WO2022124652A1 - 스마트홈 환경의 무선랜 시스템에서 c2c 연결을 기반으로 iot 제어기기와 iot 피제어기기 간 등록을 설정하는 방법 및 장치 - Google Patents
스마트홈 환경의 무선랜 시스템에서 c2c 연결을 기반으로 iot 제어기기와 iot 피제어기기 간 등록을 설정하는 방법 및 장치 Download PDFInfo
- Publication number
- WO2022124652A1 WO2022124652A1 PCT/KR2021/017482 KR2021017482W WO2022124652A1 WO 2022124652 A1 WO2022124652 A1 WO 2022124652A1 KR 2021017482 W KR2021017482 W KR 2021017482W WO 2022124652 A1 WO2022124652 A1 WO 2022124652A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- controlled device
- value
- controller
- challenge
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3271—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/083—Network architectures or network communication protocols for network security for authentication of entities using passwords
- H04L63/0846—Network architectures or network communication protocols for network security for authentication of entities using passwords using time-dependent-passwords, e.g. periodically changing passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0894—Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/63—Location-dependent; Proximity-dependent
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/068—Authentication using credential vaults, e.g. password manager applications or one time password [OTP] applications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/69—Identity-dependent
- H04W12/71—Hardware identity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/80—Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication
Definitions
- the present specification relates to a method for setting an IoT device in a wireless LAN system in a smart home environment, and more particularly, to a method and apparatus for setting registration between an IoT controller and an IoT controlled device based on C2C connection .
- the goal of the Connected Home over IP project is to simplify development for manufacturers and increase compatibility for consumers.
- the project is based on the common belief that smart home devices must ensure security, stability, and smooth usability.
- the project seeks to enable communication between smart home devices, mobile apps and cloud services based on the Internet Protocol (IP), and to define a specific set of IP-based networking technologies for device authentication.
- IP Internet Protocol
- the industry joint committee adopts an open source approach to the development and application of new unified connectivity protocols.
- the project will utilize market-proven smart home technologies such as Amazon, Apple, Google and Zigbee Alliance.
- the decision to leverage these technologies is expected to accelerate the protocol development process and provide rapid benefits to manufacturers and consumers.
- the project aims to simplify the creation of smart homes for device manufacturers, as well as devices compatible with voice recognition services such as Amazon's Alexa, Apple's Siri, and Google's Assistant.
- voice recognition services such as Amazon's Alexa, Apple's Siri, and Google's Assistant.
- the upcoming protocol will complement existing technology and the joint committee members encourage device manufacturers to continue to innovate based on existing technology.
- the Connected Home over IP project encourages device manufacturers, silicon providers and developers in the smart home industry to participate and contribute to standards development.
- the present specification proposes a method and apparatus for setting registration between an IoT controller and an IoT controlled device based on C2C connection in a wireless LAN system in a smart home environment.
- An example of the present specification proposes a method of setting registration between an IoT controller and an IoT controlled device based on C2C connection.
- This embodiment proposes a method of setting registration locally between an IoT controller and an IoT controlled device through a C2C (Cloud-to-Cloud) connection in a smart home environment.
- the user performs a proof-of-ownership procedure to confirm that the IoT controlled device physically exists.
- the IoT controller verifies the local existence of the IoT controlled device and provides BLE. It has the effect of preventing the registration of neighboring devices or devices that are not located locally.
- a control device to be described later may correspond to the IoT controller, and a controlled device may correspond to the IoT controlled device.
- a controlled device receives detection information of the controlled device from a controller.
- the controlled device transmits a challenge request message requesting first information to the controller device.
- the controlled device receives a challenge response message including the first information from the control device.
- the controlled device transmits a challenge confirm message to the control device.
- the controlled device is connected to the first cloud based on a first account, and the controller device is connected to a second cloud based on a second account.
- the detection information of the controlled device, the challenge request message, the challenge response message, and the challenge confirmation message are transmitted/received based on the connection between the first and second clouds. That is, the information and the message may be transmitted/received through a C2C connection (connection between the first cloud of the controlled device and the second cloud of the control device) for registration between the controlled device and the controller device.
- a C2C connection connection between the first cloud of the controlled device and the second cloud of the control device
- the first information is a Proof of Possession value.
- the challenge confirmation message includes a verification result for commissioning between the controlled device and the controller based on the first information.
- the user performs a proof-of-ownership procedure to confirm that the IoT controlled device physically exists.
- the IoT controller By checking the local existence, there is an effect that it is possible to prevent the registration of a neighboring device or a device that is not located locally, which is searched through BLE.
- FIG. 1 shows an example of a transmitting apparatus and/or a receiving apparatus of the present specification.
- WLAN wireless LAN
- 3 is a view for explaining a general link setup process.
- FIG. 6 shows a modified example of a transmitting apparatus and/or a receiving apparatus of the present specification.
- FIG. 7 shows a connection structure between a Controller and a Controlee connected to each cloud.
- FIG. 11 shows a Wi-Fi connection and registration process of a Controlee device.
- FIG. 12 is a flowchart illustrating a procedure for setting registration between an IoT controller and an IoT controlled device based on a C2C connection according to the present embodiment.
- a or B (A or B) may mean “only A”, “only B” or “both A and B”.
- a or B (A or B)” may be interpreted as “A and/or B (A and/or B)”.
- A, B or C (A, B or C)” herein means “only A,” “only B,” “only C,” or “any and any combination of A, B and C. combination of A, B and C)”.
- a slash (/) or a comma (comma) used herein may mean “and/or”.
- A/B may mean “and/or B”.
- A/B may mean “only A”, “only B”, or “both A and B”.
- A, B, C may mean “A, B, or C”.
- At least one of A and B may mean “only A”, “only B” or “both A and B”.
- the expression “at least one of A or B” or “at least one of A and/or B” means “at least one It can be interpreted the same as “at least one of A and B”.
- At least one of A, B and C means “only A”, “only B”, “only C” or “of A, B and C”. any combination of A, B and C”. Also, “at least one of A, B or C” or “at least one of A, B and/or C” means may mean “at least one of A, B and C”.
- control information EHT-Signal
- EHT-Signal when displayed as “control information (EHT-Signal)”, “EHT-Signal” may be proposed as an example of “control information”.
- control information of the present specification is not limited to “EHT-Signal”, and “EHT-Signal” may be proposed as an example of “control information”.
- control information ie, EHT-signal
- EHT-Signal even when displayed as “control information (ie, EHT-signal)”, “EHT-Signal” may be proposed as an example of “control information”.
- the following examples of the present specification may be applied to various wireless communication systems.
- the following example of the present specification may be applied to a wireless local area network (WLAN) system.
- the present specification may be applied to the IEEE 802.11a/g/n/ac standard or the IEEE 802.11ax standard.
- this specification may be applied to the newly proposed EHT standard or IEEE 802.11be standard.
- an example of the present specification may be applied to the EHT standard or a new wireless LAN standard that is an enhancement of IEEE 802.11be.
- an example of the present specification may be applied to a mobile communication system.
- LTE Long Term Evolution
- 3GPP 3rd Generation Partnership Project
- an example of the present specification may be applied to a communication system of the 5G NR standard based on the 3GPP standard.
- FIG. 1 shows an example of a transmitting apparatus and/or a receiving apparatus of the present specification.
- the example of FIG. 1 may perform various technical features described below.
- 1 relates to at least one STA (station).
- the STAs 110 and 120 of the present specification are a mobile terminal, a wireless device, a wireless transmit/receive unit (WTRU), a user equipment (UE), It may also be called by various names such as a mobile station (MS), a mobile subscriber unit, or simply a user.
- the STAs 110 and 120 in the present specification may be referred to by various names such as a network, a base station, a Node-B, an access point (AP), a repeater, a router, and a relay.
- the STAs 110 and 120 may be referred to by various names such as a receiving device, a transmitting device, a receiving STA, a transmitting STA, a receiving device, and a transmitting device.
- the STAs 110 and 120 may perform an access point (AP) role or a non-AP role. That is, the STAs 110 and 120 of the present specification may perform AP and/or non-AP functions.
- the AP may also be indicated as an AP STA.
- the STAs 110 and 120 of the present specification may support various communication standards other than the IEEE 802.11 standard.
- a communication standard eg, LTE, LTE-A, 5G NR standard
- the STA of the present specification may be implemented in various devices such as a mobile phone, a vehicle, and a personal computer.
