node performs the network security admission method in any of the possible aspects of the first aspect or the first aspect.
  • the chip includes: a transmitting unit, a receiving unit, and a processing unit, and the transmitting unit and the receiving unit may be an input/output interface, a pin or a circuit on the chip.
  • the processing unit can be, for example, a processor.
  • the chip further includes a storage unit, and the storage unit may be, for example, a memory.
  • the processing unit may execute computer-executable instructions stored by the storage unit to cause the chip to perform a network security admission method in any of the possible aspects of the first aspect or the first aspect.
  • a network security access device has a network security access method for implementing a home network device that needs to join a domain for pairing in any possible design of the second aspect or the second aspect.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more units corresponding to the functions described above.
  • the network security access device includes a processing unit and a sending unit, wherein the processing unit is configured to determine that a domain needs to be joined for pairing.
  • the sending unit is configured to send a notification message to the domain master node, where the notification message is used to notify the domain master node that there is a home network device that needs to join the domain for pairing.
  • the processing unit detects power-on or detects the presence of a new domain, it is determined that the domain needs to be joined for pairing.
  • the home network device that needs to join the domain for pairing may further include a storage unit, which may be, for example, a memory.
  • a storage unit which may be, for example, a memory.
  • the storage unit is configured to store a computer execution instruction
  • the processing unit is coupled to the storage unit, and the processing unit executes a computer execution instruction stored by the storage unit to enable
  • the home network device that needs to join the domain for pairing performs the network security admission method in any possible design of the second aspect or the second aspect.
  • the network security access device includes a receiving unit, a processing unit, and a sending unit, wherein the receiving unit is configured to receive domain name configuration information of the domain master node sent by the domain master node.
  • the processing unit is configured to use, as the domain name of the home network device, a domain name included in the domain name configuration information of the domain master node received by the receiving unit.
  • the sending unit is configured to send a domain name configuration confirmation message to the domain master node.
  • the network security access device may further include a storage unit, and the storage unit may be, for example, a memory.
  • the storage unit is configured to store a computer execution instruction
  • the processing unit is connected to the storage unit, and the processing unit executes a computer execution instruction stored by the storage unit, To enable the home network device to perform the network security admission method in any of the possible aspects of the second aspect or the second aspect.
  • the network security access device provided in the fourth aspect of the embodiments of the present application may be a home network device that needs to be joined to the domain for pairing, or may be a chip in the home network device that needs to join the domain for pairing.
  • the home network device or the chip has the functionality involved in implementing the network security admission method in any of the possible aspects of the second aspect or the second aspect.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more units corresponding to the functions described above.
  • the transmitting unit involved in the network security access device provided by the fourth aspect may be a transmitter, and the receiving unit may be a receiver, and the receiver and the transmitter may include a radio frequency circuit.
  • the processing unit can be, for example, a processor.
  • the storage unit can be, for example, a memory.
  • the chip includes a processing unit and a transmitting unit, and may also include a receiving unit.
  • the transmitting unit and the receiving unit may be input/output interfaces, pins or circuits on the chip.
  • the processing unit can be, for example, a processor.
  • the chip further includes a storage unit, and the storage unit may be, for example, a memory.
  • the storage unit included in the chip involved in the third aspect and the fourth aspect may be a storage unit (for example, a register, a cache, and the like) in the chip, and the storage unit may further be the A storage unit external to the chip (eg, a read only memory) or other type of static storage device (eg, random access memory) that can store static information and instructions, and the like.
  • a storage unit for example, a register, a cache, and the like
  • the storage unit may further be the A storage unit external to the chip (eg, a read only memory) or other type of static storage device (eg, random access memory) that can store static information and instructions, and the like.
  • the processor involved in the third aspect and the fourth aspect may be a central processing unit, a microprocessor or an application specific integrated circuit, or may be one or more used to control the implementation of the above aspects or aspects.
  • the cyber security access method of the program executes the integrated circuit.
  • the embodiment of the present application provides a computer readable storage medium, where the computer readable storage medium stores computer instructions, and when the instructions are run on a computer, may complete any of the above aspects or aspects.
  • the embodiment of the present application provides a computer program product, the computer program product comprising a computer program for performing network security in any of the above aspects or aspects Into the method.
  • the network security access method, the device, the domain master node, and the home network device provided by the embodiment of the present application trigger the domain master node to open the pairing window through the authorization operation of the user, so that the new device is authorized to join the domain before the domain master node opens the pairing window.
  • the situation that a new device without authorization is added to the domain after the pairing window is opened can be avoided, the resource waste is avoided, and the security of the security access is improved.
  • the home network device can automatically access the home network and perform data transmission, and the operation is convenient and concise.
  • FIG. 1 is a domain network architecture according to an embodiment of the present application
  • FIG. 2 is a schematic diagram of a process for secure admission of a home network device according to an embodiment of the present application
  • FIG. 3 is a schematic structural diagram of a home power line network according to an embodiment of the present application.
  • FIG. 4A is a flowchart of a method for secure admission of a home network device according to an embodiment of the present application
  • 4B is a flowchart of another method for secure admission of a home network device according to an embodiment of the present application.
  • FIG. 5A is a flowchart of still another method for secure admission of a home network device according to an embodiment of the present application.
  • FIG. 5B is a flowchart of still another method for secure admission of a home network device according to an embodiment of the present application.
  • 6A is a flowchart of still another method for secure admission of a home network device according to an embodiment of the present application
  • 6B is a flowchart of still another method for secure admission of a home network device according to an embodiment of the present application.
  • FIG. 7 is a schematic structural diagram of a network security access device according to an embodiment of the present application.
  • FIG. 8 is a schematic structural diagram of a home network device according to an embodiment of the present application.
  • FIG. 9 is a schematic structural diagram of another network security access device according to an embodiment of the present disclosure.
  • FIG. 10 is a schematic structural diagram of another home network device according to an embodiment of the present disclosure.
  • FIG. 11 is a schematic structural diagram of another network security access device according to an embodiment of the present application.
  • FIG. 12 is a schematic structural diagram of another home network device according to an embodiment of the present application.
  • FIG. 13 is a schematic structural diagram of another network security access device according to an embodiment of the present application.
  • FIG. 14 is a schematic structural diagram of another home network device according to an embodiment of the present application.
  • a home network device can be understood as a device that communicates over a home network medium.
  • a home network device may also be referred to as a communication node, or a terminal node.
  • the home network medium may be, for example, a coaxial cable, a twisted pair cable, a power line, a plastic optical fiber, or the like.
  • some examples of home network devices are: terminals that integrate a home network chip, such as a digital subscriber line (DSL modem), an optical network terminal (ONT), a home router, etc., such terminal devices can Connect up to the Internet, connect user terminals down through the home network; wireless or wireline access points (APs), and power line communication devices that may be used in industrial applications, including smart meters, and Various Internet of Things (IoT) devices access the home network through the above-mentioned home network medium, and connect various types of terminals downwards or themselves as terminal devices.
  • DSL modem digital subscriber line
  • ONT optical network terminal
  • home router etc.
  • IoT Internet of Things
  • a domain may be understood to be a communication network comprising a plurality of home network devices, and a domain may include a plurality of home network devices communicating over a home network medium.
  • a domain master node, a domain terminal node 1 to a domain terminal node 4 form a domain.
  • Intra-domain communication may or may not be encrypted, and the corresponding domain may include a security domain and a non-security domain. Encryption is used to communicate between each home network device in the security domain. It is not encrypted when communicating between home network devices in a non-secure domain.
  • Domain master node English representation can be domain master, referred to as DM.
  • the domain master node can be understood as a home network node with management control functions in the domain.
  • the domain master node can interact with the home network device located outside the domain to join the home network device located outside the domain into the domain.
  • the domain terminal node can be an end point node, referred to as an EP Node.
  • An EP Node can be understood as a home network node other than the domain master node in the domain.
  • the home network device may perform role switching between the domain primary node and the domain terminal node.
  • Security admission can be understood as the process of joining a home network device to a domain for pairing networking.
  • the paired networking can be understood as a process of forming a private network between home network devices.
  • Pairing window refers to the time window that allows the home network device to perform pairing networking (security access).
  • the security of communication between home network devices is ensured by means of secure admission between home network devices.
  • the domain master node, the domain terminal node 1 to the domain terminal node 4 form a domain.
  • the domain master node, the domain terminal node 1 to the domain terminal node 4 can perform secure communication in the domain through the home network medium.
  • the home network device 5 and the home network device 6 located outside the domain need to perform a secure admission process to join the domain if secure communication is required.
  • the user needs to operate the paired home network device to trigger the domain master node to open the pairing window, and both need to open the pairing window on the domain master node before the user can decide whether to authorize If the new home network device is added to the domain, if the user cannot authorize the new node to join the domain within the preset duration of the pairing window, the resource may be wasted and may be illegally added by the malicious device. Lower.
  • the embodiment of the present application provides a method for secure admission, which can be applied to a home network that communicates through a home network medium, and is also applicable to security in addition to the home network field.
  • the areas of the problem may also be used in areas such as enterprise communications, industrial interworking, and the Internet of Things.
  • the home network device that is the domain master node determines that there is a home network device that needs to join the domain for pairing, and sends a prompt message to the user.
  • the user performs an authorization operation according to the prompt information sent by the domain master node, and the domain master node receives the authorization operation of the user, and opens the pairing window when determining that the user's authorization operation is received, and sends a message indicating that the device is allowed to join the domain during the validity period of the pairing window.
  • Instructions for pairing A home network device that needs to join a domain for pairing (or a home network device that is also understood to be a domain terminal node) may initiate a registration request after receiving the indication information sent by the domain master node to complete the security admission process.
  • the user performs the authorization operation by using the prompt information, and does not require the user to cooperate with the device such as a television or a computer, so that the matching network of the home network is more friendly to the user and the operation is more convenient.
  • the user's authorization operation triggers the domain master node to open the pairing window, so that the new device is authorized to join the domain before the domain master node opens the pairing window, thereby avoiding the situation that new devices without authorization are added to the domain after the pairing window is opened, and avoiding Waste of resources and improve the security of secure access (or paired networking).
  • the validity period of the pairing window can be set relatively short compared with the prior art, thereby further reducing the chance of illegal entry of the malicious device and improving the security of the security access.
  • the prompt information may be directly sent to the user through the domain master node, or the proxy node may send the prompt information to the user.
  • the proxy node can be any domain endpoint.
  • the proxy node displays the prompt information to the user as a device of the user interface, for example, the domain master node notifies the proxy node to prompt the user to flash.
  • the user's authorization operation may be that the user directly performs a key operation on the domain master node, or the user performs a key operation on the proxy node, and the proxy node notifies the domain master node user of the button authorization operation.
  • the domain master node may directly send a push message to the terminal used by the user or notify the proxy node to send a push message to the terminal used by the user, and the user authorization operation may also be a one-click authorization performed by the user on the application installed on the used terminal. operating.
  • a power line network also known as power line communication (PLC) refers to the use of existing power lines to transmit data or information in a digital signal processing method.
  • PLC power line communication
  • the power line covers a wide range and naturally covers the households and corridors of the residents. Therefore, the home power line network has certain advantages in the application of home network technology.
  • FIG. 3 is a schematic structural diagram of a home power line network according to an embodiment of the present application.
  • the domain master node as an access device of the home power line network may be located on a terminal device such as an ONT or a DSL Modem, and connected to the carrier network through an optical fiber or a copper wire, and performs uplink data transmission.
  • the domain master node can be connected to the home network device 1 (domain terminal node 1) to the home network device 5 (domain terminal node 5) through a medium such as a power line or a coaxial cable.
  • the power line can be wirelessly fidelity in FIG.
  • wireless fidelity, Wi-Fi access point
  • wired AP and smart home appliances are connected to home network devices for downlink data transmission and management of home power line networks.
  • the domain master node device can implement data transmission across the network between the carrier network and the home power line network.
  • Home network equipment such as power cats and routers can connect to the domain master node through the power line and perform uplink data transmission.
  • Home network equipment such as power cats and routers can be used as domain terminal nodes to access the home power line network, and connected to terminals such as mobile phones, computers, and televisions used by users through connection methods such as network cable or wireless fidelity (WI-FI).
  • WI-FI wireless fidelity
  • a home network device that connects to and performs downlink data transmission as a domain terminal node to access a home power line network can also be understood as a home network device that is a lower-level network distribution node.
  • the home network device that accesses the home power line network as the domain terminal node can determine to access the home power line network, and can be used as the domain master node.
  • the home network device transmits a notification message for notifying that there is a home network device that is a domain terminal node accessing the home power line network.
  • the home network device node that is the domain master node may send a prompt message to the user, and the prompt information is used to prompt the presence of the domain power node as the domain terminal node.
  • Network home network equipment After receiving the prompt information, the user may perform an authorization operation if the home network device is allowed to join the home power line network.
  • the domain master node may open the pairing window and send indication information during the validity period of the pairing window to indicate that the home network device is allowed to access the home power line network.
  • the domain master node acts as the management node of the home network, and can also be located on other terminal devices, such as Wi-Fi AP devices.
  • the ONT or DSL modem can be used as a domain terminal node to access the home.
  • the network is connected to other home network equipment through a medium such as a power line or a coaxial cable, and is connected to the carrier network through an optical fiber or a copper wire.
  • devices such as ONTs or DSL modems do not integrate the functions of the home network chip, but are directly connected to the home network device through separate home network devices, which are connected to other home network devices through a medium such as a power line or a coaxial cable.
  • the domain master node can be located on any home network device to perform functions such as management and resource allocation. It should be noted that the method of signing security access is applicable to applications in these scenarios to ensure access and communication security on the home network.
  • the home network device is connected to the home power line network in the foregoing manner, and the user only needs to perform a simple authorization operation according to the prompt information sent by the domain master node, so that the home network device can automatically access the home power line network and perform data. Transmission, easy to operate.
  • the following is an example of applying the security admission method to the home power line network as an example.
  • the home network device involved in the embodiment of the present application may also be referred to as a power line communication device. If the secure admission method is applied to a network other than the home network, the corresponding name can be changed accordingly.
  • the home network device referred to in the following embodiments refers to a home network device located outside the domain, or may also be understood as a home network device that needs to join the domain for pairing, or may also be understood as a domain terminal node or a lower level.
  • the network distribution node accesses the home network device of the home network.
  • FIG. 4A is a flowchart of a method for implementing security admission of a home network device according to an embodiment of the present application. Referring to FIG. 4A, the method includes:
  • S101a The domain master node sends a prompt message to the user, where the prompt information is used to prompt the home network device that needs to join the domain for pairing.
  • the prompt information sent by the domain master node to the user in the embodiment of the present application may be the prompt information displayed locally on the domain master node, for example, the prompt information may be a domain master node flashing prompt.
  • the domain master node prompts the user to have a home network device that needs to join the domain for pairing.
  • the prompt information sent by the domain master node to the user in the embodiment of the present application may be a push message, and the domain master node sends a push message to the terminal used by the user.
  • the push message sent by the terminal to the domain master node may be displayed on the terminal to prompt the user to have a home network device that needs to join the domain for pairing, and the push message may be implemented by an application (APP) of the smart phone.
  • APP application
  • S102a The user performs an authorization operation according to the prompt information sent by the primary node to the user, where the authorization operation is used to indicate that the home network device is allowed to join the domain for pairing operation.
  • the domain master node receives the authorization operation of the user.
  • the authorization operation performed by the user in the embodiment of the present application may adopt different implementation forms according to different prompt information.
  • the prompt information is prompt information displayed locally on the domain master node
  • the authorization operation may be a user operation on the master node.
  • the user's operation on the master node may be, for example, a button operation, and of course other methods.
  • the user can perform the authorization operation on the domain master node through the prompt information, and does not need to perform bilateral docking operations on other home network devices and domain master nodes that access the home power line network, and the operation is simple and convenient, and can enable the family. Network devices quickly access the home power line network.
  • the prompt information is a push message sent by the domain master node to the terminal and displayed on the terminal
  • the application used by the user is installed with an application (APP) for performing the authorization operation
  • the user's authorization operation may be performed by the user to the terminal.
  • the installed APP is triggered by an operation, for example, a one-click authorization operation performed on the APP, and of course, other operation modes.
  • the user can perform one-click authorization operation on the terminal used by using the prompt information, and does not need to perform bilateral docking operation on other home network devices and domain master nodes that access the home power line network, and the operation is simple and convenient, and can Home network equipment quickly accesses the home power line network.
