Device authentication method, device, system, terminal device and storage medium

Verifying the second token generated by the authentication server of the terminal device through the cloud server solves the problem of inconsistent access processes and high complexity caused by the diversified authentication methods of IoT devices, and realizes the effect of unified authentication processes and reducing complexity.

CN112417425BActive Publication Date: 2025-08-08TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202011416308.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-03
Publication Date
2025-08-08
Estimated Expiration
2040-12-03

AI Technical Summary

Technical Problem

The diversified authentication methods of IoT devices lead to inconsistent access authentication processes and high complexity, making it difficult to achieve safe and effective management.

Method used

The second token of the terminal device is verified through a cloud server. The token is generated by the authentication server based on a variety of authentication information, unifying the authentication process and reducing complexity.

Benefits of technology

It realizes the unified authentication method when IoT devices are connected to cloud servers, reducing authentication complexity and improving security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112417425B_ABST
    Figure CN112417425B_ABST
Patent Text Reader

Abstract

The present application provides a device authentication method, apparatus, system, terminal and storage medium, which belongs to the field of Internet of Things technology. The method includes: sending a first data acquisition request to a cloud server; in response to an unauthorized access response, sending a token acquisition request to an authentication server, the token acquisition request carries a tenant identifier, a device unique identifier and a first token, the tenant identifier is used to indicate the tenant account to which the terminal device belongs, and the first token uniquely corresponds to the tenant account; and receiving a second token returned by the authentication server. In the above technical solution, when the terminal device requests data from the cloud server, the cloud server verifies the second token of the terminal device. Since the second token is generated by the authentication server based on multiple authentication information of the terminal device, the second token is both credible and the authentication method when accessing the cloud server is unified to verify the second token, which unifies the access process and reduces complexity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet of Things technology, and in particular to a device authentication method, apparatus, system, terminal device, and storage medium. Background Art

[0002] With the development of IoT technology, embedded devices, mobile terminals, cameras, and in-vehicle equipment have brought tremendous convenience to our lives. However, the increasing number of devices and product types has made it increasingly difficult for IoT companies to securely and effectively manage device authentication. Device authentication is a critical process involving data security. Therefore, providing IoT companies with secure and effective device authentication solutions is an urgent issue.

[0003] Currently, IoT devices use a one-machine-one-key approach when connecting to the IoT platform. IoT devices are authenticated based on a unique pre-programmed device certificate. Once authentication is passed, they can interact with the IoT platform.

[0004] The problem with the above solution is that due to the system differences between IoT devices produced by different IoT companies, the requirements of the above devices for transmission protocols and security authentication are diversified. As a result, different IoT devices have different authentication methods, resulting in inconsistent and complex processes for IoT device access authentication. Summary of the Invention

[0005] The embodiments of the present application provide a device authentication method, apparatus, system, terminal device, and storage medium. When a terminal device requests data from a cloud server, the cloud server verifies the terminal device's second token. Since the second token is generated by the authentication server based on multiple authentication information of the terminal device, the second token is both credible and unified with the authentication method for accessing the cloud server to verify the second token, thus unifying the access process and reducing complexity. The technical solution is as follows:

[0006] In one aspect, a device authentication method is provided, which is applied to a terminal device, and the method includes:

[0007] Sending a first data acquisition request to the cloud server;

[0008] In response to the unauthorized access response, sending a token acquisition request to the authentication server, the token acquisition request carrying a tenant identifier, a device unique identifier, and a first token, the tenant identifier being used to indicate the tenant account to which the terminal device belongs, and the first token being uniquely corresponding to the tenant account;

[0009] Receive a second token returned by the authentication server, where the second token is generated by the authentication server after the token acquisition request passes verification. The second token has a validity period and is used by the cloud server to verify the data acquisition request carrying the second token.

[0010] In another aspect, a device authentication method is provided, characterized in that it is applied to a device authentication system, the device authentication system including multiple terminal devices, an authentication server, and a cloud server, the method comprising:

[0011] For any terminal device, requesting service data from the cloud server based on the terminal device;

[0012] In response to the cloud server returning an unauthorized access response to the terminal device, sending a token acquisition request to the authentication server based on the terminal device, where the token acquisition request carries a tenant identifier, a unique device identifier of the terminal device, and a first token, where the tenant identifier is used to indicate the tenant account to which the terminal device belongs, and the first token uniquely corresponds to the tenant account;

[0013] generating, based on the authentication server receiving the token acquisition request sent by the terminal device, a second token having a validity period;

[0014] Based on the second data acquisition request carrying the second token sent by the terminal device, the cloud server returns business data to the terminal device.

[0015] In another aspect, a device authentication apparatus is provided, which is applied to a terminal device, and includes:

[0016] A first request sending module, configured to send a data acquisition request to a cloud server;

[0017] a second request sending module, configured to send a token acquisition request to the authentication server in response to an unauthorized access response, wherein the token acquisition request carries a tenant identifier, a unique device identifier, and a first token, wherein the tenant identifier is used to indicate the tenant account to which the terminal device belongs, and the first token uniquely corresponds to the tenant account;

[0018] A token receiving module is used to receive a second token returned by the authentication server. The second token is generated by the authentication server after the token acquisition request is verified. The second token has a validity period and is used by the cloud server to verify the data acquisition request carrying the second token.

[0019] In an optional implementation, the second request sending module is used to obtain the tenant identifier, the device unique identifier and the first token in response to an unauthorized access response; encrypt the tenant identifier, the device unique identifier, the first token and the timestamp to obtain signature information; combine the device unique identifier, the signature information, the tenant identifier and the timestamp to obtain the token acquisition request; and send the token acquisition request to the authentication server.

[0020] In an optional implementation, the apparatus further includes:

[0021] The first request sending module is further configured to send a second data acquisition request carrying the second token to the cloud server;

[0022] The data receiving module is used to receive the business data returned by the cloud server, and the business data is sent by the cloud server after determining that the second token is verified.

[0023] On the other hand, a device authentication system is provided, the device authentication system including a plurality of terminal devices, an authentication server, and a cloud server;

[0024] For any terminal device, the terminal device is used to request business data from the cloud server;

[0025] The terminal device is further configured to, in response to an unauthorized access response returned by the cloud server, send a token acquisition request to the authentication server, wherein the token acquisition request carries a tenant identifier, a unique device identifier of the terminal device, and a first token, wherein the tenant identifier is used to indicate the tenant account to which the terminal device belongs, and the first token uniquely corresponds to the tenant account;

[0026] The authentication server is configured to generate a second token having a validity period according to the token acquisition request sent by the terminal device;

[0027] The cloud server is used to return business data to the terminal device according to the data acquisition request carrying the second token sent by the terminal device.