- the STA of the present specification may support communication for various communication services such as voice call, video call, data communication, and autonomous driving (Self-Driving, Autonomous-Driving).
- the STAs 110 and 120 may include a medium access control (MAC) conforming to the IEEE 802.11 standard and a physical layer interface for a wireless medium.
- MAC medium access control
- the STAs 110 and 120 will be described based on the sub-view (a) of FIG. 1 as follows.
- the first STA 110 may include a processor 111 , a memory 112 , and a transceiver 113 .
- the illustrated processor, memory, and transceiver may each be implemented as separate chips, or at least two or more blocks/functions may be implemented through one chip.
- the transceiver 113 of the first STA performs a signal transmission/reception operation. Specifically, IEEE 802.11 packets (eg, IEEE 802.11a/b/g/n/ac/ax/be, etc.) may be transmitted/received.
- IEEE 802.11 packets eg, IEEE 802.11a/b/g/n/ac/ax/be, etc.
- the first STA 110 may perform an intended operation of the AP.
- the processor 111 of the AP may receive a signal through the transceiver 113 , process the received signal, generate a transmission signal, and perform control for signal transmission.
- the memory 112 of the AP may store a signal (ie, a received signal) received through the transceiver 113 , and may store a signal to be transmitted through the transceiver (ie, a transmission signal).
- the second STA 120 may perform an intended operation of a non-AP STA.
- the transceiver 123 of the non-AP performs a signal transmission/reception operation.
- IEEE 802.11 packets eg, IEEE 802.11a/b/g/n/ac/ax/be, etc.
- IEEE 802.11a/b/g/n/ac/ax/be, etc. may be transmitted/received.
- the processor 121 of the non-AP STA may receive a signal through the transceiver 123 , process the received signal, generate a transmission signal, and perform control for signal transmission.
- the memory 122 of the non-AP STA may store a signal (ie, a received signal) received through the transceiver 123 and may store a signal to be transmitted through the transceiver (ie, a transmission signal).
- an operation of a device indicated as an AP in the following specification may be performed by the first STA 110 or the second STA 120 .
- the operation of the device marked as AP is controlled by the processor 111 of the first STA 110 , and is controlled by the processor 111 of the first STA 110 .
- Relevant signals may be transmitted or received via the controlled transceiver 113 .
- control information related to an operation of the AP or a transmission/reception signal of the AP may be stored in the memory 112 of the first STA 110 .
- the operation of the device indicated by the AP is controlled by the processor 121 of the second STA 120 and controlled by the processor 121 of the second STA 120 .
- a related signal may be transmitted or received via the transceiver 123 that is used.
- control information related to an operation of the AP or a transmission/reception signal of the AP may be stored in the memory 122 of the second STA 110 .
- an operation of a device indicated as a non-AP in the following specification may be performed by the first STA 110 or the second STA 120 .
- the operation of the device marked as non-AP is controlled by the processor 121 of the second STA 120, and the processor ( A related signal may be transmitted or received via the transceiver 123 controlled by 121 .
- control information related to the operation of the non-AP or the AP transmit/receive signal may be stored in the memory 122 of the second STA 120 .
- the operation of the device marked as non-AP is controlled by the processor 111 of the first STA 110 , and the processor ( Related signals may be transmitted or received via transceiver 113 controlled by 111 .
- control information related to the operation of the non-AP or the AP transmission/reception signal may be stored in the memory 112 of the first STA 110 .
- transmission / reception STA, first STA, second STA, STA1, STA2, AP, first AP, second AP, AP1, AP2, (transmission / reception) Terminal, (transmission / reception) device , (transmitting/receiving) apparatus, a device called a network, etc. may refer to the STAs 110 and 120 of FIG. 1 .
- a device indicated by a /receiver) device, a (transmit/receive) apparatus, and a network may also refer to the STAs 110 and 120 of FIG. 1 .
- an operation in which various STAs transmit and receive signals may be performed by the transceivers 113 and 123 of FIG. 1 .
- an example of an operation of generating a transmission/reception signal or performing data processing or operation in advance for a transmission/reception signal is 1) Determining bit information of a subfield (SIG, STF, LTF, Data) field included in a PPDU /Acquisition/configuration/computation/decoding/encoding operation, 2) time resource or frequency resource (eg, subcarrier resource) used for the subfield (SIG, STF, LTF, Data) field included in the PPDU, etc.
- a specific sequence eg, pilot sequence, STF / LTF sequence, SIG
- SIG subfield
- SIG subfield
- STF subfield
- LTF LTF
- Data subfield
- an operation related to determination / acquisition / configuration / operation / decoding / encoding of an ACK signal may include
- various information eg, field/subfield/control field/parameter/power related information used by various STAs for determination/acquisition/configuration/computation/decoding/encoding of transmit/receive signals is may be stored in the memories 112 and 122 of FIG. 1 .
- the device/STA of the sub-view (a) of FIG. 1 described above may be modified as shown in the sub-view (b) of FIG. 1 .
- the STAs 110 and 120 of the present specification will be described based on the sub-drawing (b) of FIG. 1 .
- the transceivers 113 and 123 illustrated in (b) of FIG. 1 may perform the same function as the transceivers illustrated in (a) of FIG. 1 .
- the processing chips 114 and 124 illustrated in (b) of FIG. 1 may include processors 111 and 121 and memories 112 and 122 .
- the processors 111 and 121 and the memories 112 and 122 illustrated in (b) of FIG. 1 are the processors 111 and 121 and the memories 112 and 122 illustrated in (a) of FIG. ) can perform the same function.
- a technical feature in which a transmitting STA transmits a control signal is that the control signals generated by the processors 111 and 121 shown in the sub-drawings (a)/(b) of FIG. 1 are (a) of FIG. ) / (b) can be understood as a technical feature transmitted through the transceivers 113 and 123 shown in (b).
- the technical feature in which the transmitting STA transmits the control signal is a technical feature in which the control signal to be transmitted to the transceivers 113 and 123 is generated from the processing chips 114 and 124 shown in the sub-view (b) of FIG. can be understood
- the technical feature in which the receiving STA receives the control signal may be understood as the technical feature in which the control signal is received by the transceivers 113 and 123 shown in the sub-drawing (a) of FIG. 1 .
- the technical feature that the receiving STA receives the control signal is that the control signal received by the transceivers 113 and 123 shown in the sub-drawing (a) of FIG. 1 is the processor shown in (a) of FIG. 111, 121) can be understood as a technical feature obtained by.
- the technical feature for the receiving STA to receive the control signal is that the control signal received by the transceivers 113 and 123 shown in the sub-view (b) of FIG. 1 is the processing chip shown in the sub-view (b) of FIG. It can be understood as a technical feature obtained by (114, 124).
- software codes 115 and 125 may be included in the memories 112 and 122 .
- the software codes 115 and 125 may include instructions for controlling the operations of the processors 111 and 121 .
- Software code 115, 125 may be included in a variety of programming languages.
- the processors 111 and 121 or the processing chips 114 and 124 shown in FIG. 1 may include an application-specific integrated circuit (ASIC), other chipsets, logic circuits, and/or data processing devices.
- the processor may be an application processor (AP).
- the processors 111 and 121 or the processing chips 114 and 124 illustrated in FIG. 1 may include a digital signal processor (DSP), a central processing unit (CPU), a graphics processing unit (GPU), and a modem (Modem). and demodulator).
- DSP digital signal processor
- CPU central processing unit
- GPU graphics processing unit
- Modem modem
- demodulator demodulator
- SNAPDRAGONTM series processor manufactured by Qualcomm®, an EXYNOSTM series processor manufactured by Samsung®, and a processor manufactured by Apple®. It may be an A series processor, a HELIOTM series processor manufactured by MediaTek®, an ATOMTM series processor manufactured by INTEL®, or a processor enhanced therewith.
- uplink may mean a link for communication from a non-AP STA to an AP STA, and an uplink PPDU/packet/signal may be transmitted through the uplink.
- downlink may mean a link for communication from an AP STA to a non-AP STA, and a downlink PPDU/packet/signal may be transmitted through the downlink.
- WLAN wireless LAN
- FIG. 2 shows the structure of an infrastructure basic service set (BSS) of the Institute of Electrical and Electronic Engineers (IEEE) 802.11.
- BSS infrastructure basic service set
- IEEE Institute of Electrical and Electronic Engineers
- a wireless LAN system may include one or more infrastructure BSSs 200 and 205 (hereinafter, BSSs).