  • S103a The domain master node determines to start the pairing window when receiving the authorization operation of the user.
  • the domain master node sends indication information during the validity period of the pairing window, where the indication information is used to indicate that the home network device is allowed to join the domain for pairing.
  • the indication information sent by the domain master node in the embodiment of the present application may be a MAP message.
  • the home network device receives the indication information sent by the domain master node, and sends a registration request to the domain master node.
  • the domain master node receives the registration request sent by the home network device, and returns a registration confirmation message to the home network device, so as to implement the security admission process of the home network device.
  • the secret key message may be carried to implement communication between the home network device and the domain master node in the security domain.
  • the manner in which the domain master node sends the prompt information to the user in the embodiment of the present application may include the foregoing implementation manner in which the domain master node directly sends the prompt information to the user, and may also include an implementation manner in which the prompt information is indirectly sent to the user through the proxy node.
  • FIG. 4B is a flow chart showing the implementation of prompting information to the user indirectly through the proxy node according to the embodiment of the present application. Referring to FIG. 4B, the method includes:
  • S101b The domain master node sends a first notification message to the proxy node, where the first notification message is used to notify the proxy node to perform the prompt operation.
  • the proxy node receives the first notification message sent by the domain master node, and sends a prompt message to the user.
  • the implementation process of the prompting information sent by the proxy node to the user is similar to the implementation process of the prompt information sent by the domain master node to the user, and may be displayed locally or may be sent to the terminal used by the user and displayed on the terminal used by the user.
  • the domain master node sends a prompt message to the user, and details are not described herein.
  • S103b The proxy node receives the authorization operation of the user.
  • the user root prompt information After the user obtains the prompt information sent by the proxy node, the user root prompt information performs an authorization operation, and the specific authorization operation may be a key operation performed by the user on the proxy node. Or the user's authorized operation may also be a one-click authorization operation performed by the user on the application installed on the terminal used.
  • the authorization operation refer to the implementation process in the foregoing embodiment for performing the authorization operation according to the prompt information sent by the domain master node, and details are not described herein.
  • S104b The proxy node sends a second notification message to the domain master node, where the second notification message is used to notify the domain master node that the user's authorization operation has been received.
  • the proxy node may send a second notification message to the domain master node to notify the user of the domain master node that the authorization operation has been performed, for example, the proxy node notifies the domain master node user of the button authorization.
  • a second notification message to the domain master node to notify the user of the domain master node that the authorization operation has been performed, for example, the proxy node notifies the domain master node user of the button authorization.
  • S105b, S106b, S107b, and S108b is similar to the execution process of S103a, S104a, S105a, and S106a in the foregoing embodiment, and the embodiments of the present application are not described in detail herein.
  • the home network device security admission method provided by the embodiment of the present application, the user performs an authorization operation on the home network device that needs to be joined to the domain according to the prompt information of the domain master node, and the domain master node starts pairing after receiving the authorization operation of the user.
  • the window is configured to authorize the home network device to join the domain before the domain master node opens the pairing window, thereby avoiding the situation that the unauthorised home network device joins the domain after the pairing window is opened, thereby avoiding waste of resources.
  • the validity period of the pairing window can be set relatively short compared with the prior art, thereby reducing the chance of illegal entry of malicious devices to a certain extent, and improving the security of security access. .
  • the home network device that needs to join the domain for pairing may send a notification message to the domain master node to notify that there is a need to pair Home network equipment.
  • the domain master node determines the prompt information to prompt the user to have a home network device that needs to join the domain for pairing.
  • FIG. 5A is a flowchart of a method for implementing security admission of a home network device according to an embodiment of the present application. Referring to FIG. 5A, the method includes:
  • S201a The home network device sends a third notification message to the domain master node, where the third notification message is used to notify the home network device that needs to join the domain for pairing.
  • the home network device in the embodiment of the present application may send a notification message to the home network device that is the domain master node when being allowed to access the home network as the domain terminal node.
  • the home network device may send a third notification message to the domain master node after power-on, or the home network device may also send a third notification message to the domain master node when detecting that a newly created domain exists in the network.
  • the third notification message sent by the home network device to the domain master node in the embodiment of the present application may also be referred to as the node presence information (ADM_NodePresense.ind), and the specific form of the third notification message is not limited in this embodiment. .
  • the third notification message sent by the home network device to the domain master node may include an identifier of the home network device, so that the domain master node determines, by using the identifier, the home network device that needs to join the domain for pairing.
  • the domain master node receives the third notification message sent by the home network device, determines that there is a home network device that needs to join the domain for pairing (there is a home network device that is allowed to access the home network as the domain terminal node), and displays the prompt locally.
  • the information or the terminal used by the user sends a prompt message to prompt the user to have a home network device that needs to join the domain for pairing.
  • the prompt information may further include the identifier of the home network device, so that the user The home network device that needs to join the domain for pairing can be determined by the identifier to determine whether to authorize the home network device corresponding to the identifier.
  • the domain master node may determine whether the home network device that needs to join the domain to be paired belongs to the home network of the home, and determines the home network belonging to the home network. Under the premise, the user is prompted. For example, the signal strength of the home network device that sends the third notification message (which may of course be other information) may be detected, and it is determined according to the signal strength whether the home network device that sends the third notification message belongs to the home network of the home. For example, if the signal strength is less than the set threshold, it may be determined that the home network device that sends the third notification message does not belong to the home network of the home, and may belong to the home network of the neighbor home. In this case, the prompt information may not be sent to the user. In the case of intelligent elimination of false positives and misstatements.
  • S203a, S204a, S205a, S206a, and S207a is similar to the execution process of S102a, S103a, S104a, S105a, and S106a, and the embodiments of the present application are not described in detail herein.
  • the indication information sent by the domain master node to the home network device in the embodiment of the present application may include the identifier of the home network device to implement security access for the home network device corresponding to the identifier.
  • the method for implementing the security access of the home network device is to send a third notification message to the domain master node by using the home network device that needs to join the domain to notify the domain master node that there is a home network that needs to join the domain for pairing.
  • the device does not require the user to operate the home network device located in the domain, so that the implementation process of the security access can be simplified, and the efficiency of the security access is improved.
  • the domain master node may send a first notification message to the proxy node, and notify the proxy node to perform the prompt operation by using the first notification message.
  • the proxy node sends a prompt message to the user, and receives an authorization operation performed by the user according to the prompt information sent by the proxy node.
  • the proxy node sends a second notification message to the domain master node to notify the domain master node that the authorization operation has been issued.
  • the domain master node can open the pairing window and perform the security admission process.
  • FIG. 5B The specific implementation process can be seen in FIG. 5B. The execution process of S201b in FIG.
  • 5B is similar to the execution process of S201a in FIG. 5A, and the execution processes of S202b, S203b, S204b, S205b, S206b, S207b, S208b, and S209b are the same as S101b, S102b, S103b, S104b, S105b, S106b in FIG. 4B.
  • the execution processes of S107b and S108b are the same and will not be described here.
  • the home network device needs to perform domain name configuration during the security access process, but the domain name is usually configured in a pre-configured manner, which is less flexible.
  • the embodiment of the present application provides a domain name configuration method in a security access process of a home network device.
  • the domain master node may send the domain master node after receiving the authorization operation of the user.
  • the domain name configuration information the home network device can receive the domain name configuration information sent by the domain master node, use the domain name included in the domain name configuration information of the domain master node as the domain name of the home network device, and send a domain name configuration confirmation message to the domain master node.
  • the domain name configuration confirmation message indicates that the home network device uses the domain name included in the domain name configuration information of the domain master node as the domain name of the home network device. In this way, the home network device can perform domain name configuration according to the domain name configuration information of the domain master node, and the pre-configured manner is adopted to make the domain name configuration flexibility of the home network device larger.
  • the home network device that needs to join the domain for pairing in the embodiment of the present application may also send a notification message to the domain master node, and the notification message indicates that there is a home network device that needs to join the domain for pairing.
  • the domain master node Before receiving the authorization operation of the user, the domain master node receives the notification message sent by the home network device, and then determines the prompt message according to the notification message.
  • the notification message may include an identifier of the home network device.
  • the prompt information involved in the implementation of the domain name configuration in the embodiment of the present application is similar to the notification message in the foregoing embodiment. Therefore, for the related explanation of the notification message, refer to the description of the foregoing embodiment, and details are not described herein.
  • the authorization operation of the user may be performed according to the prompt information sent by the domain master node to the user, and the prompt information is used to prompt the home network device that needs to join the domain for pairing.
  • the prompt information involved in the implementation of the domain name configuration in the embodiment of the present application is similar to the prompt information in the foregoing embodiment. Therefore, for the related explanation of the prompt information, refer to the description of the foregoing embodiment, and details are not described herein.
  • the pairing window may be opened, and the indication information is sent during the validity period of the pairing window, where the indication information is used to indicate that the home network device is allowed to join the domain. pair.
  • FIG. 6A is a flowchart of still another method for implementing security admission of a home network device according to an embodiment of the present application.
  • the execution process of S301a, S302a, and S303a is the same as the execution process of S201a, S202a, and S203a, and will not be described in detail herein.
  • the domain master node receives the authorization operation of the user, and sends the domain name configuration information of the domain master node to the home network device.
  • the domain name configuration information includes the domain name of the domain where the domain master node is located.
  • the home network device receives the domain name configuration information sent by the domain master node, uses the domain name included in the domain name configuration information as the domain name of the home network device, and sends a domain name configuration confirmation message to the domain master node.
  • the domain name configuration confirmation message is used to indicate that the home network device uses the domain name included in the domain name configuration information of the domain master node as the domain name of the home network device.
  • the domain name included in the domain name configuration information is used as the domain name of the home network device, and the domain name included in the domain name configuration information may be directly used as the domain name of the home network device, or may be included in the domain name configuration information. Add the domain name to the configured domain name list, and then select the domain name included in the domain name configuration information as the domain name of the home network device in the domain name list.
  • S306a The home network device receives the domain name configuration confirmation message sent by the home network device, and starts the pairing window.
  • S307a, S308a, and S309a is similar to the execution process of S104a, S105a, and S106a, and the embodiments of the present application are not described in detail herein.
  • the domain master node may send a first notification message to the proxy node, and notify the proxy node to perform the prompt operation by using the first notification message.
  • the proxy node sends a prompt message to the user, and receives an authorization operation performed by the user according to the prompt information sent by the proxy node.
  • the proxy node sends a second notification message to the domain master node to notify the domain master node that the authorization operation has been issued.
  • the domain master node may send domain name configuration information to the home network device that needs to join the domain for pairing, and perform security admission execution.
  • the specific implementation process can be seen in Figure 6B.
  • the execution processes of S301b, S302b, S303b, S304b, and S305b in FIG. 6B are the same as the execution processes of S201b, S202b, S203b, S204b, and S205b, and the execution processes of S306b, S307b, S308b, S309b, S310b, and S311b are performed with S304a, S305a, and S306a.
  • the execution processes of S307a, S308a, and S309a are the same, and are not described herein again.
  • the solution provided by the embodiment of the present application is introduced from the perspective of interaction between the domain master node and the home network device.
  • the domain master node and the home network device include corresponding hardware structures and/or software modules for performing the respective functions in order to implement the above functions.
  • the embodiments of the present application can be implemented in a combination of hardware or hardware and computer software in combination with the units (devices, devices) and algorithm steps of the examples described in the embodiments disclosed in the application. Whether a function is implemented in hardware or computer software to drive hardware depends on the specific application and design constraints of the solution. A person skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the technical solutions of the embodiments of the present application.
  • the embodiments of the present application may perform functional unit (device, device) division on the domain master node and the home network device according to the foregoing method example.
  • each functional unit (device, device) may be divided according to each function, or two or More than two functions are integrated in one processing unit (device, device).
  • the above integrated units (devices, devices) can be implemented in the form of hardware or in the form of software functional units (devices, devices). It should be noted that the division of the unit (device, device) in the embodiment of the present application is schematic, and is only a logical function division, and the actual implementation may have another division manner.
  • FIG. 7 is a schematic structural diagram of a network security access device 100 according to an embodiment of the present application.
  • the network security access device 100 may be a domain master node or a component in the domain master node.
  • the network security admission device 100 includes a transmitting unit 101, a receiving unit 102, and a processing unit 103.
  • the sending unit 101 is configured to send a prompt message to the user, where the prompt information is used to indicate that there is a home network device that needs to join the domain for pairing.
  • the receiving unit 102 is configured to receive an authorization operation of the user, where the authorization operation is performed by the user according to the prompt information sent by the sending unit 101, and is used to indicate that the home network device is allowed to join the domain for the pairing operation.
  • the processing unit 103 is configured to start the pairing window when determining that the receiving unit 102 receives the authorization operation of the user, and send the indication information during the validity period of the pairing window, the indication information is used to indicate that the home network device is allowed to join the domain for pairing.
  • the prompt information sent by the sending unit 101 may be prompt information displayed locally on the domain master node or may also be prompt information displayed at the proxy node, and the authorization operation received by the receiving unit 102 may be the user.
  • the prompt information displayed locally on the domain master node or the prompt information displayed at the proxy node is a flashing prompt
  • the user's operation on the master node may be a button operation, which may be understood as a one-button authorization operation.
  • the user performs a one-click authorization operation through the prompt information, and does not require the user to use the television, the computer, and the like to operate together, so that the matching network of the home network is more friendly to the user, and the operation is more convenient.
  • the user's authorization operation triggers the domain master node to open the pairing window, so that the new device is authorized to join the domain before the domain master node opens the pairing window, thereby avoiding the situation that new devices without authorization are added to the domain after the pairing window is opened, and avoiding Waste of resources and improve the security of secure access (or paired networking).
  • the validity period of the pairing window can be set relatively short compared with the prior art, thereby further reducing the chance of illegal entry of the malicious device and improving the security of the security access.
  • the prompt information sent by the sending unit 101 may be a prompt information sent by the domain master node or the proxy node to the terminal used by the user and displayed on the terminal, and the terminal used by the user is installed for the user.
  • the authorization operation received by the receiving unit can be triggered by the user operating the application installed on the terminal.
  • the prompt information that the domain master node sends to the terminal used by the user and displayed on the terminal may be a push message that is sent by the domain master node to the terminal used by the user and displayed on the terminal.
  • the user's operation on the application installed on the terminal can be a one-click authorization operation.
  • the receiving unit 102 is further configured to receive a notification message sent by the home network device, where the notification message is used to notify the home network device that needs to join the domain for pairing.
  • the sending unit 101 is configured to send the prompt information to the user according to the notification message received by the receiving unit 102.
  • the notification message received by the receiving unit 102 includes the identifier of the home network device that sends the notification message.
  • the indication information sent by the sending unit 101 also includes the identifier of the home network device that sent the notification message.
  • the identifier of the home network device that sends the notification message is included in the notification message, and the identifier of the home network device that sends the notification message is also included in the indication information, so that the home network device corresponding to the identifier can be connected to the home.
  • the network prevents other home network devices from accessing and improves security.
  • the network security admission device 100 mentioned above may further include a storage unit 104.
  • the storage unit 104 is configured to store computer execution instructions
  • the processing unit 103 is coupled to the storage unit 104
  • the processing unit 103 executes computer execution instructions stored by the storage unit 104 to cause the network security admission device 100 to execute the domain master node in the above method embodiment.
  • the network security access method implemented.
  • the sending unit 101 and the receiving unit 102 may be a communication interface, a transceiver, a transceiver circuit, and the like.
  • the communication interface is a collective name and may include one or more interfaces.
  • the transceiver circuit can be a radio frequency circuit.
  • Processing unit 103 can be a processor or controller.
  • the storage unit 104 can be a memory.
  • the network security access device 100 When the sending unit 101 and the receiving unit 102 are transceivers, and the processing unit 103 is a processor, the network security access device 100 according to the embodiment of the present application may be the network security access device shown in FIG.
  • the network security access device can be applied to a home network device, which can be a domain master node.
  • FIG. 8 is a schematic structural diagram of a home network device 1000 according to an embodiment of the present application, that is, another possible structural diagram of the network security access device 100 is shown.