[0028] In an optional implementation, the cloud server is configured to return business data to the terminal device according to the data acquisition request sent by the terminal device and carrying the second token, including:

[0029] In response to receiving the data acquisition request carrying the second token sent by the terminal device, the cloud server routes the data acquisition request to the authentication server for verification by the authentication server;

[0030] In response to receiving the verification pass response returned by the authentication server, the cloud server returns the business data to the terminal device according to the data acquisition request.

[0031] In an optional implementation, the cloud server includes: a console server, a device management server, a user management server, a tenant management server, and a database server;

[0032] The console server is used to provide background services for the console page, and the console page is used to provide a device management service entrance and a tenant management service entrance;

[0033] The device management server is used to provide a device management service, and the device management service is used to manage the multiple terminal devices;

[0034] The user management server is used to provide user management services, and the user management services are used to manage multiple tenant accounts using the cloud server;

[0035] The tenant management server is used to provide tenant management services, and the tenant management service is used to manage at least one terminal device corresponding to any tenant account.

[0036] On the other hand, a terminal device is provided, which includes a processor and a memory, the memory being used to store at least one computer program, and the at least one computer program being loaded and executed by the processor to implement the operations performed in the device authentication method in the embodiment of the present application.

[0037] On the other hand, a computer-readable storage medium is provided, in which at least one computer program is stored. The at least one computer program is loaded and executed by a processor to implement the operations performed in the device authentication method in the embodiment of the present application.

[0038] In another aspect, a computer program product or computer program is provided, comprising computer program code stored in a computer-readable storage medium. A processor of a terminal device reads the computer program code from the computer-readable storage medium and executes the computer program code, causing the terminal device to perform the device authentication method provided in any of the aforementioned aspects or various optional implementations of each aspect.

[0039] The beneficial effects of the technical solution provided by the embodiments of the present application are:

[0040] In an embodiment of the present application, a device authentication method is provided. When a terminal device requests data from a cloud server, the cloud server verifies the second token of the terminal device. Since the second token is generated by the authentication server based on multiple authentication information of the terminal device, the second token is both credible and the authentication method when accessing the cloud server is unified to verify the second token, thereby unifying the access process and reducing complexity. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0042] Figure 1 Schematic diagram of an implementation environment of a device authentication method provided according to an embodiment of the present application;

[0043] Figure 2 This is a flow chart of a device authentication method provided according to an embodiment of the present application;

[0044] Figure 3 This is a flow chart of a device authentication method provided according to an embodiment of the present application;

[0045] Figure 4 is a schematic diagram of a device authentication system provided according to an embodiment of the present application;

[0046] Figure 5 This is a schematic diagram of a tenant details page provided in an embodiment of the present application;

[0047] Figure 6 is a schematic diagram of a device management page provided according to an embodiment of the present application;

[0048] Figure 7 is a flowchart of another device authentication method provided according to an embodiment of the present application;

[0049] Figure 8 This is a block diagram of a device authentication apparatus provided according to an embodiment of the present application;

[0050] Figure 9 This is a structural block diagram of a terminal device provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0051] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0052] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.

[0053] The following is a brief introduction to the technologies that may be used in the embodiments of this application.

[0054] Cloud technology refers to a hosting technology that unifies hardware, software, and network resources within a wide area network (WAN) or local area network (LAN) to enable data computing, storage, processing, and sharing. Cloud technology is a general term for network technology, information technology, integration technology, management platform technology, and application technology based on the cloud computing business model. It can form a resource pool that can be used on demand with flexibility and convenience. Cloud computing technology will become a critical support. Backend services for technical network systems, such as video websites, image websites, and more portals, require extensive computing and storage resources. With the rapid development and application of the internet industry, every item will likely have its own unique identification mark and will need to be transmitted to backend systems for logical processing. Data of different levels will be processed separately, and data from all industries will require a strong system backend, which can only be achieved through cloud computing.

[0055] Cloud storage is a new concept that has been extended and developed from the concept of cloud computing. A distributed cloud storage system (hereinafter referred to as storage system) refers to a storage system that uses cluster applications, grid technology, and distributed storage file systems to bring together a large number of different types of storage devices (storage devices are also called storage nodes) in the network through application software or application interfaces to work together and provide external data storage and business access functions.

[0056] Currently, storage systems use the following storage method: creating logical volumes. When creating a logical volume, physical storage space is allocated for each logical volume. This physical storage space may consist of disks on a specific storage device or several storage devices. When a client stores data on a logical volume, it stores the data on a file system. The file system divides the data into many parts, each of which is an object. An object contains not only the data but also additional information such as the data identifier (ID). The file system writes each object to the physical storage space of the logical volume and records the storage location information of each object. Therefore, when a client requests access to data, the file system can allow the client to access the data based on the storage location information of each object.

[0057] The storage system allocates physical storage space to the logical volume in the following ways: according to the estimated capacity of the objects stored in the logical volume (this estimate is often relatively large compared to the actual capacity of the objects to be stored) and the Redundant Array of Independent Disks (RAID) The physical storage space is divided into stripes in advance by using the group of Independent Disks. A logical volume can be understood as a stripe, thereby allocating physical storage space to the logical volume.

[0058] The Internet of Things (IoT) refers to the use of various devices and technologies, including information sensors, radio frequency identification (RFID), global positioning systems (GPS), infrared sensors, and laser scanners, to collect real-time information on any object or process that requires monitoring, connection, and interaction. This information includes acoustic, optical, thermal, electrical, mechanical, chemical, biological, and location information. Through various network access options, this enables ubiquitous connectivity between objects and between objects and people, enabling intelligent perception, identification, and management of objects and processes. The IoT is an information carrier based on the internet and traditional telecommunications networks, enabling all independently addressable, common physical objects to form an interconnected network.