- BSSs 200 and 205 are a set of APs and STAs such as an access point (AP) 225 and a station 200-1 (STA1) that can communicate with each other through successful synchronization, and are not a concept indicating a specific area.
- the BSS 205 may include one or more combinable STAs 205 - 1 and 205 - 2 to one AP 230 .
- the BSS may include at least one STA, the APs 225 and 230 providing a distribution service, and a distribution system (DS) 210 connecting a plurality of APs.
- DS distribution system
- the distributed system 210 may implement an extended service set (ESS) 240 that is an extended service set by connecting several BSSs 200 and 205 .
- ESS 240 may be used as a term indicating one network in which one or several APs are connected through the distributed system 210 .
- APs included in one ESS 240 may have the same service set identification (SSID).
- the portal 220 may serve as a bridge connecting a wireless LAN network (IEEE 802.11) and another network (eg, 802.X).
- IEEE 802.11 IEEE 802.11
- 802.X another network
- a network between the APs 225 and 230 and a network between the APs 225 and 230 and the STAs 200 - 1 , 205 - 1 and 205 - 2 may be implemented.
- a network that establishes a network and performs communication even between STAs without the APs 225 and 230 is defined as an ad-hoc network or an independent basic service set (IBSS).
- FIG. 2 The lower part of FIG. 2 is a conceptual diagram illustrating the IBSS.
- the IBSS is a BSS operating in an ad-hoc mode. Since IBSS does not include an AP, there is no centralized management entity that performs a centralized management function. That is, in the IBSS, the STAs 250-1, 250-2, 250-3, 255-4, and 255-5 are managed in a distributed manner. In IBSS, all STAs (250-1, 250-2, 250-3, 255-4, 255-5) can be mobile STAs, and access to a distributed system is not allowed, so a self-contained network network) is formed.
- 3 is a view for explaining a general link setup process.
- the STA may perform a network discovery operation.
- the network discovery operation may include a scanning operation of the STA. That is, in order for the STA to access the network, it is necessary to find a network in which it can participate.
- An STA must identify a compatible network before participating in a wireless network.
- the process of identifying a network existing in a specific area is called scanning. Scanning methods include active scanning and passive scanning.
- an STA performing scanning transmits a probe request frame to discover which APs exist nearby while moving channels, and waits for a response.
- a responder transmits a probe response frame to the STA that has transmitted the probe request frame in response to the probe request frame.
- the responder may be an STA that last transmitted a beacon frame in the BSS of the channel being scanned.
- the AP since the AP transmits a beacon frame, the AP becomes the responder.
- the STAs in the IBSS rotate and transmit the beacon frame, so the responder is not constant.
- an STA that transmits a probe request frame on channel 1 and receives a probe response frame on channel 1 stores BSS-related information included in the received probe response frame and channel) to perform scanning (ie, probe request/response transmission/reception on channel 2) in the same way.
- the scanning operation may be performed in a passive scanning manner.
- An STA performing scanning based on passive scanning may wait for a beacon frame while moving channels.
- the beacon frame is one of the management frames in IEEE 802.11, and is periodically transmitted to inform the existence of a wireless network, and to allow a scanning STA to search for a wireless network and participate in the wireless network.
- the AP plays a role of periodically transmitting a beacon frame, and in the IBSS, the STAs in the IBSS rotate and transmit the beacon frame.
- the STA performing scanning receives the beacon frame, it stores information on the BSS included in the beacon frame and records beacon frame information in each channel while moving to another channel.
- the STA may store BSS-related information included in the received beacon frame, move to the next channel, and perform scanning on the next channel in the same manner.
- the STA discovering the network may perform an authentication process through step SS320.
- This authentication process may be referred to as a first authentication process in order to clearly distinguish it from the security setup operation of step S340 to be described later.
- the authentication process of S320 may include a process in which the STA transmits an authentication request frame to the AP, and in response thereto, the AP transmits an authentication response frame to the STA.
- An authentication frame used for an authentication request/response corresponds to a management frame.
- the authentication frame includes an authentication algorithm number, an authentication transaction sequence number, a status code, a challenge text, a Robust Security Network (RSN), and a Finite Cyclic Group), etc. may be included.
- RSN Robust Security Network
- Finite Cyclic Group Finite Cyclic Group
- the STA may transmit an authentication request frame to the AP.
- the AP may determine whether to allow authentication for the corresponding STA based on information included in the received authentication request frame.
- the AP may provide the result of the authentication process to the STA through the authentication response frame.
- the successfully authenticated STA may perform a connection process based on step S330.
- the association process includes a process in which the STA transmits an association request frame to the AP, and in response, the AP transmits an association response frame to the STA.
- the connection request frame includes information related to various capabilities, a beacon listening interval, a service set identifier (SSID), supported rates, supported channels, RSN, and a mobility domain.
- SSID service set identifier
- supported rates supported channels
- RSN radio station
- TIM broadcast request Traffic Indication Map Broadcast request
- connection response frame includes information related to various capabilities, status codes, Association IDs (AIDs), support rates, Enhanced Distributed Channel Access (EDCA) parameter sets, Received Channel Power Indicator (RCPI), Received Signal to Noise (RSNI). indicator), mobility domain, timeout interval (association comeback time), overlapping BSS scan parameters, TIM broadcast response, QoS map, and the like.
- AIDs Association IDs
- EDCA Enhanced Distributed Channel Access
- RCPI Received Channel Power Indicator
- RSNI Received Signal to Noise
- indicator mobility domain
- timeout interval association comeback time
- overlapping BSS scan parameters TIM broadcast response
- QoS map QoS map
- step S340 the STA may perform a security setup process.
- the security setup process of step S340 may include, for example, a process of private key setup through 4-way handshaking through an Extensible Authentication Protocol over LAN (EAPOL) frame. .
- EAPOL Extensible Authentication Protocol over LAN
- ZigBee is a high-level communication protocol that uses a small, low-power digital radio based on IEEE 802.15.4-2003.
- IEEE 802.15.4-2003 is a standard for short-range personal wireless communication networks such as lamps, electronic meters, and consumer electronic products using short-range radio frequencies.
- ZigBee is mainly used in RF (Radio Frequency) applications that require low data rates, low battery consumption, and network safety.
- Zigbee is currently used in industrial control, embedded sensors, medical data collection, fire and theft, building automation, home automation, and more.
- Smart Energy provides utility/energy service providers with a secure and easy-to-use home wireless network to manage energy. Smart Energy gives utility/energy service providers or their customers direct control over thermostats or other associated devices.
- Water temperature sensor Power sensor, energy monitoring, fire and theft monitoring, smart devices and connection sensors
- the ZigBee coordinator can store network-related information and also serves as a trust center or storage for security keys.
- a router can not only function as an application, but also function as a writer that can forward data from other devices.
- the ZigBee end device includes the ability to communicate with the parent node. This relationship allows the node to wait a long time, which can further extend the battery life.
- Zigbee is simpler than many other protocol stacks, and the size of the Zigbee stack code is small compared to other protocols.
- MAC and PHY are defined by the IEEE 802.15.4 standard.
- the network and application layers are defined by the Zigbee Alliance and the actual application provided by the device designer.
- 802.15.4 is a simple packet data protocol for lightweight wireless networks. 802.15.4 is intended to monitor and control applications where battery life is critical. 802.15.4 is the source of ZigBee's excellent battery life.
- 802.15.4 is applicable to both IEEE long/short addressing. Short addressing is used for network management where a network ID is temporarily determined. This makes it inexpensive, but still allows use of over 65,000 network nodes.
- 802.15.4 enables reliable data transmission and beacon management.
- the network layer ensures proper operation of the MAC layer and provides an interface to the application layer.
- the network layer supports star, tree, and mesh topologies.
- the network layer is where networks are initiated, joined, destroyed, and discovered.
- the network layer is responsible for routing and security.
- the application framework is an execution environment in which application objects can exchange data.
- the application object is defined by the producer of the Zigbee device. As defined by Zigbee, the application object is located at the top of the application layer and is determined by the device manufacturer. The application object actually builds the application; This could be a light bulb, a light switch, an LED, an I/O line, and so on.
- IoT Internet of Things
- a 'smart home' is created. If you live in such a house, you can use various automation or remote functions, such as automatically turning on lights or air conditioners when users come home from work outside, and automatically playing appropriate music depending on the weather that day. Other similar concepts include 'smart building' and 'smart factory (factory)'.