  • the home network device 1000 includes a processor 1001 and a transceiver 1002.
  • the processor 1001 can also be a controller.
  • the processor 1001 is configured to support the home network device 1000 to perform the functions of the domain master nodes involved in FIGS. 4 through 5.
  • the transceiver 1002 is configured to support the home network device 1000 for transceiving messages.
  • the home network device 1000 can also include a memory 1003 for coupling with the processor 1001 that retains the necessary program instructions and data for the home network device 1000.
  • the processor 1001, the transceiver 1002 and the memory 1003 are connected to each other.
  • the memory 1003 is configured to store an instruction
  • the processor 1001 is configured to execute the instruction stored in the memory 1003 to control the transceiver 1002 to send and receive signals, and complete the domain master in the foregoing method.
  • the network security access device 100 and the home network device 1000 are referred to the foregoing method or other embodiments. The description of these contents is not described here.
  • the network security access device 100 in the embodiment of the present application may be applied to a chip in a home network device, where the chip has a method for implementing a network security access method by a domain master node in the foregoing method embodiment.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more units corresponding to the functions described above.
  • the chip includes a transmitting unit 101, a receiving unit 102, and a processing unit 103.
  • the sending unit 101 and the receiving unit 102 may be input/output interfaces, pins or circuits on the chip.
  • Processing unit 103 may be, for example, a processor.
  • the chip may also include a storage unit 104.
  • the storage unit 104 can be, for example, a memory.
  • the processing unit 103 may execute computer execution instructions stored by the storage unit 104 to cause the chip to execute the network security admission method performed by the domain master node in the above method embodiment.
  • the storage unit 104 may be a storage unit (for example, a register, a cache, and the like) in the chip, and the storage unit 104 may also be a storage unit located outside the chip in the domain master node. (For example, read-only memory (ROM)) or other types of static storage devices (for example, random access memory (RAM)) that can store static information and instructions.
  • ROM read-only memory
  • RAM random access memory
  • FIG. 9 is a schematic structural diagram of another network security access device provided by an embodiment of the present application.
  • the network security access device 200 may be a domain master node or a component in the domain master node.
  • the network security admission device 200 includes a receiving unit 201 and a transmitting unit 202.
  • the receiving unit 201 is configured to receive an authorization operation of the user, where the authorization operation is used to indicate that the home network device is allowed to join the domain for the pairing operation.
  • the sending unit 202 is configured to send domain name configuration information of the domain master node.
  • the receiving unit 201 is configured to receive a domain name configuration confirmation message sent by the home network device, where the domain name configuration confirmation message is used to indicate that the home network device uses the domain name included in the domain name configuration confirmation message of the domain master node as the domain name of the home network device.
  • the authorization operation of the user is performed according to the prompt information sent by the sending unit 202 to the user, and the prompt information is used to indicate that there is a home network device that needs to join the domain for pairing.
  • the prompt information is displayed locally on the domain master node or displayed at the proxy node, and the authorization operation is a key operation of the user to the domain master node or the proxy node.
  • the prompt information displayed locally on the domain master node or the prompt information displayed at the proxy node is a flashing prompt
  • the user's operation on the domain master node or the proxy node is a key operation.
  • the prompt information is sent by the sending unit 202 to the terminal used by the user and displayed on the terminal, and the terminal is installed with an application for the user to perform an authorization operation, and the authorization operation is performed by the user on the application. trigger.
  • the receiving unit 201 is further configured to receive a notification message sent by the home network device, where the notification message is used to notify that there is a home network device that needs to be paired.
  • the sending unit 202 is configured to send prompt information to the user according to the notification message received by the receiving unit 201.
  • the notification message sent by the home network device includes the identifier of the home network device.
  • the network security access device 200 may further include a processing unit 203, wherein the processing unit 203 is configured to open the pairing window after the receiving unit 201 receives the domain name configuration confirmation message sent by the home network device.
  • the sending unit 202 is further configured to send indication information during a validity period of the pairing window, where the indication information is used to indicate that the home network device is allowed to join the domain for pairing.
  • the network security admission device 200 mentioned above may further include a storage unit 204.
  • the storage unit 204 is configured to store computer execution instructions
  • the processing unit 203 is coupled to the storage unit 204, and the processing unit 203 executes computer execution instructions stored by the storage unit 204 to cause the network security admission device 200 to perform the domain master node in the above method embodiment.
  • the network security access method implemented.
  • the receiving unit 201 and the sending unit 202 may be a communication interface, a transceiver, a transceiver circuit, or the like.
  • the communication interface is a collective name and may include one or more interfaces.
  • the transceiver circuit can be a radio frequency circuit.
  • Processing unit 203 can be a processor or controller.
  • Storage unit 204 can be a memory.
  • the network security access device 200 may be the network security access device shown in FIG.
  • the network security access device can be applied to a home network device, which can be a domain master node.
  • FIG. 10 is a schematic structural diagram of a home network device 2000 according to an embodiment of the present application, that is, another possible structural diagram of the network security access device 200.
  • the home network device 2000 includes a processor 2001, and a transceiver 2002.
  • the processor 2001 can also be a controller.
  • the processor 2001 is configured to support the home network device 2000 to perform the functions of the domain master node involved in FIG.
  • the transceiver 2002 is configured to support the home network device 2000 for transceiving messages.
  • the home network device 2000 can also include a memory 2003 for coupling with the processor 2001 that holds the necessary program instructions and data for the home network device 2000.
  • the processor 2001, the transceiver 2002 and the memory 2003 are connected, the memory 2003 is used to store instructions, and the processor 2001 is configured to execute the instructions stored in the memory 2003 to control the transceiver 2002 to send and receive signals, and complete the domain master in the above method.
  • the network security access device 200 and the home network device 2000 are referred to the foregoing method or other embodiments. The description of these contents is not described here.
  • the network security access device 200 involved in the embodiment of the present application may be applied to a chip in a home network device, where the chip has a method for implementing a network security access method by a domain master node in the foregoing method embodiment.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more units corresponding to the functions described above.
  • the chip includes a receiving unit 201 and a transmitting unit 202.
  • the receiving unit 201 and the transmitting unit 202 may be input/output interfaces, pins or circuits on the chip.
  • the chip may also include a processing unit 203 and a storage unit 204.
  • Processing unit 203 may be, for example, a processor, and storage unit 204 may be, for example, a memory.
  • the processing unit 203 may execute computer execution instructions stored by the storage unit 204 to cause the chip to execute the network security admission method performed by the domain master node in the above method embodiment.
  • the storage unit 204 may be a storage unit (for example, a register, a cache, and the like) in the chip, and the storage unit 204 may also be a storage unit located outside the chip in the domain master node. (For example, read-only memory (ROM)) or other types of static storage devices (for example, random access memory (RAM)) that can store static information and instructions.
  • ROM read-only memory
  • RAM random access memory
  • FIG. 11 is a schematic structural diagram of a network security access device 300 according to an embodiment of the present application.
  • the network security access device 300 may be a home network device that needs to join the domain for pairing (allowed to join the domain as a domain terminal node), or may be a family that needs to join the domain for pairing (allowed to join the domain as a domain terminal node) A component within a network device.
  • the network security access device 300 includes a processing unit 301 and a transmitting unit 302.
  • the processing unit 301 is configured to determine that the home network device needs to join the domain for pairing.
  • the sending unit 302 is configured to send a notification message to the domain master node when the processing unit 301 determines that the home network device needs to join the domain for pairing, and the notification message is used to notify the domain master node that there is a home network device that needs to join the domain for pairing.
  • the processing unit 301 may determine that it is necessary to join the domain for pairing (allowing to join the domain as a domain terminal node) when detecting the power-on or detecting the presence of the new domain.
  • the network security admission device 300 may further include a storage unit 303, which may be, for example, a memory.
  • a storage unit 303 is configured to store a computer execution instruction
  • the processing unit 301 is connected to the storage unit 303
  • the processing unit 301 executes the storage unit.
  • the stored computer executes the instructions to enable the network security access device 300 to perform the network security admission method performed by the home network device that needs to join the domain for pairing in the foregoing method embodiments.
  • the processing unit 301 may be a processor.
  • the transmitting unit 302 can be a transmitter, and the transmitter can include a radio frequency circuit.
  • the storage unit 303 can be a memory.
  • the network security access device 300 When the processing unit 301 is a processor, the sending unit 302 is a transmitter, and the storage unit 303 is a memory, the network security access device 300 according to the embodiment of the present application may be the network security access device shown in FIG.
  • the illustrated network security access device can be applied to a home network device, which can be a home network device that needs to join a domain for pairing.
  • FIG. 12 is a schematic structural diagram of a home network device 3000 according to an embodiment of the present application, that is, another possible structural diagram of the network security access device 300.
  • the home network device 3000 includes a processor 3001 and a transmitter 3002.
  • the processor 3001 can also be a controller.
  • the processor 3001 is configured to support the home network device 3000 to perform the functions of the home network device that need to join the domain for pairing in FIG. 4 to FIG.
  • the transmitter 3002 is configured to support the home network device 3000 for transmitting and receiving functions of messages.
  • the home network device 3000 can also include a memory 3003 for coupling with the processor 3001 that retains the necessary program instructions and data for the home network device 3000.
  • the processor 3001, the transmitter 3002, and the memory 3003 are connected to each other.
  • the memory 3003 is configured to store an instruction
  • the processor 3001 is configured to execute the instruction stored in the memory 3003 to control the transmitter 3002 to send and receive signals, and the method needs to be added to complete the foregoing method.
  • the network security access device 300 and the home network device 3000 are referred to the foregoing method or other embodiments. The description of these contents is not described here.
  • the network security access device 300 in the embodiment of the present application may be applied to a chip in a home network device that needs to join a domain for pairing.
  • the paired home network device performs the functions involved in the network security access method.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more units corresponding to the functions described above.
  • the chip includes a processing unit 301 and a transmitting unit 302.
  • the processing unit 301 can be, for example, a processor, and the sending unit 302 can be an input/output interface, a pin or a circuit on the chip.
  • the chip may also include a storage unit 303.
  • the storage unit 303 can be, for example, a memory.
  • the processing unit 301 can execute the computer-executed instructions stored by the storage unit 303 to enable the chip to execute the network security admission method performed by the home network device that needs to join the domain for pairing in the foregoing method embodiment.
  • the storage unit 303 may be a storage unit (for example, a register, a cache, and the like) in the chip, and the storage unit 303 may also be located in the home network device that needs to join the domain for pairing.
  • a storage unit external to the chip for example, a read-only memory (ROM)) or other type of static storage device (for example, a random access memory (RAM)) that can store static information and instructions. Wait.
  • ROM read-only memory
  • RAM random access memory
  • FIG. 13 is a schematic structural diagram of a network security access device 400 according to an embodiment of the present application.
  • the network security access device 400 may be a home network device that needs to join the domain for pairing, or may be a component in the home network device that needs to join the domain for pairing.
  • the network security admission device 400 includes a receiving unit 401 and a processing unit 402.
  • the receiving unit 401 is configured to receive domain name configuration information of the domain master node sent by the domain master node.
  • the processing unit 402 is configured to use the domain name included in the domain name configuration information of the domain master node received by the receiving unit 401 as the domain name of the home network device that needs to join the domain for pairing (allowing the domain terminal node to join the domain), and to the domain owner The node sends a domain name configuration confirmation message.
  • the processing unit 402 determines that it is necessary to join the domain for pairing (allowing to join the domain as a domain terminal node) when detecting the power-on or detecting the presence of the new domain.
  • the network security access device 400 may further include a sending unit 403, where the sending unit 403 is configured to: before the receiving unit 401 receives the domain name configuration information of the domain master node sent by the domain master node, the processing unit 402 When it is determined that the domain needs to be paired (allowed to join the domain as a domain terminal node), a notification message is sent to the domain master node, and the notification message is used to notify the domain master node that there is a need to join the domain for pairing (allowed to join as a domain terminal node) Domain) home network equipment.
  • the sending unit 403 is configured to: before the receiving unit 401 receives the domain name configuration information of the domain master node sent by the domain master node, the processing unit 402 When it is determined that the domain needs to be paired (allowed to join the domain as a domain terminal node), a notification message is sent to the domain master node, and the notification message is used to notify the domain master node that there is a need to join the domain for pairing (allowed to join
  • the network security access device 400 may further include a storage unit 404, which may be, for example, a memory.
  • a storage unit 404 is configured to store a computer execution instruction
  • the processing unit 402 is connected to the storage unit 404, and the processing unit 402 executes the storage unit.
  • the 404 stored computer executes the instructions to enable the network security access device 400 to perform the network security admission method performed by the home network device that needs to join the domain for pairing in the foregoing method embodiments.
  • the receiving unit 401 may be a receiver, a communication interface, a receiving circuit, or the like.
  • Processing unit 402 can be a processor.
  • the transmitting unit 403 may be a transmitter, a communication interface, a transmitting circuit, or the like.
  • the communication interface is a collective name and may include one or more interfaces.
  • a radio frequency circuit can be included in the receiving circuit and the transmitting circuit.
  • Storage unit 404 can be a memory.
  • the network security access device 400 may be the network security shown in FIG.
  • the access device, the network security access device shown in FIG. 14 can be applied to a home network device, and the home network device can be a home network device that needs to join a domain for pairing.
  • FIG. 14 is a schematic structural diagram of a home network device 4000 provided by an embodiment of the present application, that is, another possible structural diagram of the network security access device 400.
  • the home network device 4000 includes a processor 4001 and a receiver 4002, and may further include a transmitter 4003.
  • the processor 4001 can also be a controller.
  • the processor 4001 is configured to support the home network device 4000 to perform the functions of the home network device that need to join the domain for pairing in FIG. 6 .
  • Receiver 4002 and transmitter 4003 are configured to support home network device 4000 for transceiving messages.
  • the home network device 4000 can also include a memory 4004 for coupling with the processor 4001 that preserves the necessary program instructions and data for the home network device 4000.
  • the processor 4001, the receiver 4002, the transmitter 4003, and the memory 4004 are connected to the memory 4004.
  • the processor 4001 is configured to execute the instructions stored in the memory 4004 to control the receiver 4002 and the transmitter 4003 to transmit and receive. Signal, complete the steps in the above method that need to join the domain to pair the home network device to perform the corresponding function.
  • the network security access device 400 and the home network device 4000 are referred to the foregoing method or other embodiments. The description of these contents is not described here.
  • the network security access device 400 involved in the embodiment of the present application may be applied to a chip in a home network device that needs to be joined to a domain for pairing.
  • the paired home network device performs the functions involved in the network security access method.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more units corresponding to the functions described above.
  • the chip includes a receiving unit 401 and a processing unit 402.
  • the chip may also include a transmitting unit 403, or may also include a storage unit 404.
  • the processing unit 402 may be, for example, a processor, and the receiving unit 401 and the transmitting unit 403 may be input/output interfaces, pins or circuits on the chip.
  • the storage unit 404 can be, for example, a memory.
  • the processing unit 402 can execute the computer-executed instructions stored by the storage unit 404 to enable the chip to execute the network security admission method performed by the home network device that needs to join the domain for pairing in the foregoing method embodiment.
  • the storage unit 404 may be a storage unit (for example, a register, a cache, and the like) in the chip, and the storage unit 404 may also be located in the home network device that needs to join the domain for pairing.
  • a storage unit external to the chip for example, a read-only memory (ROM)) or other type of static storage device (for example, a random access memory (RAM)) that can store static information and instructions. Wait.
  • ROM read-only memory
  • RAM random access memory
  • the processor involved in the foregoing embodiments may be a central processing unit (CPU), a general-purpose processor, a digital signal processor (DSP), and an application-specific integrated circuit (application-specific).
  • the processor can also be a combination of computing functions, for example, including one or more microprocessor combinations, a combination of a DSP and a microprocessor, and the like.
  • the memory may be integrated in the processor or may be separately provided from the processor.
  • the transceiver can include a receiver and a transmitter.
  • the functions of the receiver and transmitter can be implemented by a dedicated chip through the transceiver circuit or transceiver.
  • the processor can be implemented by a dedicated processing chip, a processing circuit, a processor, or a general purpose chip.
  • program code that implements processor, receiver, and transmitter functions is stored in a memory that implements the functions of the processor, receiver, and transmitter by executing code in memory.
  • the embodiment of the present application further provides a home network communication system, which includes the foregoing domain master node and one or more home network devices that need to join the domain for pairing.
  • the embodiment of the present application further provides a computer storage medium, where the computer storage medium stores some instructions, and when the instructions are executed, the network security admission method involved in the foregoing method embodiments may be completed.
  • the embodiment of the present application further provides a computer program product, where the computer program product includes a computer program, and the computer program is used to execute the network security access method involved in the foregoing method embodiment.
  • embodiments of the present application can be provided as a method, system, or computer program product. Therefore, the embodiments of the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Moreover, embodiments of the present application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) including computer usable program code.
  • computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
  • Embodiments of the present application are described with reference to flowchart illustrations and/or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present application. It will be understood that each flow and/or block of the flowchart illustrations and/or FIG.
  • These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing device to produce a machine for the execution of instructions for execution by a processor of a computer or other programmable data processing device.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
  • These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
  • the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Automation & Control Theory (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Power Engineering (AREA)
  • Small-Scale Networks (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Selective Calling Equipment (AREA)