[0059] Cloud IoT aims to connect the information sensed and instructions received by sensor devices in traditional IoT to the Internet, truly realizing networking and enabling massive data storage and computing through cloud computing technology. Since the characteristic of IoT is that things are connected to each other and the current operating status of each "object" is perceived in real time, a large amount of data information will be generated in this process. How to aggregate this information and how to filter useful information from the massive amount of information to support decision-making for subsequent development have become key issues affecting the development of IoT. Therefore, IoT Cloud based on cloud computing and cloud storage technology has become a strong support for IoT technology and applications.

[0060] Cloud security refers to the security software, hardware, users, organizations, and cloud platforms used in cloud computing business models. It integrates emerging technologies and concepts such as parallel processing, grid computing, and the identification of unknown virus behaviors. Through a network of numerous clients, cloud security monitors software anomalies on the network, obtains the latest information on Trojans and malicious programs on the internet, transmits it to servers for automatic analysis and processing, and then distributes virus and Trojan solutions to every client.

[0061] The main research directions of cloud security include: 1. Cloud computing security, which focuses on how to ensure the security of the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, compliance auditing, etc.; 2. Cloudification of security infrastructure, which focuses on how to use cloud computing to build and integrate security infrastructure resources and optimize security protection mechanisms, including building ultra-large-scale security event, information collection and processing platforms through cloud computing technology, realizing the collection and correlation analysis of massive amounts of information, and improving the ability to control security incidents and risks across the entire network; 3. Cloud security services, which focuses on various security services provided to users based on cloud computing platforms, such as antivirus services.

[0062] MD5 Message-Digest Algorithm (English: MD5 Message-Digest Algorithm), a widely used cryptographic hash function, can generate a 128-bit (16-byte) hash value to ensure the integrity and consistency of information transmission.

[0063] JWT (Json Web Token) is a JSON-based open standard (RFC 7519) for transmitting claims between network application environments. The token is designed to be compact and secure, and is particularly suitable for single sign-on (SSO) scenarios on distributed sites. JWT claims are generally used to transmit authenticated user identity information between identity providers and service providers to facilitate the acquisition of resources from resource servers. It can also add some additional claim information required by other business logic. The token can also be used directly for authentication or encrypted.

[0064] The following introduces the implementation environment of the device authentication method provided in the embodiment of the present application. The device authentication method is applied to the device authentication system provided in the embodiment of the present application. Figure 1 This is a schematic diagram of the implementation environment of the device authentication method provided in accordance with the embodiment of the present application. Figure 1 The implementation environment includes multiple terminal devices 101, an authentication server 102 and a cloud server 103.

[0065] The terminal device 101 and the authentication server 102 can be connected directly or indirectly via wired or wireless communication, which is not limited in this application.

[0066] Optionally, terminal 101 is a smartphone, tablet computer, laptop computer, desktop computer, smart speaker, smart watch, camera, or in-vehicle device, but is not limited thereto. Terminal 101 has an application installed and running. Illustratively, terminal device 101 is a terminal device used by a user, through which the user accesses various services provided by an IoT device service provider, such as navigation services, positioning services, monitoring services, and autonomous driving services.

[0067] Optionally, authentication server 102 is an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. Authentication server 102 is used to provide device authentication services for applications installed on terminal device 101.

[0068] The terminal device 101 and the cloud server 103 can be connected directly or indirectly via wired or wireless communication, which is not limited in this application.

[0069] Optionally, the cloud server 102 is an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The cloud server 103 is used to provide background services for applications installed on the terminal device 101. Optionally, the cloud server 103 can undertake the main computing work and the terminal device 101 can undertake the secondary computing work; or, the cloud server 103 undertakes the secondary computing work and the terminal device 101 undertakes the main computing work; or, the cloud server 103 and the terminal device 101 adopt a distributed computing architecture for collaborative computing.

[0070] Those skilled in the art will appreciate that the number of the terminal devices 101 can be greater or less. For example, there can be only one terminal device, or there can be dozens, hundreds, or even more terminal devices. The present embodiment does not limit the number and type of terminal devices.

[0071] Optionally, the above-mentioned wireless network or wired network uses standard communication technologies and / or protocols. The network is typically the Internet, but can also be any network, including but not limited to a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or any combination of a virtual private network). In some embodiments, technologies and / or formats including Hypertext Markup Language (HTML), Extensible Markup Language (XML), etc. are used to represent data exchanged over the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPsec), etc. can be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above-mentioned data communication technologies.

[0072] Figure 2 This is a flow chart of a device authentication method provided according to an embodiment of the present application. Figure 2 As shown, in the embodiment of the present application, the application is taken as an example to illustrate the application of the terminal device. The device authentication method includes the following steps:

[0073] 201. The terminal device sends a first data acquisition request to the cloud server.

[0074] In the embodiment of the present application, the terminal device is an Internet of Things device that can exchange data with a cloud server. Optionally, the terminal device is an embedded device, a mobile terminal, a camera, and a vehicle-mounted device, etc., which is not limited in the embodiment of the present application.

[0075] 202. In response to the unauthorized access response, the terminal device sends a token acquisition request to the authentication server. The token acquisition request carries a tenant identifier, a device unique identifier, and a first token. The tenant identifier is used to indicate the tenant account to which the terminal device belongs, and the first token uniquely corresponds to the tenant account.

[0076] In an embodiment of the present application, if the first data acquisition request sent by the terminal device fails to pass verification, it will receive an unauthorized access response from the end server. At this time, the terminal device can obtain a second token for authentication by sending a token acquisition request to the authentication server. When obtaining the second token, the terminal device needs to provide relevant information proving its legitimacy, such as the tenant identifier, device unique identifier, and first token, so that the authentication server can return the second token after determining that the terminal device is safe and legal.

[0077] 203. The terminal device receives a second token returned by the authentication server. The second token is generated by the authentication server after the token acquisition request passes verification. The second token has a validity period and is used by the cloud server to verify the data acquisition request carrying the second token.

[0078] In an embodiment of the present application, the authentication server can verify the information contained in the token acquisition request. If the verification fails, the terminal device receives an authentication failure response. If the verification succeeds, the terminal device receives a dynamic second token. This second token has an expiration date, meaning it is valid for a certain period of time, such as 10 minutes, 24 hours, 72 hours, one week, or one month. This embodiment of the present application does not impose any restrictions on the length of this validity period.

[0079] It should be noted that after the terminal device obtains the second token, it can send a second data acquisition request carrying the second token to the cloud server, and then receive the business data returned by the cloud server. The business data is sent by the cloud server after determining that the second token is verified.