- Matter is an IP-based protocol that can run on existing network technologies such as Wi-Fi, Ethernet, and Thread.
- the federation said Matter devices could be easily set up using Bluetooth Low Energy (BLE). Because smart home devices can inform each other of their identity and possible operations, users do not need to do complicated configuration work.
- BLE Bluetooth Low Energy
- Matter's feature called 'multi-admin' allows products from various ecosystems, such as Apple HomeKit and Amazon Alexa, to work together without the complicated work of end users.
- Multiple managers can also set up layers of control to help different family members connect to smart appliances in the home with different levels of control.
- FIG. 6 shows a modified example of a transmitting apparatus and/or a receiving apparatus of the present specification.
- Each device/STA of the sub-drawings (a)/(b) of FIG. 1 may be modified as shown in FIG. 6 .
- the transceiver 630 of FIG. 6 may be the same as the transceivers 113 and 123 of FIG. 1 .
- the transceiver 630 of FIG. 6 may include a receiver and a transmitter.
- the processor 610 of FIG. 6 may be the same as the processors 111 and 121 of FIG. 1 . Alternatively, the processor 610 of FIG. 6 may be the same as the processing chips 114 and 124 of FIG. 1 .
- the memory 150 of FIG. 6 may be the same as the memories 112 and 122 of FIG. 1 .
- the memory 150 of FIG. 6 may be a separate external memory different from the memories 112 and 122 of FIG. 1 .
- the power management module 611 manages power for the processor 610 and/or the transceiver 630 .
- the battery 612 supplies power to the power management module 611 .
- the display 613 outputs the result processed by the processor 610 .
- Keypad 614 receives input to be used by processor 610 .
- a keypad 614 may be displayed on the display 613 .
- SIM card 615 may be an integrated circuit used to securely store an international mobile subscriber identity (IMSI) used to identify and authenticate subscribers in mobile phone devices, such as mobile phones and computers, and keys associated therewith. .
- IMSI international mobile subscriber identity
- the speaker 640 may output a sound related result processed by the processor 610 .
- the microphone 641 may receive a sound related input to be used by the processor 610 .
- This specification relates to a method for generating information necessary for a CHIP Controlee device for the registration (commissioning) of a CHIP (Connected Home over IP) device and a method for acquiring the corresponding information from the CHIP Controller.
- CHIP Controller passes the value for information creation to the Cloud and enables local device registration between the two devices by passing the value required for connection to the Controller through the verification process between Controlee’s Cloud and Controller’s Cloud. .
- the conventional CHIP standard technology performs commissioning of a device by scanning a QR (Quick Response) code or a numeric code (Manual Pairing Code) attached to the Controlee device from the controller device to the camera or directly inputting it.
- the Device Discriminator value (16 bits)
- the Setup PIN Postal Index Number
- a device with a camera, such as a smartphone reads this through QR scan, so that the controller can get the value.
- a numeric code 11 digits or 21 digits
- the corresponding code is entered through the controller's input device to perform device registration through the corresponding value.
- a camera device for scanning the QR or a keypad for inputting numbers must exist in the controller device.
- a numeric code since the length of information is long, the user must directly input 11 or 21 digits, which may result in poor user experience or an error during input. Also, depending on the type of Controlee device, there are cases where the QR Code value or numeric code cannot be changed, so there is a security threat of device registration.
- the controller acquires the value (seed value) for generating the value required for device registration included in the QR or numeric code of the Controlee and transmits it to the Cloud of the Controlee manufacturer to obtain the Setup PIN Code required for device registration.
- FIG. 7 shows a connection structure between a Controller and a Controlee connected to each cloud.
- the environment proposed in this specification is an environment in which the controller of manufacturer A and the controller of manufacturer B perform initial device registration as shown in FIG. 7 .
- the case where the manufacturer A and the manufacturer B are different manufacturers is exemplified, but the present invention is not limited thereto, and the same can be applied even when the Controlee and the Controller are the same manufacturer.
- Controller B is connected to Cloud B based on the account, and Controlee A is in the state before being connected to Cloud A. That is, Controlee A is an embodiment of a new product and has not yet been connected to the Internet or Wi-Fi. Controller B's account connected to Cloud B may or may not have account linking with Cloud A's account.
- FIG. 8 is a flowchart illustrating a procedure for a case in which the user applies power to the Controlee A device.
- Controller B allows Controller B to log in to Cloud B through the account for connecting to Cloud B.
- the user inputs power to the new Controlee, Controlee A.
- Controlee A performs the initialization process.
- Controlee A's CHIP Stack creates values necessary for device registration during initialization. The generated values are as follows.
- Controlee generates a value necessary for device registration is as follows.
- Controlee generates a 4-digit Device Discriminator value through the Random Number Generator.
- a Rotating ID (18 bytes) defined in the CHIP standard is created.
- Controlee extracts Controlee's unique value (ex, BLE MAC address, Wi-Fi MAC address, etc.).
- Controlee inputs the concatenated value of the Device Discriminator (or Rotating ID) value and the BLE MAC address created earlier as the input value of the Hash function (ex SHA256).
- Controlee generates the output value (ex 256bit) of the Hash function.
- Controlee stores the upper 27 bits of the output value of the Hash function internally to use it as the Setup PIN Code value.
- Controlee stores the lower bit (12bit or 32bit) of the output value of the Hash function as a Proof of Possession Value in the form of a number.
- BLE Bluetooth Low Energy Advertisement
- the BLE Advertisement Packet uses the packet format defined in the CHIP standard as it is, and the Device Discriminator (or Rotating ID) included in the packet includes the previously generated value.
- Controller B receives the corresponding BLE Advertisement packet and finds out that there is a nearby Controlee device. At this time, you can check the MAC address of the Controlee, which is the sender of the advertisement. Controller B informs Cloud B that it has found Controlee A with the identifier for the CHIP device (including Device Discriminator (or Rotating ID) and BLE MAC Address).
- Controlee A is a device with a screen
- the Proof of Possession value (ex 4 digit number) is displayed on the screen, and the Proof of Possession process is performed by entering the corresponding number in another device.
- Controller B is expressed as an App (Application), but Controller B is not limited to the app of the smartphone, and may correspond to devices such as artificial intelligence speakers, tablets, wallpads, TVs, and robots.
- Cloud B the controller cloud, sends a notification to Controller B that Controlee A has been found.
- the user who receives this notification operates Controller B to receive confirmation from the user whether to link with Controlee A's cloud.
- Controller B's app since Controlee A has been found, the user is informed that an account in Cloud A is required to connect Controlee A to Wi-Fi, and if necessary, the user confirms whether to create an account. If the user agrees to this, Cloud B starts interworking with Cloud A.
- Cloud B can create a temporary account for Cloud A, and communication between Cloud A and Cloud B can proceed through the temporary account.
- the user already has an account in Cloud A he can link the account in Cloud A and the account in Cloud B by entering the account information in the input window of Controller B.
- Proof of Possession is the process of confirming that the device is physically present in the user before connecting the device to the network and registering it. Through this verification process, the local existence of the device is checked, and it functions to prevent the registration of neighboring devices or non-local devices that are searched through BLE. In general, the process is performed between a device of the same manufacturer and an App of the corresponding manufacturer, either by inputting a physical button, a PIN code displayed on the screen, or through locality check such as NFC tagging.
- a locality check is performed by inputting a short number (eg, a 4-digit number) through a cloud-to-cloud challenge request and response process.
- a short number eg, a 4-digit number
- Controlee A is displayed in 2.2.
- the Proof of Possession value created in the section is displayed.
- Controller B was previously 2.2. Section 2.3. As in Section 2.3. Through inter-cloud communication linked in section, Cloud B notifies Cloud A that a device has been found for device registration. At this time, the value of Device Discriminator or Rotating ID for device identification and the BLE MAC Address of Controlee A are informed together.
- Cloud A After receiving this, Cloud A requests a Challenge Request to Cloud B through a C2C (Cloud-to-Cloud) connection.
- C2C Cloud-to-Cloud
- Cloud A is the previous 2.2.
- the values are generated in the following order according to the same algorithm that Controlee generated the Setup PIN Code.
- Cloud A receives Device Discriminator or Rotating ID and BLE MAC Address from Cloud B.
- Cloud A enters the previously created Device Discriminator value or the concatenated value of Rotating ID and BLE MAC address as the input value of the Hash function (ex SHA256).
- Hash function output value (ex 256bit)
- Cloud A stores the upper 27 bits of the output value of the Hash function internally to use it as the Setup PIN Code value.