Abstract

一种网络安全准入方法及家庭网络设备,在应用该网络安全准入方法时,作为域主节点的家庭网络设备确定存在需要加入域进行配对的家庭网络设备时,向用户发出提示信息。用户根据域主节点发出的提示信息进行授权操作,域主节点接收用户的授权操作,并在确定接收到用户的授权操作时开启配对窗口,在配对窗口的有效期内发送用于指示允许设备加入域进行配对的指示信息。需要加入域进行配对的设备接收到域主节点发送的指示信息后可发起注册请求,以完成安全准入的过程。通过本申请实施例,用户通过提示信息进行授权操作,不需要用户使用电视、计算机等设备配合操作,使得家庭网络的配对组网面向用户更加友好,操作更加便捷。

Description

网络安全准入方法及家庭网络设备
本申请要求在2018年2月1日提交中国专利局、申请号为201810101960.5、发明名称为“网络安全准入方法及家庭网络设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及通信技术领域,尤其涉及一种网络安全准入及家庭网络设备。
背景技术
家庭网络(home network)技术是指家庭内部网络通信互连的技术,家庭网络介质比较丰富,常见的包括同轴电缆(coaxial cable)、双绞线(twisted pair line)、电力线(power line)及塑料光纤(plastic optical fiber)等。
包括ITU-T G.hn、IEEE Homeplug及MOCA等的标准均定义了在各种家庭网络介质上的家庭网络技术。其中ITU-T G.hn支持同轴电缆、双绞线、电力线及塑料光纤,IEEE Homeplug支持电力线,MOCA支持同轴电缆。
家庭网络用户向下连接用户终端,向上连接互联网(internet),提供家庭网络内终端互联及终端到互联网的服务。
家庭网络介质多数是开放的,在利用电力线、同轴电缆等介质进行网络通信过程中,很容易被恶意设备进行非法监听。为了防止恶意设备非法监听,利用这些介质进行通信的通信设备(以下简称为家庭网络通信设备)可通过配对组网的方法来实现一定的安全性,防止恶意设备非法监听保证通信的安全性。其中配对组网典型的实现方式是家庭网络通信设备通过安全准入(secure admission)方法加入域,该域可以理解为是家庭网络设备之间组建的私有网络。家庭网络设备在域内通过家庭网络介质进行通信,可防止恶意节点的加入,保证通信的安全。
目前,家庭网络设备进行安全准入的方法主要有以下两种方式:
方式一:用户需要先对位于域内的终端节点(end point node,EP Node)中的某一EP Node进行按键操作,接收到按键操作的EP Node向域主节点(domain master,DM)发送通知消息以通知按键事件,域主节点接收到EP Node发送的通知消息后开启配对窗口(pairing window)。用户在配对窗口的有效期内,对需要加入域的新家庭网络设备进行按键操作,新家庭网络设备接收到用户的按键操作后,可向域主节点发送注册请求,域主节点接收到注册请求后回复注册确认消息,实现新家庭网络设备的安全准入过程。
方式二:用户需要通过电视屏幕或计算机连接位于域内的EP Node,并通过屏幕显示EP Node的状态。用户通过在屏幕上对位于域内的EP Node进行操作以触发位于域内的EP Node向域主节点发送配对请求,域主节点接收到配对请求后开启配对窗口,并广播媒体接入计划(medium access plan,MAP)消息。在配对窗口有效性期内,需要加入域的新家庭网络设备接收到MAP消息后,向域主节点发送注册请求。域主节点向新家庭网络设备回复注册确认消息,并在配对窗口到期后关闭配对窗口,向位于域内的EP Node发送配对响应,该配对响应中包括发送注册请求的新家庭网络设备的媒体接入控制(media access control,MAC)地址或其他信息。位于域内的EP Node接收到配对响应后,可在屏幕上显 示新家庭网络设备的MAC地址或其他信息。用户在屏幕上基于MAC或其他信息选择通过新家庭网络设备的注册请求。位于域内的EP Node向域主节点发送配对请求。域主节点接收到配对请求后,广播发送MAP消息,并在其中携带用户已授权加入域的新家庭网络设备的MAC地址。新家庭网络设备接收到MAP消息后,检测到其中携带自己的MAC地址后,发起注册请求,实现新家庭网络设备的配对操作过程。
上述两种安全准入的实现方式中,有可能造成资源浪费,并有可能遭到恶意设备的非法加入,安全性较低。
发明内容
本申请实施例提供一种网络安全准入方法及家庭网络设备,以提高安全准入的安全性。
第一方面,提供一种网络安全准入的方法,在该方法中,域主节点向用户发出提示信息,该提示信息用于提示存在需要加入域进行配对的家庭网络设备。域主节点接收用户的授权操作,该授权操作用于指示允许家庭网络设备加入域进行配对操作,且是用户根据提示信息进行操作的。域主节点确定接收到用户的授权操作时,开启配对窗口,并在配对窗口的有效期内发送指示信息,该指示信息用于指示允许所述家庭网络设备加入域进行配对。
本申请实施例中,一方面用户通过提示信息进行授权操作,不需要用户使用电视、计算机等设备配合操作,使得家庭网络的配对组网面向用户更加友好,操作更加便捷;另一方面通过用户的授权操作触发域主节点开启配对窗口,使得在域主节点开启配对窗口之前授权新设备加入域,进而可避免出现开启配对窗口后无授权的新设备加入域的情形,避免资源浪费,提升安全准入(或配对组网)的安全性。并且,由于用户无需在配对窗口内进行授权操作,故相对现有技术,配对窗口的有效期可设置的相对短一些,进一步降低恶意设备非法加入的机会,提高安全准入的安全性。
一种可能的设计中,该网络安全准入方法可应用于家庭网络中的域主节点或域终端节点,也可应用于域主节点或域终端节点中的芯片。其中,域主节点用于管理家庭网络及家庭网络任意节点间的传输资源分配。
其中,家庭网络为通过家庭网络介质进行通信的网络,所述家庭网络介质包括电力线、双绞线、塑料光纤和同轴电缆中的至少一种。
域主节点管理作为域终端节点的家庭网络设备接入家庭网络。当域主节点接收到来自家庭网络设备发送的、用于通知存在需要接入家庭网络的家庭网络设备的通知消息时,执行如下步骤:向用户发出提示信息,所述提示信息用于提示存在需要接入所述家庭网络的家庭网络设备。接收用户的授权操作,所述授权操作用于指示允许所述家庭网络设备接入所述家庭网络,且是用户根据所述提示信息进行操作的。开启配对窗口,并在配对窗口的有效期内发送指示信息,所述指示信息用于指示允许所述家庭网络设备接入所述家庭网络。此种方式中,用户只需要根据域主节点发出的提示信息进行简单的授权操作,就可使家庭网络设备自动接入家庭网络,并进行数据传输,操作方便简洁。
其中,一种可能的实施方式中提示信息可在域主节点本地显示,例如可以是域主节点闪灯提示。用户的授权操作可以是用户对域主节点的操作,例如可以是对域主节点的按键操作。通过此种方式,用户可通过提示信息在域主节点上进行授权操作,无需对其它接入家庭网络的家庭网络设备和域主节点进行双边对接操作,操作过程面向用户友好易懂,操作简单方便,并能使家庭网络设备快速接入家庭网络。
另一种可能的实现方式中,代理节点作为用户界面的设备向用户显示提示信息,并直接接收用户的授权操作,例如域主节点通知代理节点向用户进行闪灯提示。用户的授权操作也可以是用户对代理节点进行按键操作,代理节点通知域主节点用户的按键授权操作。所述代理节点可以是任一域终端节点。
再一种可能的实施方式中,域主节点发送的提示信息由域主节点发送给用户使用的终端如手机,并在终端上显示。例如可以是域主节点发送给用户使用的终端并在所述终端上显示的推送消息。其中,用户使用的终端上安装有用于用户进行授权操作的应用程序。用户的授权操作可由用户对终端上安装的应用程序进行操作触发。通过此种方式,用户可通过提示信息在使用的终端上进行一键式授权操作,无需对其它接入家庭网络的家庭网络设备和域主节点进行双边对接操作,操作简单方便,并能使家庭网络设备快速接入家庭网络。
本申请实施例的另一种可能的设计中,域主节点可在接收到家庭网络设备发送的、用于通知存在需要加入域进行配对的家庭网络设备的通知消息时,依据所述通知消息,向用户发出所述提示信息所述通知消息。本申请实施例中由需要加入域进行配对的家庭网络设备发送通知消息,触发域主节点进行配对操作,无需其它接入家庭网络的家庭网络设备触发,处理流程相对较简单。
其中,所述通知消息中可包括发送通知消息的家庭网络设备的标识。域主节点发送的指示信息中也包括该发送通知消息的家庭网络设备的标识。本申请实施例中通过通知消息中包括发送通知消息的家庭网络设备的标识,并在域主节点发送的指示信息中也包括该发送通知消息的家庭网络设备的标识,可以使该标识对应的家庭网络设备接入家庭网络,防止其它家庭网络设备接入,提高安全性。
本申请实施例的又一种可能的设计中,域主节点接收用户的授权操作,并发送所述域主节点的域名配置信息,所述授权操作如前描述既可以是直接对域主节点的按键操作,也可以是对代理节点的按键操作,由代理节点通知域主节点用户的按键操作,还可以是通过智能终端的应用进行操作。域主节点接收家庭网络设备发送的域名配置确认消息,该域名配置确认消息用于指示家庭网络设备将所述域主节点的域名配置信息中包括的域名作为家庭网络设备的域名,通过此种方式可使家庭网络设备依据域主节点的域名配置信息进行域名配置,相对采用预先配置的方式,使家庭网络设备的域名配置灵活性更大。
第二方面,提供一种网络安全准入方法,在该方法中,家庭网络设备确定需要加入域进行配对,向域主节点发送通知消息,该通知消息用于向域主节点通知存在需要加入域进行配对的家庭网络设备。
其中,需要加入域进行配对的家庭网络设备可以理解为是作为域终端节点的家庭网络设备。家庭网络设备加入域进行配对也可以理解为是家庭网络设备被允许作为域终端节点接入家庭网络。
本申请实施例中由需要加入域进行配对的家庭网络设备发送通知消息,触发域主节点进行配对操作,无需其它已接入家庭网络的家庭网络设备触发,处理流程相对较简单。
其中,家庭网络设备检测到上电或者检测到存在新域时,可确定需要加入域进行配对。
进一步的,需要加入域进行配对的家庭网络设备发送的通知消息中包括发送通知消息的家庭网络设备的标识,可以使该标识对应的家庭网络设备接入家庭网络,防止其它家庭网络设备接入,提高安全性。
一种可能的设计中,家庭网络中作为域终端节点的家庭网络设备可接收域主节点发送的所述域主节点的域名配置信息,并将所述域主节点的域名配置信息中包括的域名作为所述家庭网络中作为域终端节点的家庭网络设备的域名,向所述域主节点发送域名配置确认消息。通过此种方式可使家庭网络中作为域终端节点的家庭网络设备依据域主节点的域名配置信息进行域名配置,相对采用预先配置的方式,使家庭网络设备的域名配置灵活性更大。
第三方面,提供一种网络安全准入装置,该网络安全准入装置具有实现第一方面或第一方面任意可能的设计中域主节点执行网络安全准入方法所涉及的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的单元。
一种可能的设计中,所述网络安全准入装置包括发送单元、接收单元和处理单元。其中,发送单元用于向用户发出提示信息。接收单元用于接收用户的授权操作。处理单元,用于确定接收到用户的授权操作时,开启配对窗口。所述发送单元用于在配对窗口的有效期内发送指示信息,所述指示信息用于指示允许所述家庭网络设备加入域进行配对。
本申请实施例中,通过用户的授权操作触发域主节点开启配对窗口,使得在域主节点开启配对窗口之前授权新设备加入域,进而可避免出现开启配对窗口后无授权的新设备加入域的情形,避免资源浪费,提升安全准入(或配对组网)的安全性。并且,由于用户无需在配对窗口内进行授权操作,故相对现有技术,配对窗口的有效期可设置的相对短一些,进一步降低恶意设备非法加入的机会,提高安全准入的安全性。
另一种可能的设计中,所述网络安全准入装置包括发送单元和接收单元。其中,接收单元用于接收用户的授权操作。发送单元用于发送域主节点的域名配置信息。接收单元用于接收家庭网络设备发送的域名配置确认消息,所述域名配置确认消息用于指示所述家庭网络设备将所述域主节点的域名配置信息中包括的域名作为所述家庭网络设备的域名。
该网络安全准入装置也可包括处理单元,该处理单元用于在接收单元接收家庭网络设备发送的域名配置确认消息之后开启配对窗口。所述发送单元还用于在配对窗口的有效期内发送指示信息,所述指示信息用于指示允许所述家庭网络设备加入域进行配对。
本申请实施例中,通过发送域主节点的域名配置信息,可使家庭网络设备依据域主节点的域名配置信息进行域名配置,相对采用预先配置的方式,使家庭网络设备的域名配置灵活性更大。
其中,发送单元向用户发出提示信息,接收单元接收的授权操作是根据发送单元向用户发出的提示信息进行操作的,所述提示信息用于提示存在需要加入域进行配对的家庭网络设备。
其中,发送单元发送的提示信息在域主节点本地显示或在代理节点显示,接收单元接收的授权操作为用户对域主节点或代理节点的操作。例如,在所述域主节点本地显示或在代理节点显示的提示信息为闪灯提示,用户对域主节点或代理节点的操作为按键操作。或者发送单元发送的提示信息由域主节点或代理节点发送给用户使用的终端并在所述终端 上显示,例如,可以是域主节点或代理节点发送给用户使用的终端并在所述终端上显示的推送消息。终端上安装有用于用户进行授权操作的应用程序,接收单元接收的授权操作由用户对所述应用程序进行操作触发。
通过此种方式,用户可通过提示信息在域主节点或使用的终端上进行一键式授权操作,无需对其它接入家庭网络的家庭网络设备和域主节点进行双边对接操作,操作简单方便,并能使家庭网络设备快速接入家庭网络。
一种可能的设计中,接收单元还用于接收家庭网络设备发送的通知消息,所述通知消息用于通知存在需要加入域进行配对的家庭网络设备。发送单元采用如下方式向域主节点向用户发出提示信息:依据所述通知消息,向用户发出所述提示信息。
其中,接收单元接收的通知消息中包括发送通知消息的家庭网络设备的标识。发送单元发送的指示信息中包括发送通知消息的家庭网络设备的标识。
本申请实施例中通过通知消息中包括发送通知消息的家庭网络设备的标识,并在指示信息中也包括该发送通知消息的家庭网络设备的标识,可以使该标识对应的家庭网络设备接入家庭网络,防止其它家庭网络设备接入,提高安全性。
本申请实施例第三方面提供的网络安全准入装置可以是域主节点,也可以是域主节点内的芯片。所述域主节点或所述芯片具有实现第一方面或第一方面任意可能的设计中执行网络安全准入方法所涉及的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的单元。
所述域主节点包括发送单元、接收单元和处理单元,所述发送单元可以是发射器,所述接收单元可以是接收器,所述接收器和发射器中可包括射频电路。所述处理单元例如可以是处理器。可选的,所述域主节点还可包括存储单元,所述存储单元例如可以是存储器。当所述域主节点包括存储单元时,所述存储单元用于存储计算机执行指令,所述处理单元与所述存储单元连接,所述处理单元执行所述存储单元存储的计算机执行指令,以使所述域主节点执行第一方面或第一方面任意可能的设计中的网络安全准入方法。
所述芯片包括:发送单元、接收单元和处理单元,所述发送单元和所述接收单元可以是所述芯片上的输入/输出接口、管脚或电路等。所述处理单元例如可以是处理器。可选的,所述芯片还包括存储单元,所述存储单元例如可以是存储器。所述处理单元可执行存储单元存储的计算机执行指令,以使所述芯片执行第一方面或第一方面任意可能的设计中的网络安全准入方法。
第四方面,提供一种网络安全准入装置,该网络安全准入装置具有实现第二方面或第二方面任意可能的设计中需要加入域进行配对的家庭网络设备执行网络安全准入方法所涉及的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的单元。
一种可能的设计中,网络安全准入装置包括处理单元和发送单元,其中,处理单元用于确定需要加入域进行配对。发送单元用于向域主节点发送通知消息,该通知消息用于向域主节点通知存在需要加入域进行配对的家庭网络设备。
其中,处理单元检测到上电或者检测到存在新域时,确定需要加入域进行配对。
可选的,需要加入域进行配对的家庭网络设备还可包括存储单元,所述存储单元例如可以是存储器。当所述域主节点包括存储单元时,所述存储单元用于存储计算机执行指令,所述处理单元与所述存储单元连接,所述处理单元执行所述存储单元存储的计算机执行指 令,以使所述需要加入域进行配对的家庭网络设备执行第二方面或第二方面任意可能的设计中的网络安全准入方法。