[0080] In an embodiment of the present application, a device authentication method is provided. When a terminal device requests data from a cloud server, the cloud server verifies the second token of the terminal device. Since the second token is generated by the authentication server based on multiple authentication information of the terminal device, the second token is both credible and the authentication method when accessing the cloud server is unified to verify the second token, thereby unifying the access process and reducing complexity.

[0081] An embodiment of the present application also provides a device authentication system, in which the above-mentioned device authentication method is applied, and the authentication system includes multiple terminal devices, an authentication server, and a cloud server. For any terminal device, the terminal device is used to request business data from the above-mentioned cloud server. The terminal device is also used to send a token acquisition request to the authentication server in response to the unauthorized access response returned by the cloud server, and the token acquisition request carries a tenant identifier, a unique device identifier of the terminal device, and a first token. The tenant identifier is used to indicate the tenant account to which the terminal device belongs, and the first token uniquely corresponds to the tenant account. The terminal device is also used to send a token acquisition request to the authentication server, and accordingly, the authentication server is used to generate a second token with a validity period based on the token acquisition request sent by the terminal device. After the terminal device obtains the second token through the above-mentioned device authentication method, it can send a second data acquisition request carrying the second token to the cloud server, and accordingly, the cloud server is used to return business data to the terminal device based on the second data acquisition request carrying the second token sent by the terminal device.

[0082] The following is a detailed description of the device authentication method provided by the embodiment of the present application based on a specific application scenario. The device authentication method is applied to a device authentication system, which is a universal cloud access authentication platform that supports multiple tenants. The device authentication system includes multiple terminal devices, an authentication server, and a cloud server. Optionally, the cloud server includes a console server, a device management server, a user management server, a tenant management server, and a database server. See Figure 3 As shown, Figure 3 This is a flow chart of a device authentication method provided according to an embodiment of the present application. Figure 3 As shown, in the embodiment of the present application, the device authentication system is used as an example for explanation. The device authentication method includes the following steps:

[0083] 301. For any terminal device, the terminal device sends a first data acquisition request to the cloud server.

[0084] In the embodiment of the present application, the terminal device is any IoT device capable of exchanging data with a cloud server. Optionally, the terminal device may be an embedded device, a mobile terminal, a camera, or an in-vehicle device, etc., which is not limited in the embodiment of the present application. The terminal device can obtain business data from the cloud server by sending a first data acquisition request to the cloud server. Optionally, the business data obtained by the terminal device is stored in a database server included in the cloud server.

[0085] For example, the terminal device is a vehicle-mounted device, which can upload driving data to the cloud server and download business data such as positioning information, map information, and update packages from the cloud server.

[0086] It should be noted that each time a terminal device requests business data from a cloud server, it must include authentication information such as a token in the data request. If the terminal device fails to submit authentication information, submits incorrect authentication information, or submits expired authentication information, resulting in authentication failure, the terminal device will receive a denied access response from the cloud server. If the terminal device submits correct, unexpired authentication information and passes verification, the terminal device will receive the business data returned by the cloud server.

[0087] 302. In response to the unauthorized access response returned by the cloud server, the terminal device sends a token acquisition request to the authentication server. The token acquisition request carries a tenant identifier, a device unique identifier, and a first token. The tenant identifier is used to indicate the tenant account to which the terminal device belongs, and the first token uniquely corresponds to the tenant account.

[0088] In an embodiment of the present application, in response to a terminal device receiving a "no access" response from a cloud server, the terminal device obtains a tenant identifier, a unique device identifier, and a first token. The terminal device then encrypts the tenant identifier, the unique device identifier, the first token, and a timestamp to obtain signature information. The terminal device then combines the unique device identifier, the signature information, the tenant identifier, and the timestamp to obtain a token acquisition request. Finally, the terminal device sends the token acquisition request to the authentication server.

[0089] It should be noted that the tenant identifier, device unique identifier, and first token are stored in the terminal device by burning or other means when the terminal device leaves the factory. Each tenant of the cloud server corresponds to a first token, and different tenants have different first tokens. The first token is generated for the tenant by the authentication server when the terminal device is registered.

[0090] For example, when registering, a tenant needs to fill in the tenant's tenant ID, tenant's email address and password and other information. The tenant ID is represented as TenantID. After successful registration, the authentication server generates a corresponding first token for the tenant, namely a static Token, which is similar to a key. The unique device identifier of the terminal device is the SN information of the terminal device, namely deviceID. Before requesting access to the cloud server, the terminal device encrypts the TenantID, static Token, deviceID and timestamp into signature information using the MD5 encryption algorithm. The combined token acquisition request is sent to the dynamic Token acquisition interface provided by the authentication server. The combined token acquisition request is in the following form:

[0091]

[0092] 303. The authentication server generates a second token with a validity period according to the token acquisition request sent by the terminal device.

[0093] In an embodiment of the present application, after receiving the token acquisition request sent by the terminal device, the authentication server verifies the device unique identifier and signature information of the terminal device at the same time. In response to the authentication server determining that the terminal device corresponding to the device unique identifier has been registered and the content included in the signature information is legal, the authentication server determines that the token acquisition request has passed the verification, generates a second token with a validity period, and then returns the second token to the terminal device. In response to the authentication server determining that the terminal device corresponding to the unique identifier has not been registered, or the content included in the signature information is illegal, the authentication server determines that the token acquisition request has not passed the verification. For example, the tenant identifier, the device unique identifier, and the first token do not correspond to each other. Among them, the validity period of the second token can be set according to actual needs, such as 10 minutes, 24 hours, 72 hours, one week, and 1 month, etc. The embodiment of the present application does not limit the length of the validity period.

[0094] For example, the second token includes the applicable service name, port number, log level, database information, JWT information, cache setting information, and tenant information. The second token is in the following form:

[0095]

[0096] 304. The terminal device receives the second token returned by the authentication server, and sends a second data acquisition request carrying the second token to the cloud server.

[0097] In an embodiment of the present application, the terminal device generates a second data acquisition request carrying the second token and the service identifier based on the received second token, and then sends the second data acquisition request to the cloud server.

[0098] 305. In response to receiving the second data acquisition request carrying the second token sent by the terminal device, the cloud server routes the second data acquisition request to the authentication server.

[0099] In an embodiment of the present application, after receiving the above-mentioned second data acquisition request sent by the terminal device, the cloud server routes the second data acquisition request to the dynamic token verification interface of the authentication server, and the authentication server verifies the second token.