- Cloud A stores the lower bit (12bit or 32bit) internally as a Proof of Possession Value in the form of a number.
- the Setup PIN Code and Proof of Possession Value which are output values of the hash function generated in this way, are exactly the same as the values generated by Controlee A before. Cloud A stores this value internally, and then uses it for validation of the challenge response received from Cloud B.
- Cloud B guides Controller B to input the Proof of Possession value that is being output to Controlee A through Controller B.
- Controller B has a keypad for the user input device, the corresponding number is input, and in the case of a voice recognition device such as an artificial intelligence speaker or robot, the user enters the number by reading the number displayed by Controlee A.
- Controller B receiving the input, delivers the numeric value to its Cloud B, and sends a Challenge Response message including the number input from the user from Cloud B to Cloud A.
- Cloud A compares the Proof of Possession value included in the received Challenge Response message with the Proof of Possession value it created just before. If the received value and the calculated value of Cloud A are the same, Cloud A recognizes that it was received from the actual user of the device and sends the Setup PIN Code for registering Controlee A to Cloud B as a Challenge Confirm message. If the corresponding values are different, Cloud A notifies Cloud B of failure through fail in the reason code.
- an algorithm generated through SHA256 is used for simplicity, but Controlee A and Cloud A can generate a value in a complex way, and since the algorithm is shared within Vendor A, the same manufacturer, the external device Discriminator or Rotating ID and MAC address cannot be inferred.
- FIG. 11 shows a Wi-Fi connection and registration process of a Controlee device.
- Controller B registers the Controlee A with the device (Commissioning) through the Setup PIN code obtained through the Proof of Possession process in Section 2.4.
- Controller B receives Setup PIN Code through Cloud B.
- the Setup PIN Code can be obtained by either Controller B scanning the QR code of Controlee A as described in the previous chapter, or by directly entering the 11 or 22-digit number written on the Controlee into the Controlee by the user. there was.
- Controller B performs BLE Connection through the BLE Rendezvous process in the same way as Controlee A and CHIP standard. will be passed on to
- Controller B will be able to receive Cloud A's account information from Controller B as described in previous 2.3. Through this information, Controlee A can log in to Cloud A without using the manufacturer's app through Cloud URL information, account information, or Access Token.
- Controlee A which has obtained the Wi-Fi Credential information, can access the same AP connected to Controller B based on the information. After that, when connecting to a secure session, Controlee A uses the setup PIN code value initially created by itself, and Controller B uses the setup PIN code value received from its Cloud B. Since these two values are completely the same, a secure session can be connected between them according to the SPAKE2+ algorithm according to the CHIP standard.
- the CHIP Commissioning process can be completed through device authentication and certificate registration through the Device Attestation process defined in the CHIP standard.
- FIG. 12 is a flowchart illustrating a procedure for setting registration between an IoT controller and an IoT controlled device based on a C2C connection according to the present embodiment.
- This embodiment proposes a method of setting registration locally between an IoT controller and an IoT controlled device through a C2C (Cloud-to-Cloud) connection in a smart home environment.
- the user performs a proof-of-ownership procedure to confirm that the IoT controlled device physically exists.
- the IoT controller verifies the local existence of the IoT controlled device and provides BLE. It has the effect of preventing the registration of neighboring devices or devices that are not located locally.
- a control device to be described later may correspond to the IoT controller, and a controlled device may correspond to the IoT controlled device.
- step S1210 the controlled device (controlee) receives the detection information of the controlled device from the controller (controller).
- step S1220 the controlled device transmits a challenge request message requesting the first information to the control device.
- step S1230 the controlled device receives a challenge response message including the first information from the control device.
- step S1240 the controlled device transmits a challenge confirm message to the control device.
- the controlled device is connected to the first cloud based on a first account, and the controller device is connected to a second cloud based on a second account.
- the detection information of the controlled device, the challenge request message, the challenge response message, and the challenge confirmation message are transmitted/received based on the connection between the first and second clouds. That is, the information and the message may be transmitted/received through a C2C connection (connection between the first cloud of the controlled device and the second cloud of the control device) for registration between the controlled device and the controller device.
- a C2C connection connection between the first cloud of the controlled device and the second cloud of the control device
- the first information is a Proof of Possession value.
- the challenge confirmation message includes a verification result for commissioning between the controlled device and the controller based on the first information.
- the controlled device may request the ownership proof value (four digits) from the controller (or the second cloud).
- the second cloud may request the user to input or say the ownership proof value, and the user may input or say the ownership proof value to the controlled device or an App (Application) of the controlled device.
- the controller may transmit the proof-of-ownership value input from the user to the second cloud, and the second cloud may include the proof-of-ownership value input from the user in the challenge response message and deliver it to the first cloud. have.
- the detection information of the controlled device may include second and third information.
- the second information may be a device discriminator (or Rotating ID) value for identification of the controlled device
- the third information may be a Bluetooth Low Energy (BLE) MAC address value of the controlled device.
- BLE Bluetooth Low Energy
- the controlled device may generate fourth and fifth information through the first cloud (or the first cloud may generate the fourth and fifth information).
- the fourth information may be a setup personal identification number (PIN) code value
- the fifth information may be a device identifier value calculated by the first cloud.
- PIN personal identification number
- the verification result for registration between the controlled device and the controller device may include the fourth information. That is, as a result of successful verification, the controlled device (or the first cloud) may transmit the set PIN code value to the control device (or the second cloud).
- the verification result for registration between the controlled device and the controller device may include a reason code for verification failure. That is, the controlled device (or the first cloud) may notify the control device (or the second cloud) of the verification failure with the reason code.
- the controlled device may perform BLE connection with the controller based on the second, fourth, and fifth information.
- the controlled device may receive Wi-Fi credential information of an access point (AP) connected to the controller through the BLE connection from the controller device.
- the controlled device may establish a connection with the AP based on the Wi-Fi credential information.
- the controlled device may establish a secure session with the controller based on the fourth information.
- the controlled device may complete registration between the controlled device and the controller device based on authentication of the controlled device.
- AP access point
- a procedure for the user to apply power to the controlled device to perform initialization and search processes is as follows.
- the controlled device may generate the ownership proof value, the device identifier value, and the set PIN code value for registration with the controller.
- the device discriminant value may be generated as a 4-digit number by a random number generator.
- the set PIN code value may be generated as a number of upper 27 bits among output values of a hash function.
- the proof of ownership value may be generated as a number of lower 12 bits or 13 bits among the output values of the hash function.
- the input value of the hash function may be a value in which the device discriminator value and the BLE MAC address value are concatenated.
- the controlled device may transmit a BLE advertisement message including the device identifier value to the controller device.
- the controlled device may perform BLE connection with the controller based on the BLE advertisement message.
- the detection information of the controlled device may be obtained by the controller based on the BLE connection. That is, the controller device can search for the controlled device through the BLE connection, but there is a disadvantage in that the controlled device can be searched even if the controlled device is not physically local.
- the control device can check the local existence of the controlled device to prevent the registration of neighboring devices or devices that are not locally searched through BLE. It works.
- an account of the first cloud of the controlled device may be created in the second cloud of the control device.
- the controlled device may receive information about the first account from the controller device based on the connection between the first and second clouds.
- the first account may be a temporary account created by the second cloud.
- the first and second accounts may be linked with each other. Thereby, inter-cloud communication can be established.
- the technical features of the present specification described above may be applied to various devices and methods.
- the above-described technical features of the present specification may be performed/supported through the apparatus of FIGS. 1 and/or 6 .
- the technical features of the present specification described above may be applied only to a part of FIGS. 1 and/or 6 .
- the technical features of the present specification described above are implemented based on the processing chips 114 and 124 of FIG. 1 , or implemented based on the processors 111 and 121 and the memories 112 and 122 of FIG. 1 , or , may be implemented based on the processor 610 and the memory 620 of FIG. 6 .
- the device of the present specification is a device operating in a wireless LAN system in a smart home environment, and the device includes a memory and a processor operatively coupled to the memory, wherein the processor includes a controller.
- receiving detection information of the controlled device from transmitting a challenge request message for requesting first information to the control device; receiving a challenge response message including the first information from the control device; and transmits a challenge confirm message to the control device.
- CRM computer readable medium
- CRM proposed by the present specification is at least one computer readable medium including at least one computer readable medium including instructions based on being executed by at least one processor.