另一种可能的设计中,网络安全准入装置包括接收单元、处理单元和发送单元,其中,接收单元用于接收域主节点发送的所述域主节点的域名配置信息。处理单元用于将所述接收单元接收的域主节点的域名配置信息中包括的域名作为所述家庭网络设备的域名。发送单元用于向所述域主节点发送域名配置确认消息。
可选的,所述网络安全准入装置还可包括存储单元,所述存储单元例如可以是存储器。当所述网络安全准入装置包括存储单元时,所述存储单元用于存储计算机执行指令,所述处理单元与所述存储单元连接,所述处理单元执行所述存储单元存储的计算机执行指令,以使所述家庭网络设备执行第二方面或第二方面任意可能的设计中的网络安全准入方法。
本申请实施例第四方面提供的网络安全准入装置可以是需要加入域进行配对的家庭网络设备,也可以是需要加入域进行配对的家庭网络设备内的芯片。所述家庭网络设备或所述芯片具有实现第二方面或第二方面任意可能的设计中执行网络安全准入方法所涉及的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的单元。
第四方面提供的网络安全准入装置中涉及的所述发送单元可以是发射器,所述接收单元可以是接收器,所述接收器和发射器中可包括射频电路。所述处理单元例如可以是处理器。所述存储单元例如可以是存储器。
所述芯片包括:处理单元和发送单元,也可以包括接收单元。所述发送单元和所述接收单元可以是所述芯片上的输入/输出接口、管脚或电路等。所述处理单元例如可以是处理器。可选的,所述芯片还包括存储单元,所述存储单元例如可以是存储器。
可选的,第三方面和第四方面中涉及的芯片中包括的存储单元可以是所述芯片内的存储单元(例如,寄存器、缓存等),所述存储单元还可以是所述位于所述芯片外部的存储单元(例如,只读存储器)或可存储静态信息和指令的其他类型的静态存储设备(例如,随机存取存储器)等。
可选的,第三方面和第四方面涉及的处理器可以是一个中央处理器、微处理器或专用集成电路,也可以是一个或多个用于控制执行上述各方面或各方面设计中涉及的网络安全准入方法的程序执行的集成电路。
第五方面,本申请提实施例提供一种计算机可读存储介质,所述计算机可读存储介质存储有计算机指令,当所述指令在计算机上运行时,可以完成上述各方面或各方面中任意可能的设计中执行的网络安全准入方法。
第六方面,本申请提实施例提供一种计算机程序产品,所述计算机程序产品中包括有计算机程序,该计算机程序用于执行完成上述各方面或各方面中任意可能的设计中的网络安全准入方法。
本申请实施例提供的网络安全准入方法、装置、域主节点以及家庭网络设备,通过用户的授权操作触发域主节点开启配对窗口,使得在域主节点开启配对窗口之前授权新设备加入域,进而可避免出现开启配对窗口后无授权的新设备加入域的情形,避免资源浪费,提升安全准入的安全性。并且,由于用户只需要根据域主节点发出的提示信息进行简单的授权操作,就可使家庭网络设备自动接入家庭网络,并进行数据传输,操作方便简洁。
附图说明
图1为本申请实施例涉及的域网络架构;
图2为本申请实施例涉及的一种家庭网络设备安全准入的过程示意图;
图3为本申请实施例涉及的一种家庭电力线网络架构示意图;
图4A为本申请实施例涉及的一种家庭网络设备安全准入的方法流程图;
图4B为本申请实施例涉及的另一种家庭网络设备安全准入的方法流程图;
图5A为本申请实施例涉及的又一种家庭网络设备安全准入的方法流程图;
图5B为本申请实施例涉及的又一种家庭网络设备安全准入的方法流程图;
图6A为本申请实施例涉及的又一种家庭网络设备安全准入的方法流程图;
图6B为本申请实施例涉及的又一种家庭网络设备安全准入的方法流程图;
图7为本申请实施例提供的一种网络安全准入装置结构示意图;
图8为本申请实施例提供的一种家庭网络设备结构示意图;
图9为本申请实施例提供的另一种网络安全准入装置结构示意图;
图10为本申请实施例提供的另一种家庭网络设备结构示意图;
图11为本申请实施例提供的又一种网络安全准入装置结构示意图;
图12为本申请实施例提供的又一种家庭网络设备结构示意图;
图13为本申请实施例提供的又一种网络安全准入装置结构示意图;
图14为本申请实施例提供的又一种家庭网络设备结构示意图。
具体实施方式
下面将结合附图,对本申请实施例的技术方案进行描述。
首先,对本申请实施例涉及的部分用语进行解释说明,以便于理解。
1)家庭网络设备,可以理解为是通过家庭网络介质进行通信的设备。家庭网络设备也可称为是通信节点,或者终端节点。其中,家庭网络介质例如可以是同轴电缆、双绞线、电力线以及塑料光纤等。目前,一些家庭网络设备的举例为:集成家庭网络芯片的终端如数字用户线路猫(digital subscriber line,DSL modem)、光网络终端(optical network terminal,ONT),家用路由器等,此类终端设备可以向上连接互联网,向下通过家庭网络连接用户终端;无线(wireless)或有线(wireline)接入点(access point,AP),以及可能用于工业应用场景的电力线通信设备,包括智能电表等,及各种物联网(internet of things,IoT)设备等通过上述家庭网络介质向上接入家庭网络,向下连接各类终端或者自身即是终端设备。
2)域,英文表示可以是domain。域可以理解为是包括有多个家庭网络设备的通信网络,一个域内可包括通过家庭网络介质进行通信的多个家庭网络设备。例如图1中,域主节点、域终端节点1~域终端节点4组建一个域。
域内通信可以加密或者不加密,对应的域可包括安全域和非安全域。在安全域内各家庭网络设备之间采用加密方式进行通信。在非安全域内各家庭网络设备之间进行通信时不加密。
3)域主节点,英文表示可以是domain master,简称DM。域主节点可以理解为是域内具有管理控制功能的家庭网络节点。域主节点可以通过与位于域外的家庭网络设备进行交互,以将位于域外的家庭网络设备加入域内。
4)域终端节点,英文表示可以是end point node,简称为EP Node。EP Node可以理解 为是域内除域主节点以外的其它家庭网络节点。
本申请实施例中,家庭网络设备可以在域主节点和域终端节点之间进行角色切换。
5)安全准入,英文表示可以是Secure admission。安全准入可以理解为是家庭网络设备加入域进行配对组网的过程。其中,配对组网可以理解为是家庭网络设备间组建私有网络的过程。
6)配对窗口,是指允许家庭网络设备进行配对组网(安全准入)的时间窗。
目前,家庭网络设备之间通过安全准入(Secure admission)的方式,保障各家庭网络设备之间通信的安全性。例如,图2中,域主节点、域终端节点1~域终端节点4组建一个域。域主节点、域终端节点1~域终端节点4在域内可通过家庭网络介质进行安全通信。位于域外的家庭网络设备5和家庭网络设备6,若需要进行安全通信,需要执行安全准入的过程加入域内。现有家庭网络设备安全准入的方法中,均需要用户对已配对家庭网络设备进行操作,才能触发域主节点开启配对窗口,并且都需要在域主节点开启配对窗口后,用户才能决定是否授权新家庭网络设备加入域,在配对窗口开启后,若用户不能在配对窗口预设的时长内授权新节点加入域,则可能造成资源的浪费,并且有可能遭到恶意设备的非法加入,安全性较低。
有鉴于此,本申请实施例提供一种安全准入的方法,该安全准入方法可应用于通过家庭网络介质进行通信的家庭网络中,当然也可应用于除家庭网络领域之外同样关注安全问题的领域,例如也可能用于企业通信、工业互通互连、物联网等领域。在这些领域的应用中,作为域主节点的家庭网络设备确定存在需要加入域进行配对的家庭网络设备时,向用户发出提示信息。用户根据域主节点发出的提示信息进行授权操作,域主节点接收用户的授权操作,并在确定接收到用户的授权操作时开启配对窗口,在配对窗口的有效期内发送用于指示允许设备加入域进行配对的指示信息。需要加入域进行配对的家庭网络设备(或也可以理解为是作为域终端节点的家庭网络设备)接收到域主节点发送的指示信息后可发起注册请求,以完成安全准入的过程。通过本申请实施例,一方面用户通过提示信息进行授权操作,不需要用户使用电视、计算机等设备配合操作,使得家庭网络的配对组网面向用户更加友好,操作更加便捷。另一方面通过用户的授权操作触发域主节点开启配对窗口,使得在域主节点开启配对窗口之前授权新设备加入域,进而可避免出现开启配对窗口后无授权的新设备加入域的情形,避免资源浪费,提升安全准入(或配对组网)的安全性。并且,由于用户无需在配对窗口内进行授权操作,故相对现有技术,配对窗口的有效期可设置的相对短一些,进一步降低恶意设备非法加入的机会,提高安全准入的安全性。
本申请实施例中,可以通过域主节点直接向用户发出提示信息,也可由代理节点向用户发出提示信息。该代理节点可以是任一域终端节点。一种可能的实现方式中,代理节点作为用户界面的设备向用户显示提示信息,例如域主节点通知代理节点向用户进行闪灯提示。用户的授权操作可以是用户直接对域主节点进行按键操作,也可以是用户对代理节点进行按键操作,代理节点通知域主节点用户的按键授权操作。或者域主节点可直接向用户使用的终端发送推送消息或通知代理节点向用户使用的终端发送推送消息,用户的授权操作也可以是用户对使用的终端上安装的应用程序进行的一键式授权操作。
本申请实施例提供的安全准入方法可应用于家庭电力线网络。电力线网络,又可称为电力线通信(power line communication,PLC),指利用既有电力线,将数据或信息以数字信号处理方法进行传输。电力线的覆盖广泛且天然覆盖居民的家庭与楼道,故家庭电力线 网络在家庭网络技术的应用中占据一定优势。
图3所示为本申请实施例提供的一种家庭电力线网络的架构示意图。在一个典型的实施方案中如图3,域主节点作为家庭电力线网络的接入设备可位于ONT或DSL Modem等终端设备上,通过诸如光纤或铜线等与运营商网络相连并进行上行数据传输。此种情况下域主节点可以通过电力线或同轴电缆等介质与家庭网络设备1(域终端节点1)~家庭网络设备5(域终端节点5)相连,例如图3中可通过电力线无线保真(wireless fidelity,Wi-Fi)接入点(access point,AP)、有线AP及智能家居电器等家庭网络设备相连,进行下行数据传输,并管理家庭电力线网络。这样域主节点设备可在运营商网络和家庭电力线网络间实现跨网络的数据传输。电力猫、路由器等家庭网络设备可通过电力线与域主节点连接并进行上行数据传输。电力猫、路由器等家庭网络设备可作为域终端节点接入家庭电力线网络,通过诸如网线或无线保真(wireless fidelity,WI-FI)等连接方式与用户使用的手机、电脑、电视机等终端相连接并进行下行数据传输,作为域终端节点接入家庭电力线网络的家庭网络设备也可以理解为是作为下级网络分发节点的家庭网络设备。其中,在家庭电力线网络中应用本申请实施例提供的安全准入方法时,作为域终端节点接入家庭电力线网络的家庭网络设备在确定需要接入家庭电力线网络时,可向作为域主节点的家庭网络设备发送用于通知存在作为域终端节点接入所述家庭电力线网络的家庭网络设备的通知消息。作为域主节点的家庭网络设备节点接收到来自作为域终端节点的家庭网络设备发送的通知消息时,可向用户发出提示信息,该提示信息用于提示存在作为域终端节点接入所述家庭电力线网络的家庭网络设备。用户接收到该提示信息后,若允许家庭网络设备加入家庭电力线网络,则可进行授权操作。域主节点接收到该授权操作后,可开启配对窗口,并在配对窗口的有效期内发送指示信息,以指示允许所述家庭网络设备接入家庭电力线网络。相对应的,域主节点作为家庭网络的管理节点,同样也可以位于其他终端设备上,如Wi-Fi AP设备上,此种情况下ONT或DSL modem等可作为域终端节点向下接入家庭网络,通过电力线或同轴电缆等介质与其它家庭网络设备相连,向上通过光纤或铜线等与运营商网络相连。再者ONT或DSL modem等设备并不集成家庭网络芯片功能,而是通过分离的家庭网络设备与其直接相连,此家庭网络设备再通过电力线或同轴电缆等介质与其他家庭网络设备相连,此种情况下域主节点可以位于任一家庭网络设备上执行管理和资源分配等功能。需要说明的是签署安全准入的方法均适用于这些场景下的应用,保障家庭网络上接入和通信安全。
本申请实施例通过上述方式将家庭网络设备接入家庭电力线网络,用户只需要根据域主节点发出的提示信息进行简单的授权操作,就可使家庭网络设备自动接入家庭电力线网络,并进行数据传输,操作方便简洁。
本申请实施例以下以安全准入方法应用于家庭电力线网络为例进行说明。
可以理解的是,在家庭电力线网络中,本申请实施例中涉及的家庭网络设备也可以称为电力线通信设备。若安全准入方法应用到除家庭网络以外的其它网络时,相应的名称可以做对应的更改。
进一步可以理解的是,本申请实施例中涉及的“加入域进行配对”以及“接入家庭电力线网络”有时可以混用,应当指出的是,在不强调其区别时,其所要表达的含义是一致的。
进一步的,本申请实施例以下涉及的家庭网络设备是指位于域外的家庭网络设备,或者也可以理解为是需要加入域进行配对的家庭网络设备,或者还可以理解为是作为域终端节点或下级网络分发节点接入家庭网络的家庭网络设备。
图4A所示为本申请实施例提供的一种家庭网络设备安全准入的方法实施流程图,参阅图4A所示,该方法包括:
S101a:域主节点向用户发出提示信息,该提示信息用于提示存在需要加入域进行配对的家庭网络设备。
一种可能的示例中,本申请实施例中域主节点向用户发出的提示信息可以是在域主节点本地显示的提示信息,例如该提示信息可以是域主节点闪灯提示。域主节点通过闪灯提示用户存在需要加入域进行配对的家庭网络设备。
另一种可能的示例中,本申请实施例中域主节点向用户发出的提示信息可以是推送消息,域主节点向用户使用的终端发送推送消息。终端接收到域主节点发送的推送消息可以在终端上进行显示,以提示用户存在需要加入域进行配对的家庭网络设备,所述推送消息可以通过智能手机的应用程序(APP)来实现。
S102a:用户根据主节点向用户发出的提示信息进行授权操作,该授权操作用于指示允许家庭网络设备加入域进行配对操作。域主节点接收用户的授权操作。
具体的,本申请实施例中用户进行的授权操作可以依据不同的提示信息,采用不同的实现形式。例如,若提示信息为在域主节点本地显示的提示信息,所述授权操作可以为用户对主节点的操作。用户对主节点的操作例如可以是按键操作,当然也可以是其它的方式。通过此种方式,用户可通过提示信息在域主节点上进行授权操作,无需对其它接入家庭电力线网络的家庭网络设备和域主节点进行双边对接操作,操作简单方便易理解,并能使家庭网络设备快速接入家庭电力线网络。
再例如,若提示信息为域主节点发送给终端并在终端上显示的推送消息,用户使用的终端上安装有用户进行授权操作的应用程序(APP),则用户的授权操作可以由用户对终端上安装的APP进行操作触发,例如可以是在APP上进行的一键式授权操作,当然也可以是其它的操作方式。通过此种方式,用户可通过提示信息在使用的终端上进行一键式授权操作,无需对其它接入家庭电力线网络的家庭网络设备和域主节点进行双边对接操作,操作简单方便,并能使家庭网络设备快速接入家庭电力线网络。
S103a:域主节点确定接收到用户的授权操作时,开启配对窗口。
S104a:域主节点在配对窗口的有效期内发送指示信息,该指示信息用于指示允许家庭网络设备加入域进行配对。
本申请实施例中域主节点发送的指示信息可以是MAP消息。
S105a:家庭网络设备接收域主节点发送的指示信息,并向域主节点发送注册请求。
S106a:域主节点接收家庭网络设备发送的注册请求,并向家庭网络设备回复注册确认消息,实现家庭网络设备的安全准入过程。
具体的,本申请实施例中域主节点向家庭网络设备回复的注册确认消息中可以携带秘钥消息,以实现家庭网络设备与域主节点之间在安全域内的通信。
本申请实施例中域主节点向用户发出提示信息可以包括上述涉及的由域主节点直接向用户发出提示信息的实施方式,也可包括通过代理节点间接向用户发出提示信息的实施方式。图4B所示为本申请实施例涉及的通过代理节点间接向用户发出提示信息的实施流 程图,参阅图4B所示,该方法包括:
S101b:域主节点向代理节点发送第一通知消息,该第一通知消息用于通知代理节点进行提示操作。
S102b:代理节点接收域主节点发送的第一通知消息,并向用户发出提示信息。
本申请实施例中代理节点向用户发出提示信息的实施过程与域主节点向用户发出提示信息的实施过程类似,可以在本地显示,也可以向用户使用的终端发送并在用户使用的终端上显示,具体的实施过程可参阅上述实施例中有关域主节点向用户发出提示信息的实施过程,在此不再详述。
S103b:代理节点接收用户的授权操作。