[0100] 306. The authentication server verifies the second data acquisition request.

[0101] In an embodiment of the present application, the authentication server verifies the received second data acquisition request. If the second token in the second data acquisition request passes the verification, a verification pass response is returned to the cloud server; if the second token in the second data acquisition request fails the verification, such as the token has expired, the token does not match the terminal device, the token content is incorrect, etc., a verification failure response is returned to the cloud server.

[0102] It should be noted that the authentication server can cache the second token that has been verified, so as to avoid the problem that the terminal device has to be routed to the dynamic token verification interface of the authentication server every time it requests data from the cloud server. Frequent interface access puts pressure on the authentication server. The authentication server does not need to query the database every time it verifies, which saves the resources of the authentication server and makes the authentication server more stable.

[0103] 307. In response to receiving the verification pass response returned by the authentication server, the cloud server returns the business data to the terminal device according to the second data acquisition request.

[0104] In the embodiment of the present application, the cloud server receives a verification pass response, indicating that the terminal device has access rights, and the cloud server can return the business data requested by the terminal device.

[0105] It should be noted that, in response to receiving the verification failure response returned by the authentication server, the cloud server returns the verification failure response to the terminal device.

[0106] 308. The terminal device receives the business data returned by the cloud server.

[0107] In an embodiment of the present application, the terminal device can receive business data returned by the cloud server and display or subsequently process it, and this embodiment of the present application does not limit this.

[0108] It should be noted that the above steps 301 to 308 are optional implementation methods of the device authentication method provided in the embodiment of the present application. Accordingly, there are other optional implementation methods. Optionally, the above-mentioned cloud server includes: a console server, a device management server, a user management server, a tenant management server and a database server. The console server is used to provide background services for the console page, and the console page is used to provide a device management service entrance and a tenant management service entrance. The device management server is used to provide device management services, and the device management service is used to manage the multiple terminal devices. The user management server is used to provide user management services, and the user management service is used to manage multiple tenant accounts using the cloud server. The tenant management server is used to provide tenant management services, and the tenant management service is used to manage at least one terminal device corresponding to any tenant account. The database server is used to provide data management services to the console server, device management server, user management server, and tenant management server. The authentication server is used to provide access authentication services for terminal devices.

[0109] For example, see Figure 4 As shown, Figure 4 Schematic diagram of a device authentication system provided according to an embodiment of the present application. Figure 4 As shown, when registering, a terminal device sends a device access request to the access authentication service provided by authentication server 401. Authentication server 401 then stores the terminal device's SN information and the tenant identifier of the tenant to which the terminal device belongs in a corresponding manner in database server 402. Administrator users can use the console page provided by console server 403 to perform operations such as batch device SN import and deletion, tenant registration management, and tenant login management. Batch device SN import and deletion is implemented using the device SN management service provided by device management server 404, which is based on database server 402. Tenant registration management and tenant login management are implemented using the user management service provided by user management server 405, which is based on database server 402. Furthermore, for a single tenant account, the administrator user can use the tenant management service provided by tenant management server 406, which is based on database server 402, to manage at least one terminal device corresponding to the tenant account. Optionally, the administrator user logs in to the console page using a username and password. The administrator account of the administrator user has the highest permissions and can perform operations such as tenant management, device authorization, and device deauthorization.

[0110] Optionally, administrator users can view the information of each tenant from the tenant dimension through the tenant management service portal in the console page provided by the console server. The tenant management service portal is used to enter the tenant management page, where administrator users can approve tenant registration requests and click on any tenant to enter the tenant details page to view the tenant details of the tenant. For example, see Figure 5 As shown, Figure 5 This is a schematic diagram of a tenant details page provided in an embodiment of the present application. Figure 5 As shown, the tenant details page includes the tenant identifier, the tenant's mailbox, and the tenant's first token, and optionally, also includes a unique device identifier of at least one terminal device belonging to the tenant.

[0111] Optionally, the administrator user can also view the information of each terminal device from the terminal device dimension through the device management service entrance in the console page provided by the console server. For example, see Figure 6 As shown, Figure 6 This is a schematic diagram of a device management page provided according to an embodiment of the present application. Through this device management page, administrators can register, unbind, and search for devices. 601 indicates that when registering a device, administrators must enter the tenant ID of the device and the device's unique device ID. 602 indicates that when searching for a device, administrators can use the device's unique device ID to find the tenant ID of the tenant to which the device belongs. They can also search for other device information, such as its location, registration time, and access logs.

[0112] It should be noted that, unlike the prior art scheme in which terminal devices are authenticated by the authentication method set by the tenant themselves, the device authentication method provided in the embodiment of the present application, by dividing the authentication process into two steps: token acquisition and data acquisition, unifies the device authentication method to be performed by the system's authentication server based on a second token with a time limit. That is, instead of each tenant performing different authentication methods, the system layer that manages the tenants performs unified authentication, which not only unifies the authentication process but also simplifies the complexity of authentication. Moreover, by authenticating with the second token, even if the tenant's first token is leaked, malicious devices cannot use the first token to defraud data from the cloud server, thus ensuring data security.

[0113] For example, see Figure 7 As shown, Figure 7 This is a flow chart of another device authentication method provided according to an embodiment of the present application. Figure 7As shown, 701: During registration, the terminal device obtains a static token from the authentication server and pre-installs it in the terminal device. 702: The device SN and static token are encrypted and used as parameters to request a dynamic token from the authentication server. 703: The console server batch adds the SNs of accessible devices, and the authentication server determines access permissions based on the device SNs. 704: The request for a dynamic token fails, indicating no access permissions; the request for a dynamic token succeeds, indicating access permissions. 705: The authentication server returns the dynamic token. 706: The terminal device accesses the cloud server with the dynamic token. 706: The cloud server routes the dynamic token value to the authentication server to verify the validity of the dynamic token.

[0114] In an embodiment of the present application, a device authentication method is provided. When a terminal device requests data from a cloud server, the cloud server verifies the second token of the terminal device. Since the second token is generated by the authentication server based on multiple authentication information of the terminal device, the second token is both credible and the authentication method when accessing the cloud server is unified to verify the second token, thereby unifying the access process and reducing complexity.