- the CRM may include: receiving detection information of the controlled device from a controller; transmitting a challenge request message for requesting first information to the controller; receiving a challenge response message including the first information from the control device; and transmitting a challenge confirm message to the controller device.
- the instructions stored in the CRM of the present specification may be executed by at least one processor.
- At least one processor related to CRM in the present specification may be the processors 111 and 121 or the processing chips 114 and 124 of FIG. 1 , or the processor 610 of FIG. 6 .
- the CRM of the present specification may be the memories 112 and 122 of FIG. 1 , the memory 620 of FIG. 6 , or a separate external memory/storage medium/disk.
- Machine learning refers to a field that defines various problems dealt with in the field of artificial intelligence and studies methodologies to solve them. do.
- Machine learning is also defined as an algorithm that improves the performance of a certain task through constant experience.
- An artificial neural network is a model used in machine learning, and may refer to an overall model having problem-solving ability, which is composed of artificial neurons (nodes) that form a network by combining synapses.
- An artificial neural network may be defined by a connection pattern between neurons of different layers, a learning process that updates model parameters, and an activation function that generates an output value.
- the artificial neural network may include an input layer, an output layer, and optionally one or more hidden layers. Each layer includes one or more neurons, and the artificial neural network may include neurons and synapses connecting neurons. In the artificial neural network, each neuron may output a function value of an activation function for input signals, weights, and biases input through synapses.
- Model parameters refer to parameters determined through learning, and include the weight of synaptic connections and the bias of neurons.
- the hyperparameter refers to a parameter that must be set before learning in a machine learning algorithm, and includes a learning rate, the number of iterations, a mini-batch size, an initialization function, and the like.
- the purpose of learning the artificial neural network can be seen as determining the model parameters that minimize the loss function.
- the loss function may be used as an index for determining optimal model parameters in the learning process of the artificial neural network.
- Machine learning can be classified into supervised learning, unsupervised learning, reinforcement learning, and semi-supervised learning according to a learning method.
- Supervised learning refers to a method of training an artificial neural network in a state where a label for the training data is given, and the label is the correct answer (or result value) that the artificial neural network should infer when the training data is input to the artificial neural network.
- Unsupervised learning may refer to a method of training an artificial neural network in a state where no labels are given for training data.
- Reinforcement learning can refer to a learning method in which an agent defined in an environment learns to select an action or sequence of actions that maximizes the cumulative reward in each state.
- machine learning implemented as a deep neural network (DNN) including a plurality of hidden layers is also called deep learning (deep learning), and deep learning is a part of machine learning.
- DNN deep neural network
- deep learning deep learning
- machine learning is used in a sense including deep learning.
- a robot can mean a machine that automatically handles or operates a task given by its own capabilities.
- a robot having a function of recognizing an environment and performing an operation by self-judgment may be referred to as an intelligent robot.
- Robots can be classified into industrial, medical, home, military, etc. depending on the purpose or field of use.
- the robot may be provided with a driving unit including an actuator or a motor to perform various physical operations such as moving the robot joints.
- the movable robot includes a wheel, a brake, a propeller, and the like in the driving unit, and may travel on the ground or fly in the air through the driving unit.
- the extended reality is a generic term for virtual reality (VR), augmented reality (AR), and mixed reality (MR).
- VR technology provides only CG images of objects or backgrounds in the real world
- AR technology provides virtual CG images on top of images of real objects
- MR technology is a computer that mixes and combines virtual objects in the real world. graphic technology.
- MR technology is similar to AR technology in that it shows both real and virtual objects. However, there is a difference in that in AR technology, a virtual object is used in a form that complements a real object, whereas in MR technology, a virtual object and a real object are used with equal characteristics.
- HMD Head-Mount Display
- HUD Head-Up Display
- mobile phone tablet PC, laptop, desktop, TV, digital signage, etc.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims (16)
- 스마트홈 환경의 무선랜 시스템에서,피제어기기(controlee)가, 제어기기(controller)로부터 상기 피제어기기의 검출 정보를 수신하는 단계;상기 피제어기기가, 상기 제어기기에게 제1 정보를 요청하는 챌린지 요청(challenge request) 메시지를 전송하는 단계;상기 피제어기기가, 상기 제어기기로부터 상기 제1 정보를 포함하는 챌린지 응답(challenge response) 메시지를 수신하는 단계; 및상기 피제어기기가, 상기 제어기기에게 챌린지 확인(challenge confirm) 메시지를 전송하는 단계를 포함하되,상기 피제어기기는 제1 계정을 기반으로 상기 제1 클라우드와 연결되고,상기 제어기기는 제2 계정을 기반으로 제2 클라우드와 연결되고,상기 피제어기기의 검출 정보, 상기 챌린지 요청 메시지, 상기 챌린지 응답 메시지 및 상기 챌린지 확인 메시지는 상기 제1 및 제2 클라우드 간 연결을 기반으로 송수신되고,상기 제1 정보는 소유 증명(Proof of Possession) 값이고, 및상기 챌린지 확인 메시지는 상기 제1 정보를 기반으로 상기 피제어기기와 상기 제어기기 간의 등록(commissioning)에 대한 검증 결과를 포함하는방법.
- 제1항에 있어서,상기 피제어기기의 검출 정보는 제2 및 제3 정보를 포함하고,상기 제2 정보는 상기 피제어기기의 식별을 위한 기기 판별자(device discriminator 또는 Rotating Identifier) 값이고,상기 제3 정보는 상기 피제어기기의 BLE(Bluetooth Low Energy) MAC 주소 값인방법.
- 제2항에 있어서,상기 피제어기기가, 상기 제1 클라우드를 통해 제4 및 제5 정보를 생성하는 단계를 더 포함하되,상기 제5 정보가 상기 제1 정보와 동일하면, 상기 피제어기기와 상기 제어기기 간의 등록에 대한 검증 결과는 상기 제4 정보를 포함하고,상기 제5 정보가 상기 제1 정보와 다르다면, 상기 피제어기기와 상기 제어기기 간의 등록에 대한 검증 결과는 검증 실패에 대한 이유 코드(reason code)를 포함하고,상기 제4 정보는 설정(Setup) PIN(Personal Identification Number) 코드 값이고,상기 제5 정보는 상기 제1 클라우드에 의해 계산된 기기 판별자 값인방법.
- 제3항에 있어서,상기 피제어기기가, 상기 제2, 상기 제4 및 제5 정보를 기반으로 상기 제어기기와 BLE 연결을 수행하는 단계;상기 피제어기기가, 상기 제어기기로부터 상기 BLE 연결을 통해 상기 제어기기와 연결된 AP(Access Point)의 Wi-Fi 크리덴셜(credential) 정보를 수신하는 단계;상기 피제어기기가, 상기 Wi-Fi 크리덴셜 정보를 기반으로 상기 AP와 연결을 수행하는 단계;상기 피제어기기가, 상기 제4 정보를 기반으로 상기 제어기기와 보안 세션을 설정하는 단계; 및상기 피제어기기가, 상기 피제어기기의 인증(attestation)을 기반으로 상기 피제어기기와 상기 제어기기 간의 등록을 완료하는 단계를 더 포함하는방법.
- 제3항에 있어서,상기 피제어기기가, 상기 제어기기와의 등록을 위해 상기 소유 증명 값, 상기 기기 판별자 값 및 상기 설정 PIN 코드 값을 생성하는 단계를 더 포함하되,상기 기기 판별자 값은 임의 숫자 생성기(Random Number Generator)에 의해 4자리 숫자로 생성되고,상기 설정 PIN 코드 값은 해쉬(Hash) 함수의 출력 값 중 상위 27비트의 숫자로 생성되고,상기 소유 증명 값은 상기 해쉬 함수의 출력 값 중 하위 12비트 또는 13비트의 숫자로 생성되고,상기 해쉬 함수의 입력 값은 상기 기기 판별자 값과 상기 BLE MAC 주소 값이 연결된(concatenate) 값인방법.
- 제5항에 있어서,상기 피제어기기가, 상기 제어기기에게 상기 기기 판별자 값을 포함한 BLE 광고(BLE advertisement) 메시지를 전송하는 단계; 및상기 피제어기기가, 상기 BLE 광고 메시지를 기반으로 상기 제어기기와 BLE 연결을 수행하는 단계를 더 포함하되,상기 피제어기기의 검출 정보는 상기 BLE 연결을 기반으로 상기 제어기기에 의해 획득되는방법.