用户获取到代理节点发出的提示信息后,用户根提示信息进行授权操作,具体的授权操作可以是用户对代理节点进行的按键操作。或者用户的授权操作也可以是用户对使用的终端上安装的应用程序进行的一键式授权操作。对于授权操作的相关描述,可参阅上述实施例中有关根据域主节点发出的提示信息进行授权操作的实施过程,在此不再详述。
S104b:代理节点向域主节点发送第二通知消息,该第二通知消息用于通知域主节点已接收到用户的授权操作。
本申请实施例中,代理节点接收到用户的授权操作后,可向域主节点发送第二通知消息,以通知域主节点的用户已进行授权操作,例如代理节点通知域主节点用户的按键授权操作或用户对使用的终端上安装的应用程序进行的一键式授权操作。
S105b、S106b、S107b和S108b的执行过程与上述实施例中涉及对的S103a、S104a、S105a和S106a的执行过程类似,本申请实施例在此不再详述。
本申请实施例提供的家庭网络设备安全准入方法,用户根据域主节点的提示信息进行对需要加入域进行配对的家庭网络设备进行授权操作,域主节点在接收到用户的授权操作后开启配对窗口,使得在域主节点开启配对窗口之前授权家庭网络设备加入域,进而可避免出现开启配对窗口后无授权的家庭网络设备加入域的情形,避免资源浪费。并且,由于用户无需在配对窗口内进行授权操作,故相对现有技术,配对窗口的有效期可设置的相对短一些,进而可一定程度上降低恶意设备非法加入的机会,提高安全准入的安全性。
本申请实施例中一种可能的实施方式中,当存在需要加入域进行配对的家庭网络设备时,该需要加入域进行配对的家庭网络设备可向域主节点发送通知消息,以通知存在需要配对的家庭网络设备。域主节点接收到家庭网络设备发送的通知消息后,确定提示信息,以提示用户存在需要加入域进行配对的家庭网络设备。
图5A所示为本申请实施例提供的一种家庭网络设备安全准入的方法实施流程图,参阅图5A所示,该方法包括:
S201a:家庭网络设备向域主节点发送第三通知消息,该第三通知消息用于通知存在需要加入域进行配对的家庭网络设备。
具体的,本申请实施例中家庭网络设备可在被允许作为域终端节点接入家庭网络时向作为域主节点的家庭网络设备发送通知消息。例如,家庭网络设备可在上电后向域主节点发送第三通知消息,或者家庭网络设备也可以在检测到网络中存在新建的域时,向域主节点发送第三通知消息。可能的示例中,本申请实施例中家庭网络设备向域主节点发送的第三通知消息也可以称为节点存在信息(ADM_NodePresense.ind),对于第三通知消息的具体形式本申请实施例不作限定。
一种可能的示例中,家庭网络设备向域主节点发送的第三通知消息中可包括家庭网络设备的标识,以使域主节点通过该标识确定需要加入域进行配对的家庭网络设备。
S202a:域主节点接收家庭网络设备发送的第三通知消息,确定存在需要加入域进行配对的家庭网络设备(存在被允许作为域终端节点接入家庭网络的家庭网络设备),并在本地显示提示信息或者向用户使用的终端发送提示信息,以提示用户存在需要加入域进行配对的家庭网络设备。
可能的示例中,若域主节点采用向用户使用的终端发送提示信息的方式提示用户存在需要加入域进行配对的家庭网络设备,则该提示信息中还可包括家庭网络设备的标识,以使用户可通过该标识确定需要加入域进行配对的家庭网络设备,以确定是否对该标识对应的家庭网络设备进行授权。
又一种可能的示例中,域主节点接收到家庭网络设备发送的第三通知消息后,可确定该需要加入域进行配对的家庭网络设备是否属于自家的家庭网络,在确定属于自己的家庭网络的前提下,向用户发出提示信息。例如可检测发送第三通知消息的家庭网络设备的信号强度(当然也可以是其它信息),根据信号强度判断发送第三通知消息的家庭网络设备是否属于自家的家庭网络。例如,若信号强度小于设定的阈值,则可确定该发送第三通知消息的家庭网络设备不属于自家的家庭网络,可能属于邻居家的家庭网络,此种情况下,可不向用户发出提示信息,以智能的排除误报错报的情况发生。
S203a、S204a、S205a、S206a以及S207a的执行过程与S102a、S103a、S104a、S105a以及S106a的执行过程类似,本申请实施例在此不再详述。
需要着重说明的是,本申请实施例中域主节点向家庭网络设备发送的指示信息中可包括家庭网络设备的标识,以实现针对该标识对应的家庭网络设备的安全准入。
本申请实施例提供的家庭网络设备安全准入的实现方法,通过需要加入域进行配对的家庭网络设备向域主节点发送第三通知消息,以通知域主节点存在需要加入域进行配对的家庭网络设备,无需用户对位于域内的家庭网络设备进行操作,使得安全准入的执行过程能够得到简化,提高安全准入的效率。
一种可能的实施方式中,域主节点接收到第三通知消息后,可向代理节点发送第一通知消息,通过第一通知消息通知代理节点进行提示操作。代理节点接收到第一通知消息后向用户发出提示信息,并接收用户根据代理节点发出的提示信息进行的授权操作。代理节点向域主节点发送第二通知消息,以通知域主节点用户已发出授权操作。域主节点接收到代理节点发出的第二通知消息后,可开启配对窗口,并进行安全准入的执行过程。具体实施过程可参阅图5B所示。图5B中S201b的执行过程与图5A中S201a的执行过程类似,S202b、S203b、S204b、S205b、S206b、S207b、S208b和S209b的执行过程与图4B中S101b、S102b、S103b、S104b、S105b、S106b、S107b和S108b的执行过程相同,在此不再赘述。
家庭网络设备执行安全准入过程中需要进行域名配置,但是通常采用预先配置的方式类配置域名,此种方式灵活性较差。有鉴于此,本申请实施例中提供一种家庭网络设备安全准入过程中的域名配置方法,在该域名配置方法中,域主节点可在接收到用户的授权操作后发送该域主节点的域名配置信息,家庭网络设备可接收到域主节点发送的域名配置信息,将域主节点的域名配置信息中包括的域名作为所述家庭网络设备的域名,并向域主 节点发送域名配置确认消息,通过该域名配置确认消息指示家庭网络设备将域主节点的域名配置信息中包括的域名作为所述家庭网络设备的域名。通过此种方式可使家庭网络设备依据域主节点的域名配置信息进行域名配置,相对采用预先配置的方式,使家庭网络设备的域名配置灵活性更大。
一种可能的实施方式中,本申请实施例中需要加入域进行配对的家庭网络设备也可向域主节点发送通知消息,通过该通知消息提示存在需要加入域进行配对的家庭网络设备。域主节点接收用户的授权操作之前,接收家庭网络设备发送的通知消息,然后依据该通知消息确定提示消息。具体的,该通知消息中可包括家庭网络设备的标识。
本申请实施例中用于域名配置实现过程中涉及的提示信息与上述实施例涉及的通知消息类似,故对于通知消息的相关解释可参阅上述实施例的描述,在此不再详述。
用户的授权操作可以是根据域主节点向用户发出的提示信息进行操作的,该提示信息用于提示存在需要加入域进行配对的家庭网络设备。本申请实施例中用于域名配置实现过程中涉及的提示信息与上述实施例涉及的提示信息类似,故对于提示信息的相关解释可参阅上述实施例的描述,在此不再详述。
本申请实施例中,域主节点完成家庭网络设备的域名配置后,可开启配对窗口,并在配对窗口的有效期内发送指示信息,所述指示信息用于指示允许所述家庭网络设备加入域进行配对。
图6A所示为本申请实施例提供的又一种家庭网络设备安全准入的方法实施流程图。
图6A所示的方法中,S301a、S302a、S303a的执行过程与S201a、S202a、S203a的执行过程相同,在此不再详述。
S304a:域主节点接收用户的授权操作,并向家庭网络设备发送域主节点的域名配置信息。该域名配置信息中包括有域主节点所在域的域名。
S305a:家庭网络设备接收域主节点发送的域名配置信息,将该域名配置信息中包括的域名作为家庭网络设备的域名,并向域主节点发送域名配置确认消息。该域名配置确认消息用于指示所述家庭网络设备将所述域主节点的域名配置信息中包括的域名作为家庭网络设备的域名。
本申请实施例中家庭网络设备将域名配置信息中包括的域名作为家庭网络设备的域名,可以是直接将域名配置信息中包括的域名作为家庭网络设备的域名,或者也可将域名配置信息中包括的域名加入已配置的域名列表中,后续在域名列表中选择该域名配置信息中包括的域名作为家庭网络设备的域名。
S306a:家庭网络设备接收家庭网络设备发送的域名配置确认消息,并开启配对窗口。
S307a、S308a以及S309a的执行过程与S104a、S105a以及S106a的执行过程类似,本申请实施例在此不再详述。
一种可能的实施方式中,域主节点接收到第三通知消息后,可向代理节点发送第一通知消息,通过第一通知消息通知代理节点进行提示操作。代理节点接收到第一通知消息后向用户发出提示信息,并接收用户根据代理节点发出的提示信息进行的授权操作。代理节点向域主节点发送第二通知消息,以通知域主节点用户已发出授权操作。域主节点接收到代理节点发出的第二通知消息后,可向需要加入域进行配对的家庭网络设备发送域名配置信息,并进行安全准入的执行过程。具体实施过程可参阅图6B 所示。图6B中S301b、S302b、S303b、S304b和S305b的执行过程与S201b、S202b、S203b、S204b和S205b的执行过程相同,S306b、S307b、S308b、S309b、S310b和S311b的执行过程与S304a、S305a、S306a、S307a、S308a和S309a的执行过程相同,在此不再赘述。
需要说明的是,本申请实施例的说明书和权利要求书及附图中涉及的术语“第一”、“第二”“第三”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序,例如本申请实施例中上述涉及的第一通知消息、第二通知消息和第三通知消息仅是用于方便描述以及区分不同的通知消息,不构成对通知消息的限定。应该理解这样使用的数据在适当情况下可以互换,以便这里描述的本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施。
上述主要从域主节点和家庭网络设备交互的角度对本申请实施例提供的方案进行了介绍。可以理解的是,域主节点和家庭网络设备为了实现上述功能,其包含了执行各个功能相应的硬件结构和/或软件模块。结合本申请中所公开的实施例描述的各示例的单元(器、器件)及算法步骤,本申请实施例能够以硬件或硬件和计算机软件的结合形式来实现。某个功能究竟以硬件还是计算机软件驱动硬件的方式来执行,取决于技术方案的特定应用和设计约束条件。本领域技术人员可以对每个特定的应用来使用不同的方法来实现所描述的功能,但是这种实现不应认为超出本申请实施例的技术方案的范围。
本申请实施例可以根据上述方法示例对域主节点和家庭网络设备进行功能单元(器、器件)的划分,例如,可以对应各个功能划分各个功能单元(器、器件),也可以将两个或两个以上的功能集成在一个处理单元(器、器件)中。上述集成的单元(器、器件)既可以采用硬件的形式实现,也可以采用软件功能单元(器、器件)的形式实现。需要说明的是,本申请实施例中对单元(器、器件)的划分是示意性的,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式。
在采用集成的单元(器、器件)的情况下,图7示出了本申请实施例提供的一种网络安全准入装置100的结构示意图。其中,网络安全准入装置100可以是域主节点,也可以是域主节点内的部件。参阅图7所示,网络安全准入装置100包括发送单元101、接收单元102和处理单元103。
其中,发送单元101用于向用户发出提示信息,该提示信息用于提示存在需要加入域进行配对的家庭网络设备。接收单元102用于接收用户的授权操作,该授权操作是用户根据发送单元101发出的提示信息进行操作的,并用于指示允许家庭网络设备加入域进行配对操作。处理单元103用于在确定接收单元102接收到用户的授权操作时开启配对窗口,并在配对窗口的有效期内发送指示信息,该指示信息用于指示允许家庭网络设备加入域进行配对。
其中,一种可能的示例中,发送单元101发出的提示信息可以是在域主节点本地显示的提示信息或者也可以是在代理节点处显示的提示信息,接收单元102接收的授权操作可以是用户对域主节点或代理节点的操作。例如,在域主节点本地显示的提示信息或在代理节点处显示的提示信息为闪灯提示,用户对主节点的操作可以为按键操作,该按键操作可以理解为是一键式授权操作。
本申请实施例中,一方面用户通过提示信息进行一键式授权操作,不需要用户使用电视、计算机等设备配合操作,使得家庭网络的配对组网面向用户更加友好,操作更加便捷。 另一方面通过用户的授权操作触发域主节点开启配对窗口,使得在域主节点开启配对窗口之前授权新设备加入域,进而可避免出现开启配对窗口后无授权的新设备加入域的情形,避免资源浪费,提升安全准入(或配对组网)的安全性。并且,由于用户无需在配对窗口内进行授权操作,故相对现有技术,配对窗口的有效期可设置的相对短一些,进一步降低恶意设备非法加入的机会,提高安全准入的安全性。
另一种可能的示例中,发送单元101发出的提示信息可以是由域主节点或代理节点发送给用户使用的终端并在所述终端上显示的提示信息,用户使用的终端上安装有用于用户进行授权操作的应用程序,接收单元接收的授权操作可以由用户对终端上安装的应用程序进行操作触发。例如,域主节点发送给用户使用的终端并在所述终端上显示的提示信息可以是域主节点发送给用户使用的终端并在所述终端上显示的推送消息。用户对终端上安装的应用程序进行的操作可以是一键式授权操作。
一种可能的设计中,接收单元102还用于接收家庭网络设备发送的通知消息,该通知消息用于通知存在需要加入域进行配对的家庭网络设备。发送单元101用于依据接收单元102接收到的通知消息,向用户发出所述提示信息。其中,接收单元102接收的通知消息中包括发送通知消息的家庭网络设备的标识。发送单元101发送的指示信息中也包括发送通知消息的家庭网络设备的标识。
本申请实施例中通过通知消息中包括发送通知消息的家庭网络设备的标识,并在指示信息中也包括该发送通知消息的家庭网络设备的标识,可以使该标识对应的家庭网络设备接入家庭网络,防止其它家庭网络设备接入,提高安全性。
进一步的,上述涉及的网络安全准入装置100还可以包括存储单元104。存储单元104用于存储计算机执行指令,处理单元103与存储单元104连接,处理单元103执行存储单元104存储的计算机执行指令,以使网络安全准入装置100执行上述方法实施例中域主节点所执行的网络安全准入方法。
当采用硬件形式实现时,本申请实施例中,发送单元101和接收单元102可以是通信接口、收发器、收发电路等。其中,通信接口是统称,可以包括一个或多个接口。收发电路可以是射频电路。处理单元103可以是处理器或控制器。存储单元104可以是存储器。
当发送单元101和接收单元102是收发器,处理单元103是处理器时,本申请实施例所涉及的网络安全准入装置100可以为图8所示网络安全准入装置,图8所示的网络安全准入装置可以应用于家庭网络设备,该家庭网络设备可以是域主节点。
图8示出了本申请实施例提供的家庭网络设备1000的结构示意图,即示出了网络安全准入装置100另一种可能的结构示意图。参阅图8所示,家庭网络设备1000包括处理器1001、和收发器1002。其中,处理器1001也可以为控制器。所述处理器1001被配置为支持家庭网络设备1000执行图4至图5中涉及的域主节点的功能。收发器1002被配置为支持家庭网络设备1000进行消息的收发功能。所述家庭网络设备1000还可以包括存储器1003,所述存储器1003用于与处理器1001耦合,其保存家庭网络设备1000必要的程序指令和数据。其中,处理器1001、收发器1002和存储器1003相连,该存储器1003用于存储指令,该处理器1001用于执行该存储器1003存储的指令,以控制收发器1002收发信号,完成上述方法中域主节点执行相应功能的步骤。
本申请实施例中,网络安全准入装置100和家庭网络设备1000所涉及的与本申请实施例提供的技术方案相关的概念,解释和详细说明及其他步骤请参见前述方法或其他实施 例中关于这些内容的描述,此处不做赘述。
当采用芯片形式实现时,本申请实施例中涉及的网络安全准入装置100可以应用于家庭网络设备内的芯片,所述芯片具有实现上述方法实施例中域主节点执行网络安全准入方法所涉及的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的单元。所述芯片包括:发送单元101、接收单元102和处理单元103。其中,发送单元101、接收单元102可以是所述芯片上的输入/输出接口、管脚或电路等。处理单元103例如可以是处理器。所述芯片还可包括存储单元104。存储单元104例如可以是存储器。所述处理单元103可执行存储单元104存储的计算机执行指令,以使所述芯片执行上述方法实施例中域主节点执行的网络安全准入方法。可选地,所述存储单元104可以是所述芯片内的存储单元(例如,寄存器、缓存等),所述存储单元104还可以是所述域主节点内的位于所述芯片外部的存储单元(例如,只读存储器(read-only memory,ROM))或可存储静态信息和指令的其他类型的静态存储设备(例如,随机存取存储器(random access memory,RAM))等。