[0115] Figure 8 This is a block diagram of a device authentication apparatus according to an embodiment of the present application. The apparatus is used to execute the steps of the above-mentioned device authentication method. Figure 8 The device includes: a first request sending module 801, a second request sending module 802, and a token receiving module 803.

[0116] A first request sending module 801 is used to send a data acquisition request to a cloud server;

[0117] A second request sending module 802 is configured to send a token acquisition request to the authentication server in response to an unauthorized access response, wherein the token acquisition request carries a tenant identifier, a unique device identifier, and a first token, wherein the tenant identifier is used to indicate the tenant account to which the terminal device belongs, and the first token uniquely corresponds to the tenant account;

[0118] The token receiving module 803 is used to receive the second token returned by the authentication server. The second token is generated by the authentication server after the token acquisition request is verified. The second token has a validity period and is used by the cloud server to verify the data acquisition request carrying the second token.

[0119] In one possible implementation, the second request sending module 802 is used to obtain the tenant identifier, the device unique identifier and the first token in response to the unauthorized access response; encrypt the tenant identifier, the device unique identifier, the first token and the timestamp to obtain signature information; combine the device unique identifier, the signature information, the tenant identifier and the timestamp to obtain the token acquisition request; and send the token acquisition request to the authentication server.

[0120] In one possible implementation, the device further includes:

[0121] The first request sending module 801 is further configured to send a second data acquisition request carrying the second token to the cloud server;

[0122] The data receiving module is used to receive the business data returned by the cloud server, and the business data is sent by the cloud server after determining that the second token verification is passed.

[0123] In an embodiment of the present application, a device authentication method is provided. When a terminal device requests data from a cloud server, the cloud server verifies the second token of the terminal device. Since the second token is generated by the authentication server based on multiple authentication information of the terminal device, the second token is both credible and the authentication method when accessing the cloud server is unified to verify the second token, thereby unifying the access process and reducing complexity.

[0124] It should be noted that the device authentication apparatus provided in the above embodiments uses the aforementioned functional modules as examples for device authentication. In actual applications, the aforementioned functions can be assigned to different functional modules as needed, i.e., the internal structure of the apparatus can be divided into different functional modules to perform all or part of the functions described above. Furthermore, the device authentication apparatus and the device authentication method provided in the above embodiments share the same concept. The specific implementation process is detailed in the method embodiments and will not be further described here.

[0125] Figure 9 The following is a block diagram of a terminal device 900 according to an embodiment of the present application. Terminal device 900 may be a portable mobile terminal, such as a smartphone, tablet computer, MP3 player (Moving Picture Experts Group Audio Layer III), MP4 player (Moving Picture Experts Group Audio Layer IV), laptop computer, or desktop computer. Terminal device 900 may also be referred to as user equipment, portable terminal, laptop terminal, desktop terminal, or other similar names.

[0126] Typically, the terminal device 900 includes a processor 901 and a memory 902 .

[0127] The processor 901 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 901 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor 901 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 901 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 901 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.

[0128] The memory 902 may include one or more computer-readable storage media, which may be non-transitory. The memory 902 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash memory storage devices. In some embodiments, the non-transitory computer-readable storage medium in the memory 902 is used to store at least one computer program, which is executed by the processor 901 to implement the device authentication method provided in the method embodiment of the present application.

[0129] In some embodiments, the terminal device 900 may also optionally include a peripheral device interface 903 and at least one peripheral device. The processor 901, memory 902, and peripheral device interface 903 may be connected via a bus or signal lines. Each peripheral device may be connected to the peripheral device interface 903 via a bus, signal lines, or circuit boards. Specifically, the peripheral device includes at least one of a radio frequency circuit 904, a display screen 905, a camera assembly 906, an audio circuit 907, and a power supply 909.

[0130] The peripheral device interface 903 can be used to connect at least one I / O (Input / Output)-related peripheral device to the processor 901 and the memory 902. In some embodiments, the processor 901, the memory 902, and the peripheral device interface 903 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 901, the memory 902, and the peripheral device interface 903 can be implemented on separate chips or circuit boards, which is not limited in this embodiment.

[0131] The RF circuit 904 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The RF circuit 904 communicates with communication networks and other communication devices via electromagnetic signals. The RF circuit 904 converts electrical signals into electromagnetic signals for transmission, or converts received electromagnetic signals into electrical signals. Optionally, the RF circuit 904 includes an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a user identity module card, and the like. The RF circuit 904 can communicate with other terminals via at least one wireless communication protocol. Such wireless communication protocols include, but are not limited to, the World Wide Web, metropolitan area networks, intranets, various generations of mobile communication networks (2G, 3G, 4G, and 5G), wireless local area networks, and / or WiFi (Wireless Fidelity) networks. In some embodiments, the RF circuit 904 may also include circuits related to Near Field Communication (NFC), which is not limited in this application.

[0132] The display screen 905 is used to display a user interface (UI). This UI may include graphics, text, icons, videos, or any combination thereof. When the display screen 905 is a touch screen display, it is also capable of collecting touch signals on or above the surface of the display screen 905. These touch signals can be input as control signals to the processor 901 for processing. In this case, the display screen 905 can also be used to provide virtual buttons and / or a virtual keyboard, also known as soft buttons and / or a soft keyboard. In some embodiments, there can be one display screen 905, disposed on the front panel of the terminal device 900; in other embodiments, there can be at least two display screens 905, disposed on different surfaces of the terminal device 900 or in a foldable design; in still other embodiments, the display screen 905 can be a flexible display, disposed on a curved or foldable surface of the terminal device 900. Furthermore, the display screen 905 can be configured as a non-rectangular irregular shape, i.e., a special-shaped screen. The display screen 905 can be made of materials such as LCD (Liquid Crystal Display) and OLED (Organic Light-Emitting Diode).

[0133] The camera assembly 906 is used to capture images or videos. Optionally, the camera assembly 906 includes a front camera and a rear camera. Typically, the front camera is arranged on the front panel of the terminal, and the rear camera is arranged on the back of the terminal. In some embodiments, there are at least two rear cameras, which are any one of a main camera, a depth of field camera, a wide-angle camera, and a telephoto camera, so as to realize the fusion of the main camera and the depth of field camera to realize the background blur function, the fusion of the main camera and the wide-angle camera to realize panoramic shooting and VR (Virtual Reality) shooting function or other fusion shooting functions. In some embodiments, the camera assembly 906 may also include a flash. The flash can be a monochrome temperature flash or a dual-color temperature flash. A dual-color temperature flash refers to a combination of a warm light flash and a cold light flash, which can be used for light compensation at different color temperatures.