- 제1항에 있어서,상기 피제어기기가, 상기 제어기기로부터 상기 제1 및 제2 클라우드 간 연결을 기반으로 상기 제1 계정에 대한 정보를 수신하는 단계를 더 포함하되,상기 제1 계정은 상기 제2 클라우드에 의해 생성된 임시 계정이고,상기 제1 및 제2 계정은 서로 연동되는방법.
- 스마트홈 환경의 무선랜 시스템에서 피제어기기(controlee)에 있어서,메모리;트랜시버; 및상기 메모리 및 상기 트랜시버와 동작 가능하게 결합된 프로세서를 포함하되, 상기 프로세서는:제어기기(controller)로부터 상기 피제어기기의 검출 정보를 수신하고;상기 제어기기에게 제1 정보를 요청하는 챌린지 요청(challenge request) 메시지를 전송하고;상기 제어기기로부터 상기 제1 정보를 포함하는 챌린지 응답(challenge response) 메시지를 수신하고; 및상기 제어기기에게 챌린지 확인(challenge confirm) 메시지를 전송하되,상기 피제어기기는 제1 계정을 기반으로 상기 제1 클라우드와 연결되고,상기 제어기기는 제2 계정을 기반으로 제2 클라우드와 연결되고,상기 피제어기기의 검출 정보, 상기 챌린지 요청 메시지, 상기 챌린지 응답 메시지 및 상기 챌린지 확인 메시지는 상기 제1 및 제2 클라우드 간 연결을 기반으로 송수신되고,상기 제1 정보는 소유 증명(Proof of Possession) 값이고, 및상기 챌린지 확인 메시지는 상기 제1 정보를 기반으로 상기 피제어기기와 상기 제어기기 간의 등록(commissioning)에 대한 검증 결과를 포함하는피제어기기.
- 제8항에 있어서,상기 피제어기기의 검출 정보는 제2 및 제3 정보를 포함하고,상기 제2 정보는 상기 피제어기기의 식별을 위한 기기 판별자(device discriminator 또는 Rotating Identifier) 값이고,상기 제3 정보는 상기 피제어기기의 BLE(Bluetooth Low Energy) MAC 주소 값인피제어기기.
- 제9항에 있어서,상기 프로세서는, 상기 제1 클라우드를 통해 제4 및 제5 정보를 생성하되,상기 제5 정보가 상기 제1 정보와 동일하면, 상기 피제어기기와 상기 제어기기 간의 등록에 대한 검증 결과는 상기 제4 정보를 포함하고,상기 제5 정보가 상기 제1 정보와 다르다면, 상기 피제어기기와 상기 제어기기 간의 등록에 대한 검증 결과는 검증 실패에 대한 이유 코드(reason code)를 포함하고,상기 제4 정보는 설정(Setup) PIN(Personal Identification Number) 코드 값이고,상기 제5 정보는 상기 제1 클라우드에 의해 계산된 기기 판별자 값인피제어기기.
- 제10항에 있어서,상기 프로세서는:상기 제2, 상기 제4 및 제5 정보를 기반으로 상기 제어기기와 BLE 연결을 수행하고;상기 제어기기로부터 상기 BLE 연결을 통해 상기 제어기기와 연결된 AP(Access Point)의 Wi-Fi 크리덴셜(credential) 정보를 수신하고;상기 Wi-Fi 크리덴셜 정보를 기반으로 상기 AP와 연결을 수행하고;상기 제4 정보를 기반으로 상기 제어기기와 보안 세션을 설정하고; 및상기 피제어기기의 인증(attestation)을 기반으로 상기 피제어기기와 상기 제어기기 간의 등록을 완료하는피제어기기.
- 제10항에 있어서,상기 프로세서는, 상기 제어기기와의 등록을 위해 상기 소유 증명 값, 상기 기기 판별자 값 및 상기 설정 PIN 코드 값을 생성하되,상기 기기 판별자 값은 임의 숫자 생성기(Random Number Generator)에 의해 4자리 숫자로 생성되고,상기 설정 PIN 코드 값은 해쉬(Hash) 함수의 출력 값 중 상위 27비트의 숫자로 생성되고,상기 소유 증명 값은 상기 해쉬 함수의 출력 값 중 하위 12비트 또는 13비트의 숫자로 생성되고,상기 해쉬 함수의 입력 값은 상기 기기 판별자 값과 상기 BLE MAC 주소 값이 연결된(concatenate) 값인피제어기기.
- 제12항에 있어서,상기 프로세서는:상기 제어기기에게 상기 기기 판별자 값을 포함한 BLE 광고(BLE advertisement) 메시지를 전송하고; 및상기 BLE 광고 메시지를 기반으로 상기 제어기기와 BLE 연결을 수행하되,상기 피제어기기의 검출 정보는 상기 BLE 연결을 기반으로 상기 제어기기에 의해 획득되는방법.
- 제8항에 있어서,상기 프로세서는, 상기 제어기기로부터 상기 제1 및 제2 클라우드 간 연결을 기반으로 상기 제1 계정에 대한 정보를 수신하되,상기 제1 계정은 상기 제2 클라우드에 의해 생성된 임시 계정이고,상기 제1 및 제2 계정은 서로 연동되는피제어기기.
- 적어도 하나의 프로세서(processor)에 의해 실행됨을 기초로 하는 명령어(instruction)를 포함하는 적어도 하나의 컴퓨터로 읽을 수 있는 기록매체(computer readable medium)에 있어서,제어기기(controller)로부터 상기 피제어기기의 검출 정보를 수신하는 단계;상기 제어기기에게 제1 정보를 요청하는 챌린지 요청(challenge request) 메시지를 전송하는 단계;상기 제어기기로부터 상기 제1 정보를 포함하는 챌린지 응답(challenge response) 메시지를 수신하는 단계; 및상기 제어기기에게 챌린지 확인(challenge confirm) 메시지를 전송하는 단계를 포함하되,피제어기기(controlee)는 제1 계정을 기반으로 상기 제1 클라우드와 연결되고,상기 제어기기는 제2 계정을 기반으로 제2 클라우드와 연결되고,상기 피제어기기의 검출 정보, 상기 챌린지 요청 메시지, 상기 챌린지 응답 메시지 및 상기 챌린지 확인 메시지는 상기 제1 및 제2 클라우드 간 연결을 기반으로 송수신되고,상기 제1 정보는 소유 증명(Proof of Possession) 값이고, 및상기 챌린지 확인 메시지는 상기 제1 정보를 기반으로 상기 피제어기기와 상기 제어기기 간의 등록(commissioning)에 대한 검증 결과를 포함하는기록매체.