在采用集成的单元(器、器件)的情况下,图9示出了本申请实施例提供的另一种网络安全准入装置的结构示意图。其中,网络安全准入装置200可以是域主节点,也可以是域主节点内的部件。参阅图9所示,网络安全准入装置200包括接收单元201和发送单元202。其中,接收单元201用于接收用户的授权操作,该授权操作用于指示允许家庭网络设备加入域进行配对操作。发送单元202用于发送域主节点的域名配置信息。接收单元201用于接收家庭网络设备发送的域名配置确认消息,该域名配置确认消息用于指示家庭网络设备将域主节点的域名配置确认消息中包括的域名作为家庭网络设备的域名。
其中,用户的授权操作是根据发送单元202向用户发出的提示信息进行操作的,该提示信息用于提示存在需要加入域进行配对的家庭网络设备。
其中,提示信息在域主节点本地显示或在代理节点处显示,授权操作为用户对域主节点或代理节点的按键操作。例如,在所述域主节点本地显示的提示信息或在代理节点处显示的提示信息为闪灯提示,用户对域主节点或代理节点的操作为按键操作。或者提示信息由所发送单元202发送给用户使用的终端并在所述终端上显示,所述终端上安装有用于用户进行授权操作的应用程序,所述授权操作由用户对所述应用程序进行操作触发。
一种可能的实施方式中,接收单元201还用于接收家庭网络设备发送的通知消息,该通知消息用于通知存在需要配对的家庭网络设备。发送单元202用于根据接收单元201接收的通知消息向用户发出提示信息。其中,家庭网络设备发送的通知消息中包括家庭网络设备的标识。
网络安全准入装置200还可包括处理单元203,其中,处理单元203用于在接收单元201接收家庭网络设备发送的域名配置确认消息之后开启配对窗口。所述发送单元202还用于在配对窗口的有效期内发送指示信息,所述指示信息用于指示允许所述家庭网络设备加入域进行配对。
进一步的,上述涉及的网络安全准入装置200还可以包括存储单元204。存储单元204用于存储计算机执行指令,处理单元203与存储单元204连接,处理单元203执行存储单元204存储的计算机执行指令,以使网络安全准入装置200执行上述方法实施例中域主节点所执行的网络安全准入方法。
当采用硬件形式实现时,本申请实施例中,接收单元201和发送单元202可以是通信 接口、收发器、收发电路等。其中,通信接口是统称,可以包括一个或多个接口。收发电路可以是射频电路。处理单元203可以是处理器或控制器。存储单元204可以是存储器。
当接收单元201和发送单元202是收发器,处理单元203是处理器时,本申请实施例所涉及的网络安全准入装置200可以为图10所示网络安全准入装置,图10所示的网络安全准入装置可以应用于家庭网络设备,该家庭网络设备可以是域主节点。
图10示出了本申请实施例提供的家庭网络设备2000的结构示意图,即示出了网络安全准入装置200另一种可能的结构示意图。参阅图10所示,家庭网络设备2000包括处理器2001、和收发器2002。其中,处理器2001也可以为控制器。所述处理器2001被配置为支持家庭网络设备2000执行图6中涉及的域主节点的功能。收发器2002被配置为支持家庭网络设备2000进行消息的收发功能。所述家庭网络设备2000还可以包括存储器2003,所述存储器2003用于与处理器2001耦合,其保存家庭网络设备2000必要的程序指令和数据。其中,处理器2001、收发器2002和存储器2003相连,该存储器2003用于存储指令,该处理器2001用于执行该存储器2003存储的指令,以控制收发器2002收发信号,完成上述方法中域主节点执行相应功能的步骤。
本申请实施例中,网络安全准入装置200和家庭网络设备2000所涉及的与本申请实施例提供的技术方案相关的概念,解释和详细说明及其他步骤请参见前述方法或其他实施例中关于这些内容的描述,此处不做赘述。
当采用芯片形式实现时,本申请实施例中涉及的网络安全准入装置200可以应用于家庭网络设备内的芯片,所述芯片具有实现上述方法实施例中域主节点执行网络安全准入方法所涉及的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的单元。所述芯片包括:接收单元201和发送单元202。其中,接收单元201和发送单元202可以是所述芯片上的输入/输出接口、管脚或电路等。所述芯片还可包括处理单元203和存储单元204。处理单元203例如可以是处理器,存储单元204例如可以是存储器。所述处理单元203可执行存储单元204存储的计算机执行指令,以使所述芯片执行上述方法实施例中域主节点执行的网络安全准入方法。可选地,所述存储单元204可以是所述芯片内的存储单元(例如,寄存器、缓存等),所述存储单元204还可以是所述域主节点内的位于所述芯片外部的存储单元(例如,只读存储器(read-only memory,ROM))或可存储静态信息和指令的其他类型的静态存储设备(例如,随机存取存储器(random access memory,RAM))等。
在采用集成的单元(器、器件)的情况下,图11示出了本申请实施例提供的一种网络安全准入装置300的结构示意图。其中,网络安全准入装置300可以是需要加入域进行配对(被允许作为域终端节点加入域)的家庭网络设备,也可以是需要加入域进行配对(被允许作为域终端节点加入域)的家庭网络设备内的部件。参阅图11所示,网络安全准入装置300包括处理单元301和发送单元302。其中,处理单元301用于确定家庭网络设备需要加入域进行配对。发送单元302用于在处理单元301确定家庭网络设备需要加入域进行配对时,向域主节点发送通知消息,该通知消息用于向域主节点通知存在需要加入域进行配对的家庭网络设备。
其中,处理单元301可在检测到上电,或检测到存在新域时,确定需要加入域进行配对(被允许作为域终端节点加入域)。
可选的,所述网络安全准入装置300还可包括存储单元303,所述存储单元303例如 可以是存储器。当所述网络安全准入装置300包括存储单元303时,所述存储单元303用于存储计算机执行指令,所述处理单元301与所述存储单元303连接,所述处理单元301执行所述存储单元303存储的计算机执行指令,以使所述网络安全准入装置300执行上述方法实施例中涉及的需要加入域进行配对的家庭网络设备所执行的网络安全准入方法。
本申请实施例中,处理单元301可以是处理器。发送单元302可以是发射器,发射器中可包括射频电路。存储单元303可以是存储器。
当处理单元301是处理器,发送单元302是发射器,存储单元303是存储器时,本申请实施例所涉及的网络安全准入装置300可以为图12所示网络安全准入装置,图12所示的网络安全准入装置可以应用于家庭网络设备,该家庭网络设备可以是需要加入域进行配对的家庭网络设备。
图12示出了本申请实施例提供的家庭网络设备3000的结构示意图,即示出了网络安全准入装置300另一种可能的结构示意图。参阅图12所示,家庭网络设备3000包括处理器3001、和发射器3002。其中,处理器3001也可以为控制器。所述处理器3001被配置为支持家庭网络设备3000执行图4至图5中涉及的需要加入域进行配对的家庭网络设备的功能。发射器3002被配置为支持家庭网络设备3000进行消息的收发功能。所述家庭网络设备3000还可以包括存储器3003,所述存储器3003用于与处理器3001耦合,其保存家庭网络设备3000必要的程序指令和数据。其中,处理器3001、发射器3002和存储器3003相连,该存储器3003用于存储指令,该处理器3001用于执行该存储器3003存储的指令,以控制发射器3002收发信号,完成上述方法中需要加入域进行配对的家庭网络设备执行相应功能的步骤。
本申请实施例中,网络安全准入装置300和家庭网络设备3000所涉及的与本申请实施例提供的技术方案相关的概念,解释和详细说明及其他步骤请参见前述方法或其他实施例中关于这些内容的描述,此处不做赘述。
当采用芯片形式实现时,本申请实施例中涉及的网络安全准入装置300可以应用于需要加入域进行配对的家庭网络设备内的芯片,所述芯片具有实现上述方法实施例中需要加入域进行配对的家庭网络设备执行网络安全准入方法所涉及的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的单元。所述芯片包括:处理单元301和发送单元302。其中,处理单元301例如可以是处理器,发送单元302可以是所述芯片上的输入/输出接口、管脚或电路等。所述芯片还可包括存储单元303。存储单元303例如可以是存储器。所述处理单元301可执行存储单元303存储的计算机执行指令,以使所述芯片执行上述方法实施例中需要加入域进行配对的家庭网络设备执行的网络安全准入方法。可选地,所述存储单元303可以是所述芯片内的存储单元(例如,寄存器、缓存等),所述存储单元303还可以是所述需要加入域进行配对的家庭网络设备内的位于所述芯片外部的存储单元(例如,只读存储器(read-only memory,ROM))或可存储静态信息和指令的其他类型的静态存储设备(例如,随机存取存储器(random access memory,RAM))等。
在采用集成的单元(器、器件)的情况下,图13示出了本申请实施例提供的一种网络安全准入装置400的结构示意图。其中,网络安全准入装置400可以是需要加入域进行配对的家庭网络设备,也可以是需要加入域进行配对的家庭网络设备内的部件。参阅图13所示,网络安全准入装置400包括接收单元401和处理单元402。其中,接收单元401 用于接收域主节点发送的域主节点的域名配置信息。处理单元402用于将接收单元401接收到的域主节点的域名配置信息中包括的域名作为需要加入域进行配对(被允许作为域终端节点加入域)的家庭网络设备的域名,并向域主节点发送域名配置确认消息。
其中,处理单元402在检测到上电或者检测到存在新域时,确定需要加入域进行配对(被允许作为域终端节点加入域)。
一种可能的实施方式中,网络安全准入装置400还可包括发送单元403,其中,发送单元403用于在接收单元401接收域主节点发送的域主节点的域名配置信息之前,处理单元402确定需要加入域进行配对(被允许作为域终端节点加入域)时,向域主节点发送通知消息,该通知消息用于向域主节点通知存在需要加入域进行配对(被允许作为域终端节点加入域)的家庭网络设备。
可选的,所述网络安全准入装置400还可包括存储单元404,所述存储单元404例如可以是存储器。当所述网络安全准入装置400包括存储单元404时,所述存储单元404用于存储计算机执行指令,所述处理单元402与所述存储单元404连接,所述处理单元402执行所述存储单元404存储的计算机执行指令,以使所述网络安全准入装置400执行上述方法实施例中涉及的需要加入域进行配对的家庭网络设备所执行的网络安全准入方法。
本申请实施例中,接收单元401可以是接收器、通信接口、接收电路等。处理单元402可以是处理器。发送单元403可以是发射器、通信接口、发射电路等。其中,通信接口是统称,可以包括一个或多个接口。接收电路和发射电路中可包括射频电路。存储单元404可以是存储器。
当接收单元401是接收器,处理单元402是处理器,发送单元403是发射器,存储单元404是存储器时,本申请实施例所涉及的网络安全准入装置400可以为图14所示网络安全准入装置,图14所示的网络安全准入装置可以应用于家庭网络设备,该家庭网络设备可以是需要加入域进行配对的家庭网络设备。
图14示出了本申请实施例提供的家庭网络设备4000的结构示意图,即示出了网络安全准入装置400另一种可能的结构示意图。参阅图14所示,家庭网络设备4000包括处理器4001和接收器4002,还可包括发射器4003。其中,处理器4001也可以为控制器。所述处理器4001被配置为支持家庭网络设备4000执行图6中涉及的需要加入域进行配对的家庭网络设备的功能。接收器4002和发射器4003被配置为支持家庭网络设备4000进行消息的收发功能。所述家庭网络设备4000还可以包括存储器4004,所述存储器4004用于与处理器4001耦合,其保存家庭网络设备4000必要的程序指令和数据。其中,处理器4001、接收器4002、发射器4003和存储器4004相连,该存储器4004用于存储指令,该处理器4001用于执行该存储器4004存储的指令,以控制接收器4002和发射器4003收发信号,完成上述方法中需要加入域进行配对的家庭网络设备执行相应功能的步骤。
本申请实施例中,网络安全准入装置400和家庭网络设备4000所涉及的与本申请实施例提供的技术方案相关的概念,解释和详细说明及其他步骤请参见前述方法或其他实施例中关于这些内容的描述,此处不做赘述。
当采用芯片形式实现时,本申请实施例中涉及的网络安全准入装置400可以应用于需要加入域进行配对的家庭网络设备内的芯片,所述芯片具有实现上述方法实施例中需要加入域进行配对的家庭网络设备执行网络安全准入方法所涉及的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功 能相对应的单元。所述芯片包括:接收单元401和处理单元402。所述芯片还可包括发送单元403,或者也还可包括存储单元404。其中,处理单元402例如可以是处理器,接收单元401和发送单元403可以是所述芯片上的输入/输出接口、管脚或电路等。存储单元404例如可以是存储器。所述处理单元402可执行存储单元404存储的计算机执行指令,以使所述芯片执行上述方法实施例中需要加入域进行配对的家庭网络设备执行的网络安全准入方法。可选地,所述存储单元404可以是所述芯片内的存储单元(例如,寄存器、缓存等),所述存储单元404还可以是所述需要加入域进行配对的家庭网络设备内的位于所述芯片外部的存储单元(例如,只读存储器(read-only memory,ROM))或可存储静态信息和指令的其他类型的静态存储设备(例如,随机存取存储器(random access memory,RAM))等。
需要说明的是,本申请实施例上述涉及的处理器可以是中央处理器(central processing unit,CPU),通用处理器,数字信号处理器(digital signal processor,DSP),专用集成电路(application-specific integrated circuit,ASIC),现场可编程门阵列(field programmable gate array,FPGA)或者其他可编程逻辑器件、晶体管逻辑器件、硬件部件或者其任意组合。其可以实现或执行结合本申请公开内容所描述的各种示例性的逻辑方框,模块和电路。处理器也可以是实现计算功能的组合,例如包含一个或多个微处理器组合,DSP和微处理器的组合等等。
其中,所述存储器可以集成在所述处理器中,也可以与所述处理器分开设置。
作为一种实现方式,收发器可以包括接收器和发射器。接收器和发射器的功能可以考虑通过收发电路或者收发的专用芯片实现。处理器可以考虑通过专用处理芯片、处理电路、处理器或者通用芯片实现。
作为另一种实现方式,将实现处理器、接收器和发射器功能的程序代码存储在存储器中,通用处理器通过执行存储器中的代码来实现处理器、接收器和发射器的功能。
根据本申请实施例提供的方法,本申请实施例还提供一种家庭网络通信系统,其包括前述的域主节点和一个或多于一个需要加入域进行配对的家庭网络设备。
本申请实施例还提供一种计算机存储介质,该计算机存储介质中存储有一些指令,这些指令被执行时,可以完成上述方法实施例中涉及的网络安全准入方法。
本申请实施例还提供一种计算机程序产品,该计算机程序产品中包括计算机程序,该计算机程序用于执行上述方法实施例中涉及的网络安全准入方法。
本领域内的技术人员应明白,本申请实施例可提供为方法、系统、或计算机程序产品。因此,本申请实施例可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本申请实施例可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
本申请实施例是参照根据本申请实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的 功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。