[0134] The audio circuit 907 may include a microphone and a speaker. The microphone is used to collect sound waves from the user and the environment, and convert the sound waves into electrical signals to be input into the processor 901 for processing, or input into the radio frequency circuit 904 to achieve voice communication. For the purpose of stereo acquisition or noise reduction, there can be multiple microphones, which are respectively arranged in different parts of the terminal device 900. The microphone can also be an array microphone or an omnidirectional acquisition microphone. The speaker is used to convert the electrical signals from the processor 901 or the radio frequency circuit 904 into sound waves. The speaker can be a traditional thin film speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can not only convert the electrical signals into sound waves audible to humans, but also convert the electrical signals into sound waves inaudible to humans for purposes such as ranging. In some embodiments, the audio circuit 907 may also include a headphone jack.

[0135] The power supply 909 is used to power the various components in the terminal device 900. The power supply 909 can be AC power, DC power, a disposable battery, or a rechargeable battery. When the power supply 909 includes a rechargeable battery, the rechargeable battery can be a wired rechargeable battery or a wireless rechargeable battery. A wired rechargeable battery is a battery that is charged via a wired line, while a wireless rechargeable battery is a battery that is charged via a wireless coil. The rechargeable battery can also be used to support fast charging technology.

[0136] In some embodiments, the terminal device 900 further includes one or more sensors 910 , including but not limited to: an acceleration sensor 911 , a gyroscope sensor 912 , a pressure sensor 913 , an optical sensor 915 , and a proximity sensor 916 .

[0137] The accelerometer 911 can detect the magnitude of acceleration along the three coordinate axes of the coordinate system established by the terminal device 900. For example, the accelerometer 911 can be used to detect the components of gravity acceleration along the three coordinate axes. The processor 901 can control the display screen 905 to display the user interface in a landscape or portrait view based on the gravity acceleration signal collected by the accelerometer 911. The accelerometer 911 can also be used to collect game or user motion data.

[0138] The gyroscope sensor 912 can detect the body orientation and rotation angle of the terminal device 900. The gyroscope sensor 912 can work with the acceleration sensor 911 to collect the user's 3D movements of the terminal device 900. Based on the data collected by the gyroscope sensor 912, the processor 901 can implement the following functions: motion sensing (such as changing the UI based on the user's tilt operation), image stabilization during shooting, game control, and inertial navigation.

[0139] The pressure sensor 913 can be set on the side frame of the terminal device 900 and / or the lower layer of the display screen 905. When the pressure sensor 913 is set on the side frame of the terminal device 900, it can detect the user's grip signal of the terminal device 900, and the processor 901 performs left and right hand recognition or shortcut operations based on the grip signal collected by the pressure sensor 913. When the pressure sensor 913 is set on the lower layer of the display screen 905, the processor 901 controls the operable controls on the UI interface based on the user's pressure operation on the display screen 905. The operable controls include at least one of a button control, a scroll bar control, an icon control, and a menu control.

[0140] The optical sensor 915 is used to detect ambient light intensity. In one embodiment, the processor 901 can control the display brightness of the display screen 905 based on the ambient light intensity detected by the optical sensor 915. Specifically, when the ambient light intensity is high, the display brightness of the display screen 905 is increased; when the ambient light intensity is low, the display brightness of the display screen 905 is decreased. In another embodiment, the processor 901 can also dynamically adjust the shooting parameters of the camera assembly 906 based on the ambient light intensity detected by the optical sensor 915.

[0141] The proximity sensor 916, also known as a distance sensor, is typically located on the front panel of the terminal device 900. The proximity sensor 916 is used to detect the distance between the user and the front of the terminal device 900. In one embodiment, when the proximity sensor 916 detects that the distance between the user and the front of the terminal device 900 is gradually decreasing, the processor 901 controls the display screen 905 to switch from the screen-on state to the screen-off state. When the proximity sensor 916 detects that the distance between the user and the front of the terminal device 900 is gradually increasing, the processor 901 controls the display screen 905 to switch from the screen-off state to the screen-on state.

[0142] Those skilled in the art will understand that Figure 9 The structure shown in the figure does not constitute a limitation on the terminal device 900, and the terminal device 900 may include more or fewer components than shown in the figure, or combine certain components, or adopt a different component arrangement.

[0143] An embodiment of the present application also provides a computer-readable storage medium, which is applied to a terminal device, and the computer-readable storage medium stores at least one computer program, which is loaded and executed by a processor to implement the operations performed by the terminal device in the device authentication method of the above embodiment.

[0144] The present application also provides a computer program product or computer program, which includes computer program code stored in a computer-readable storage medium. A processor of a terminal reads the computer program code from the computer-readable storage medium and executes the computer program code, causing the terminal device to perform the device authentication method provided in the various optional implementations described above.

[0145] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.

[0146] The above description is merely an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A device authentication method, characterized in that: Applied to a terminal device, the method includes: Sending a first data acquisition request to the cloud server; In response to the unauthorized access response, obtain a tenant identifier, a device unique identifier and a first token; encrypt the tenant identifier, the device unique identifier, the first token and the timestamp to obtain signature information; combine the device unique identifier, the signature information, the tenant identifier and the timestamp to obtain a token acquisition request; send the token acquisition request to the authentication server; the tenant identifier is used to indicate the tenant account to which the terminal device belongs, the first token uniquely corresponds to the tenant account, each tenant has a first token corresponding to it, the first token is generated by the authentication server for the corresponding tenant when the terminal device is registered, the tenant identifier is information filled in when registering for the tenant, multiple terminal devices belonging to the same tenant account share a tenant identifier, the tenant identifier is used to distinguish tenants, and the device unique identifier is used to distinguish multiple devices of the tenant; receiving a second token returned by the authentication server, where the second token is generated by the authentication server after the token acquisition request passes verification, the second token having a validity period, which refers to a period of time during which the second token is valid, and the second token includes tenant information. When the tenant identifier, the device unique identifier, and the first token do not correspond to each other, the token acquisition request fails verification; Sending a second data acquisition request carrying the second token to the cloud server, so that the cloud server routes the second data acquisition request to the dynamic token verification interface of the authentication server, and the authentication server verifies the second token; Receive the business data returned by the cloud server, which is sent by the cloud server in response to receiving the verification response returned by the authentication server; the authentication server caches the second token that has passed the verification for use in the next data acquisition process.