- 스마트홈 환경의 무선랜 시스템에서 장치에 있어서,메모리; 및상기 메모리와 동작 가능하게 결합된 프로세서를 포함하되, 상기 프로세서는:제어기기(controller)로부터 상기 피제어기기의 검출 정보를 수신하고;상기 제어기기에게 제1 정보를 요청하는 챌린지 요청(challenge request) 메시지를 전송하고;상기 제어기기로부터 상기 제1 정보를 포함하는 챌린지 응답(challenge response) 메시지를 수신하고; 및상기 제어기기에게 챌린지 확인(challenge confirm) 메시지를 전송하되,피제어기기(controlee)는 제1 계정을 기반으로 상기 제1 클라우드와 연결되고,상기 제어기기는 제2 계정을 기반으로 제2 클라우드와 연결되고,상기 피제어기기의 검출 정보, 상기 챌린지 요청 메시지, 상기 챌린지 응답 메시지 및 상기 챌린지 확인 메시지는 상기 제1 및 제2 클라우드 간 연결을 기반으로 송수신되고,상기 제1 정보는 소유 증명(Proof of Possession) 값이고, 및상기 챌린지 확인 메시지는 상기 제1 정보를 기반으로 상기 피제어기기와 상기 제어기기 간의 등록(commissioning)에 대한 검증 결과를 포함하는장치.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US18/038,426 US12418424B2 (en) | 2020-12-10 | 2021-11-25 | Method and apparatus for setting registration between IoT controller and IoT controlee on basis of C2C connection in wireless LAN system of smart home environment |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR10-2020-0172676 | 2020-12-10 | ||
| KR20200172676 | 2020-12-10 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022124652A1 true WO2022124652A1 (ko) | 2022-06-16 |
Family
ID=81973812
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2021/017482 Ceased WO2022124652A1 (ko) | 2020-12-10 | 2021-11-25 | 스마트홈 환경의 무선랜 시스템에서 c2c 연결을 기반으로 iot 제어기기와 iot 피제어기기 간 등록을 설정하는 방법 및 장치 |
Country Status (2)
| Country | Link |
|---|---|
| US (1) | US12418424B2 (ko) |
| WO (1) | WO2022124652A1 (ko) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2024216639A1 (zh) * | 2023-04-21 | 2024-10-24 | Oppo广东移动通信有限公司 | 接入网络的方法及装置 |
Families Citing this family (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2025506396A (ja) | 2022-02-02 | 2025-03-11 | オラクル・インターナショナル・コーポレイション | 異なるクラウド環境間の通信を可能にするためのネットワーク技術 |
| US12204955B2 (en) * | 2022-02-02 | 2025-01-21 | Oracle International Corporation | Multi-cloud infrastructure-database adaptor |
| WO2023150522A1 (en) | 2022-02-02 | 2023-08-10 | Oracle International Corporation | Enhanced network-link architecture for improved end-to-end latency in communication between different cloud environments |
| JP2025507288A (ja) | 2022-02-02 | 2025-03-18 | オラクル・インターナショナル・コーポレイション | 異なるクラウドサービスプロバイダにわたるアイデンティティの伝搬 |
| JP2025535771A (ja) | 2022-10-14 | 2025-10-28 | オラクル・インターナショナル・コーポレイション | マルチクラウドインフラストラクチャにおけるsaasアプリケーションのためのネットワークリンクの確立 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20150122199A (ko) * | 2013-02-25 | 2015-10-30 | 퀄컴 인코포레이티드 | 사물 인터넷 (IoT) 디바이스들의 그룹들의 확립 및 디바이스들의 그룹들 간 통신의 인에이블링 |
| US20160156614A1 (en) * | 2014-11-28 | 2016-06-02 | Hcl Technologies Limited | Provisioning a device over an internet of things |
| KR20160146346A (ko) * | 2015-06-12 | 2016-12-21 | 삼성전자주식회사 | 전자 장치 및 그 연결 방법 |
| US20190364096A1 (en) * | 2009-12-17 | 2019-11-28 | Intel Corporation | Cloud Federation As A Service |
| KR20200098561A (ko) * | 2017-11-30 | 2020-08-20 | 모카나 코포레이션 | 연결된 엔드포인트 장치의 가입 및 등록을 위한 장치 식별 시스템 및 방법, 그리고 블록 체인 서비스 |
Family Cites Families (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| PL3114884T3 (pl) * | 2014-03-07 | 2020-05-18 | Ubiquiti Inc. | Uwierzytelnianie i identyfikacja urządzenia w chmurze |
| US10638417B1 (en) * | 2015-12-23 | 2020-04-28 | Amazon Technologies, Inc. | Cloud-based provisioning using peer devices |
| KR102816413B1 (ko) * | 2016-12-07 | 2025-06-04 | 삼성전자주식회사 | 디바이스를 클라우드 서버에 등록시키는 방법 및 장치 |
| US11509644B2 (en) * | 2017-07-05 | 2022-11-22 | Intel Corporation | Establishing connections between IOT devices using authentication tokens |
| WO2020089724A1 (en) * | 2018-11-01 | 2020-05-07 | 3M Innovative Properties Company | Device, user, or server registration and verification |
| US20200287905A1 (en) * | 2019-03-06 | 2020-09-10 | Angaza Design, Inc. | Devices, systems, and methods for controlling user rights in electrical appliances |
| US10924920B2 (en) * | 2019-04-22 | 2021-02-16 | Afero, Inc. | System and method for internet of things (IoT) device validation |
| CN111917810B (zh) * | 2019-05-09 | 2022-09-23 | Oppo广东移动通信有限公司 | 一种云通信方法及装置、用户设备、网络设备 |
| US11758396B2 (en) * | 2020-04-07 | 2023-09-12 | Schlage Lock Company Llc | Bluetooth device authentication over Bluetooth advertisements |
-
2021
- 2021-11-25 US US18/038,426 patent/US12418424B2/en active Active
- 2021-11-25 WO PCT/KR2021/017482 patent/WO2022124652A1/ko not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20190364096A1 (en) * | 2009-12-17 | 2019-11-28 | Intel Corporation | Cloud Federation As A Service |
| KR20150122199A (ko) * | 2013-02-25 | 2015-10-30 | 퀄컴 인코포레이티드 | 사물 인터넷 (IoT) 디바이스들의 그룹들의 확립 및 디바이스들의 그룹들 간 통신의 인에이블링 |
| US20160156614A1 (en) * | 2014-11-28 | 2016-06-02 | Hcl Technologies Limited | Provisioning a device over an internet of things |
| KR20160146346A (ko) * | 2015-06-12 | 2016-12-21 | 삼성전자주식회사 | 전자 장치 및 그 연결 방법 |
| KR20200098561A (ko) * | 2017-11-30 | 2020-08-20 | 모카나 코포레이션 | 연결된 엔드포인트 장치의 가입 및 등록을 위한 장치 식별 시스템 및 방법, 그리고 블록 체인 서비스 |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2024216639A1 (zh) * | 2023-04-21 | 2024-10-24 | Oppo广东移动通信有限公司 | 接入网络的方法及装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| US20240097901A1 (en) | 2024-03-21 |
| US12418424B2 (en) | 2025-09-16 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2022124652A1 (ko) | 스마트홈 환경의 무선랜 시스템에서 c2c 연결을 기반으로 iot 제어기기와 iot 피제어기기 간 등록을 설정하는 방법 및 장치 | |
| WO2020149718A1 (en) | Method and apparatus for access control in wireless communication system | |
| WO2022025614A1 (ko) | 스마트홈 환경의 무선랜 시스템에서 다중 제어기를 설정하는 방법 및 장치 | |
| WO2014200240A1 (en) | Method and apparatus for registering wireless device in wireless communication system | |
| WO2016148534A1 (en) | Method and apparatus for configuring connection between devices in communication system | |
| EP3878163A1 (en) | Seal system and method for provisioning inter-services communication in seal system of wireless communication network | |
| WO2020130582A1 (en) | Electronic device and method for controlling electronic device | |
| WO2020101348A1 (en) | Apparatus and method for flexible operational structures for uwb devices | |
| WO2022158637A1 (ko) | 무선통신 시스템에서 액세스 포인트의 정보를 제공하는 전자 장치 및 그 방법 | |
| WO2022010260A1 (ko) | 무선 통신 시스템에서 멀티 링크 셋업 | |
| WO2022220584A1 (ko) | 전자 장치 및 전자 장치에서 외부 전자 장치의 클라우드 온보딩을 수행하는 방법 | |
| WO2020166952A1 (en) | Method and apparatus for measurement report in wireless communication system | |
| WO2022025717A1 (en) | Method and apparatus for handling resource collision between multiple networks in wireless communication system | |
| WO2016072781A1 (en) | Bootstrapping wi-fi direct communication by a trusted network entity | |
| WO2020222592A1 (en) | Method and apparatus for direct link management in wireless communication system | |
| EP3459274A1 (en) | Method and apparatus for communication in wireless communication system | |
| WO2019199084A1 (ko) | 무선 통신 시스템에서 단말 및 이의 제어 방법 | |
| WO2022119232A1 (ko) | 스마트홈 환경의 무선랜 시스템에서 c2c의 계정 연동을 기반으로 iot 기기를 다중 제어하는 방법 및 장치 | |
| WO2022225195A1 (ko) | 무선 네트워크에서 장치 프로비져닝을 위한 전자 장치 및 그 동작 방법 | |
| EP4183123A1 (en) | Methods and systems for aggregating and exchanging messages in an iot communication system | |
| WO2023219234A1 (ko) | 피제어 장치를 관리하는 전자 장치 및 그 동작 방법 | |
| WO2020153807A1 (en) | Method and apparatus for load and mobility control in wireless communication system | |
| US12150020B2 (en) | Method and apparatus for acquiring information of chip device using gas in wireless LAN system in smart home environment | |
| WO2017007146A1 (en) | Communication device, communication method, and communication system | |
| WO2022260395A1 (ko) | 스마트홈 환경의 무선랜 시스템에서 제어기기가 미디어 데이터를 획득하고 분석하여 피제어기기를 제어하는 방법 및 장치 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 21903698 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 18038426 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21903698 Country of ref document: EP Kind code of ref document: A1 |
|
| WWG | Wipo information: grant in national office |
Ref document number: 18038426 Country of ref document: US |