Claims (24)

  1. 一种网络安全准入的方法,其特征在于,包括:
    域主节点向用户发出提示信息,所述提示信息用于提示存在需要加入域进行配对的家庭网络设备;
    所述域主节点接收用户的授权操作,所述授权操作用于指示允许所述家庭网络设备加入域进行配对操作,且是用户根据所述提示信息进行操作的;
    所述域主节点开启配对窗口,并在配对窗口的有效期内发送指示信息,所述指示信息用于指示允许所述家庭网络设备加入域进行配对。
  2. 根据权利要求1所述的方法,其特征在于,所述提示信息在所述域主节点本地显示或在代理节点显示,所述授权操作为用户对域主节点或代理节点的操作;或者
    所述提示信息由所述域主节点或代理节点发送给用户使用的终端并在所述终端上显示,所述终端上安装有用于用户进行授权操作的应用程序,所述授权操作由用户对所述应用程序进行操作触发。
  3. 根据权利要求2所述的方法,其特征在于,在所述域主节点本地或代理节点显示的提示信息为闪灯提示,用户对域主节点或代理节点的操作为按键操作。
  4. 根据权利要求1-3任一项所述的方法,其特征在于,域主节点向用户发出提示信息,包括:
    所述域主节点接收家庭网络设备发送的通知消息,所述通知消息用于通知存在需要加入域进行配对的家庭网络设备;
    所述域主节点依据所述通知消息,直接向用户或间接通过代理节点向用户发出所述提示信息。
  5. 根据权利要求4所述的方法,其特征在于,所述通知消息中包括发送通知消息的家庭网络设备的标识;
    所述指示信息中包括所述标识。
  6. 一种网络安全准入的方法,其特征在于,包括:
    域主节点接收用户的授权操作,所述授权操作用于指示允许家庭网络设备加入域进行配对操作;
    所述域主节点发送所述域主节点的域名配置信息;
    所述域主节点接收所述家庭网络设备发送的域名配置确认消息,所述域名配置确认消息用于指示所述家庭网络设备将所述域主节点的域名配置信息中包括的域名作为所述家庭网络设备的域名。
  7. 根据权利要求6所述的方法,其特征在于,所述授权操作是根据域主节点向用户发出的提示信息进行操作的,所述提示信息用于提示存在需要加入域进行配对的家庭网络设备。
  8. 根据权利要求7所述的方法,其特征在于,所述提示信息在所述域主节点本地显示或在代理节点显示,所述授权操作为用户对域主节点或代理节点的按键操作;或 者
    所述提示信息由所述域主节点或代理节点发送给用户使用的终端并在所述终端上显示,所述终端上安装有用于用户进行授权操作的应用程序,所述授权操作由用户对所述应用程序进行操作触发。
  9. 根据权利要求8所述的方法,其特征在于,在所述域主节点本地显示或在代理节点显示的提示信息为闪灯提示,用户对域主节点或代理节点的操作为按键操作。
  10. 根据权利要求7-8任一项所述的方法,其特征在于,域主节点接收用户的授权操作之前,所述方法还包括:
    所述域主节点接收家庭网络设备发送的通知消息,所述通知消息用于通知存在需要配对的家庭网络设备;
    所述域主节点依据所述通知消息,向用户发出所述提示信息。
  11. 根据权利要求10所述的方法,其特征在于,所述通知消息中包括发送通知消息的家庭网络设备的标识。
  12. 根据权利要求6至11任一项所述的方法,其特征在于,所述域主节点接收所述家庭网络设备发送的域名配置确认消息之后,所述方法还包括:
    所述域主节点开启配对窗口,并在配对窗口的有效期内发送指示信息,所述指示信息用于指示允许所述家庭网络设备加入域进行配对。
  13. 一种网络安全准入方法,其特征在于,包括:
    家庭网络设备检测到上电或者检测到存在新域;
    所述家庭网络设备向域主节点发送通知消息,所述通知消息用于向域主节点通知存在需要加入域进行配对的家庭网络设备。
  14. 一种网络安全准入方法,其特征在于,包括:
    家庭网络设备接收域主节点发送的所述域主节点的域名配置信息;
    所述家庭网络设备将所述域主节点的域名配置信息中包括的域名作为所述家庭网络设备的域名,并向所述域主节点发送域名配置确认消息。
  15. 根据权利要求14所述的方法,其特征在于,家庭网络设备接收域主节点发送的所述域主节点的域名配置信息之前,所述方法还包括:
    所述家庭网络设备检测到上电或者检测到存在新域时,向域主节点发送通知消息,所述通知消息用于向域主节点通知存在需要加入域进行配对的家庭网络设备。
  16. 一种家庭网络设备,其特征在于,所述家庭网络设备作为域主节点用于管理家庭网络及家庭网络中节点间通信传输资源的分配,所述家庭网络为通过家庭网络介质进行通信的网络,所述家庭网络介质包括电力线、双绞线、塑料光纤和同轴电缆中的至少一种;
    作为域主节点的家庭网络设备管理作为域终端节点的家庭网络设备接入所述家庭网络,当所述域主节点接收来自作为域终端节点的家庭网络设备发送的、用于通知存在需要接入所述家庭网络的家庭网络设备的通知消息时,所述域主节点执行如下步骤:
    向用户发出提示信息,所述提示信息用于提示存在需要接入所述家庭网络的家庭网络设备;
    接收用户的授权操作,所述授权操作用于指示允许所述家庭网络设备接入所述家庭网络,且是用户根据所述提示信息进行操作的;
    开启配对窗口,并在配对窗口的有效期内发送指示信息,所述指示信息用于指示允许所述家庭网络设备接入所述家庭网络。
  17. 根据权利要求16所述的家庭网络设备,其特征在于,所述提示信息为域主节点或代理节点的闪灯提示,所述授权操作为用户对主节点或代理节点的按键操作。
  18. 根据权利要求16所述的家庭网络设备,其特征在于,所述提示信息为所述域主节点或间接通过代理节点发送给用户使用的终端并在所述终端上显示的推送消息,所述终端上安装有用于用户进行授权操作的应用程序,所述授权操作由用户对所述应用程序进行操作触发。
  19. 根据权利要求16-18任一项所述的家庭网络设备,其特征在于,所述通知消息中包括家庭网络设备的标识;
    所述指示信息中包括所述标识。
  20. 根据权利要求16所述的家庭网络设备,其特征在于,所述域主节点接收用户的授权操作之后,还用于执行如下步骤:
    发送所述域主节点的域名配置信息;
    接收所述家庭网络设备发送的域名配置确认消息,所述域名配置确认消息用于指示所述家庭网络设备将所述域主节点的域名配置信息中包括的域名作为所述家庭网络设备的域名。
  21. 根据权利要求16所述的家庭网络设备,其特征在于,所述家庭网络设备作为家庭网络的接入设备与运营商网络相连,在所述运营商网络和所述家庭网络间实现跨网络的数据传输。
  22. 一种家庭网络设备,其特征在于,所述家庭网络设备作为域终端节点接入家庭网络,所述家庭网络为通过家庭网络介质进行通信的网络,所述家庭网络介质包括电力线、双绞线、塑料光纤和同轴电缆中的至少一种;
    作为域终端节点接入家庭网络的所述家庭网络设备用于执行如下步骤:
    确定被允许作为域终端节点接入家庭网络;
    向域主节点发送通知消息,所述通知消息用于通知存在作为域终端节点接入所述家庭网络的家庭网络设备。
  23. 根据权利要求22所述的家庭网络设备,其特征在于,所述家庭网络设备检测到上电或者检测到存在新域时,确定被允许作为域终端节点接入家庭网络。
  24. 根据权利要求22所述的家庭网络设备,其特征在于,所述家庭网络设备向域主节点发送通知消息之后,还用于执行如下步骤:
    接收所述域主节点发送的所述域主节点的域名配置信息;
    将所述域主节点的域名配置信息中包括的域名作为所述家庭网络设备的域名,并向所述域主节点发送域名配置确认消息。
PCT/CN2019/073204 2018-02-01 2019-01-25 网络安全准入方法及家庭网络设备 WO2019149151A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP19748132.8A EP3739817B1 (en) 2018-02-01 2019-01-25 Network security access method and home network device
US16/945,504 US20200366514A1 (en) 2018-02-01 2020-07-31 Network Secure Admission Method and Home Network Device

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201810101960.5 2018-02-01
CN201810101960.5A CN110113175B (zh) 2018-02-01 2018-02-01 网络安全准入方法及家庭网络设备

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US16/945,504 Continuation US20200366514A1 (en) 2018-02-01 2020-07-31 Network Secure Admission Method and Home Network Device

Publications (1)

Publication Number Publication Date
WO2019149151A1 true WO2019149151A1 (zh) 2019-08-08

Family

ID=67478619

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/073204 WO2019149151A1 (zh) 2018-02-01 2019-01-25 网络安全准入方法及家庭网络设备

Country Status (4)

Country Link
US (1) US20200366514A1 (zh)
EP (1) EP3739817B1 (zh)
CN (1) CN110113175B (zh)
WO (1) WO2019149151A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114982199A (zh) * 2020-01-17 2022-08-30 Oppo广东移动通信有限公司 一种安全信息发现方法、安全信息配置方法及设备

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8085802B1 (en) * 2004-12-02 2011-12-27 Entropic Communications, Inc. Multimedia over coaxial cable access protocol
CN104253853A (zh) * 2013-06-25 2014-12-31 埃克申铁克电子公司 嵌入式设备加载应用程序组件以在朋友与家人间的移动设备间共享数字信息的系统和方法
CN106559357A (zh) * 2015-09-30 2017-04-05 中国电信股份有限公司 设备接入网络的方法和系统、网络管理节点
CN107295510A (zh) * 2016-03-31 2017-10-24 中国移动通信有限公司研究院 基于ocsp实现家庭基站准入控制的方法、设备及系统

Family Cites Families (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7701858B2 (en) * 2003-07-17 2010-04-20 Sensicast Systems Method and apparatus for wireless communication in a mesh network
DE102008003573A1 (de) * 2008-01-09 2009-07-16 Endress + Hauser Process Solutions Ag Verfahren zur Integration eines Teilnehmers in ein drahtloses Kommunikations-Netzwerk der Prozessautomatisierung
CN101374050B (zh) * 2008-10-23 2011-04-06 普天信息技术研究院有限公司 一种实现身份认证的装置、系统及方法
CN102098593A (zh) * 2011-02-23 2011-06-15 华为技术有限公司 一种epon系统中上行注册的方法和远端设备
US9319140B2 (en) * 2011-12-02 2016-04-19 Futurewei Technologies, Inc. Apparatus and method for registering a coaxial network unit on an optical network
WO2013083752A1 (en) * 2011-12-08 2013-06-13 Siemens Aktiengesellschaft Method and devices for running push-button configuration sessions
CN103248543B (zh) * 2013-04-24 2017-01-25 华为技术有限公司 一种对码方法、对码控制设备及对码设备
WO2014178605A1 (ko) * 2013-04-30 2014-11-06 인텔렉추얼디스커버리 주식회사 스마트 가전 장치 및 네트워크 관리 시스템
CN105099837A (zh) * 2014-05-23 2015-11-25 中兴通讯股份有限公司 家庭网络的有线通用介质联网技术组网方法及装置
CN105577485A (zh) * 2014-10-13 2016-05-11 中兴通讯股份有限公司 一种实现家庭网络组网的方法及装置和G.hn设备
US10439674B2 (en) * 2014-11-30 2019-10-08 Integrated Silicon Solution Israel Ltd. Domain establishment, registration and resignation via a push button mechanism
JP6512725B2 (ja) * 2015-03-03 2019-05-15 華為技術有限公司Huawei Technologies Co.,Ltd. ネットワークにノードを接続するための方法、装置、およびシステム
WO2017031504A1 (en) * 2015-08-20 2017-02-23 Cloudwear, Inc. Method and apparatus for geographic location based electronic security management

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8085802B1 (en) * 2004-12-02 2011-12-27 Entropic Communications, Inc. Multimedia over coaxial cable access protocol
CN104253853A (zh) * 2013-06-25 2014-12-31 埃克申铁克电子公司 嵌入式设备加载应用程序组件以在朋友与家人间的移动设备间共享数字信息的系统和方法
CN106559357A (zh) * 2015-09-30 2017-04-05 中国电信股份有限公司 设备接入网络的方法和系统、网络管理节点
CN107295510A (zh) * 2016-03-31 2017-10-24 中国移动通信有限公司研究院 基于ocsp实现家庭基站准入控制的方法、设备及系统

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3739817A4

Also Published As

Publication number Publication date
CN110113175A (zh) 2019-08-09
CN110113175B (zh) 2021-11-09
EP3739817B1 (en) 2023-06-21
EP3739817A1 (en) 2020-11-18
US20200366514A1 (en) 2020-11-19
EP3739817A4 (en) 2021-03-03

Similar Documents

Publication Publication Date Title
US9185641B2 (en) Using discoverable peer-to-peer services to allow remote onboarding of headless devices over a Wi-Fi network
EP2561708B1 (en) Method and apparatus for determining access point service capabilities
US9858425B2 (en) Method and apparatus for incrementally sharing greater amounts of information between user devices
EP1872250B1 (en) Wireless device discovery and configuration
US9628691B2 (en) Method and apparatus for identifying a physical IoT device
US20150026779A1 (en) Performing remote wi-fi network configuration when a network security protocol is unknown
KR102210823B1 (ko) 스마트 홈 디바이스를 위한 연결 방법 및 그 장치
KR20210032133A (ko) IoT 단말의 무선랜 AP 자동 접속 방법 및 시스템
US20150071216A1 (en) Allowing mass re-onboarding of headless devices
CN110830968A (zh) 一种组网方法、装置、蓝牙设备及计算机可读介质
US9794119B2 (en) Method and system for preventing the propagation of ad-hoc networks
CN103959832B (zh) 用于运行按钮配置会话的方法和设备
US20230164666A1 (en) System and methods for topology-aware configuration distribution
WO2015055807A1 (en) Method and network node device for controlling the run of technology specific push-button configuration sessions within a heterogeneous or homogeneous wireless network and heterogeneous or homogeneous wireless network
WO2023001082A1 (zh) 一种配网方法及装置
CN113965334A (zh) 在线签约方法、装置及系统
US20170093679A1 (en) Networking method and apparatus for home network with universal wired media networking technology
WO2019149151A1 (zh) 网络安全准入方法及家庭网络设备
CN105577485A (zh) 一种实现家庭网络组网的方法及装置和G.hn设备
US20230007576A1 (en) Access network intelligent controller for multiple types of access networks
US20230284333A1 (en) Control of communication devices in a wireless network
CN110061858B (zh) 基于无线网络的父子节点设备间防误配方法
CN108512738A (zh) 终端的远程控制方法和系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19748132

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2019748132

Country of ref document: EP

Effective date: 20200812