2. A device authentication method, characterized in that: Applied to a device authentication system, the device authentication system includes multiple terminal devices, an authentication server, and a cloud server, and the method includes: For any terminal device, requesting service data from the cloud server based on the terminal device; In response to the cloud server returning an unauthorized access response to the terminal device, based on the terminal device, obtaining a tenant identifier, a device unique identifier and a first token; encrypting the tenant identifier, the device unique identifier, the first token and the timestamp to obtain signature information; combining the device unique identifier, the signature information, the tenant identifier and the timestamp to obtain a token acquisition request; sending the token acquisition request to the authentication server; the tenant identifier is used to indicate the tenant account to which the terminal device belongs, the first token uniquely corresponds to the tenant account, each tenant has a first token corresponding to it, the first token is generated by the authentication server for the corresponding tenant when the terminal device is registered, the tenant identifier is information filled in when registering for the tenant, multiple terminal devices belonging to the same tenant account share a tenant identifier, the tenant identifier is used to distinguish tenants, and the device unique identifier is used to distinguish multiple devices of the tenant; generating, based on the authentication server according to the token acquisition request sent by the terminal device, a second token with a validity period after the token acquisition request passes verification, wherein the validity period refers to a period of time during which the second token is valid, and the second token includes tenant information; when the tenant identifier, the device unique identifier, and the first token do not correspond to each other, the token acquisition request fails verification; In response to a second data acquisition request sent by the terminal device and carrying the second token, the cloud server routes the second data acquisition request to a dynamic token verification interface of the authentication server, and the authentication server verifies the second token; In response to the verification pass response returned by the authentication server, the business data is sent to the terminal device based on the cloud server; the authentication server caches the second token that has passed the verification for use in the next data acquisition process.

3. The method according to claim 2, characterized in that The cloud server includes: a console server, a device management server, a user management server, a tenant management server and a database server; the method further includes: Based on the console server, a backend service is provided for the console page, and the console page is used to provide a device management service entrance and a tenant management service entrance; Providing a device management service based on the device management server, wherein the device management service is used to manage the plurality of terminal devices; Providing a user management service based on the user management server, wherein the user management service is used to manage multiple tenant accounts using the cloud server; Providing a tenant management service based on the tenant management server, wherein the tenant management service is used to manage at least one terminal device corresponding to any tenant account; The database server provides data management services to the console server, device management server, user management server, and tenant management server.

4. A device authentication system, characterized in that: The device authentication system includes multiple terminal devices, an authentication server and a cloud server; For any terminal device, the terminal device is used to request business data from the cloud server; The terminal device is further configured to obtain a tenant identifier, a device unique identifier, and a first token in response to a no-access response returned by the cloud server; Encrypt the tenant identifier, the device unique identifier, the first token, and the timestamp to obtain signature information; Combine the device unique identifier, the signature information, the tenant identifier, and the timestamp to obtain a token acquisition request; Sending the token acquisition request to the authentication server; The tenant identifier is used to indicate the tenant account to which the terminal device belongs. The first token uniquely corresponds to the tenant account. Each tenant corresponds to a first token. The first token is generated by the authentication server for the corresponding tenant when the terminal device is registered. The tenant identifier is information filled in when registering a tenant. Multiple terminal devices belonging to the same tenant account share a tenant identifier. The tenant identifier is used to distinguish tenants. The device unique identifier is used to distinguish multiple devices of a tenant. The authentication server is configured to generate, based on a token acquisition request sent by the terminal device, a second token having a validity period after the token acquisition request passes verification, wherein the validity period refers to a period of time during which the second token is valid, and the second token includes tenant information. When the tenant identifier, the device unique identifier, and the first token do not correspond to each other, the token acquisition request fails verification; The cloud server is configured to respond to a second data acquisition request sent by the terminal device and carrying the second token, and route the second data acquisition request to the dynamic token verification interface of the authentication server, so that the authentication server verifies the second token; In response to a verification pass response returned by the authentication server, sending service data to the terminal device; The authentication server caches the verified second token for use in the next data acquisition process.

5. A device authentication apparatus, characterized in that: Applied to a terminal device, the device includes: A first request sending module, configured to send a first data acquisition request to a cloud server; The second request sending module is used to obtain the tenant identifier, the device unique identifier and the first token in response to the unauthorized access response; encrypt the tenant identifier, the device unique identifier, the first token and the timestamp to obtain signature information; combine the device unique identifier, the signature information, the tenant identifier and the timestamp to obtain a token acquisition request; and send the token acquisition request to the authentication server; the tenant identifier is used to indicate the tenant account to which the terminal device belongs, the first token is uniquely corresponding to the tenant account, each tenant has a first token corresponding to the first token, the first token is generated by the authentication server for the corresponding tenant when the terminal device is registered, the tenant identifier is the information filled in when registering for the tenant, multiple terminal devices belonging to the same tenant account share a tenant identifier, the tenant identifier is used to distinguish tenants, and the device unique identifier is used to distinguish multiple devices of the tenant; a token receiving module, configured to receive a second token returned by the authentication server, the second token being generated by the authentication server after the token acquisition request passes verification, the second token having a validity period, which refers to a period of time during which the second token is valid, and the second token including tenant information. When the tenant identifier, the device unique identifier, and the first token do not correspond to each other, the token acquisition request fails verification; The first request sending module is further configured to send a second data acquisition request carrying the second token to the cloud server, so that the cloud server routes the second data acquisition request to the dynamic token verification interface of the authentication server, and the authentication server verifies the second token; A data receiving module is used to receive the business data returned by the cloud server, and the business data is sent by the cloud server in response to receiving the verification response returned by the authentication server; the authentication server caches the second token that has passed the verification for use in the next data acquisition process.

6. A terminal device, characterized in that: The terminal device includes a processor and a memory, the memory is used to store at least one computer program, and the at least one computer program is loaded by the processor and executes the device authentication method according to claim 1.

7. A storage medium, characterized in that: The storage medium is used to store at least one computer program, and the at least one computer program is used to execute the device authentication method according to claim 1.

8. A computer program product, characterized in that The computer program product includes a computer program code, which is stored in a computer-readable storage medium. The processor of the terminal device reads the computer program code from the computer-readable storage medium, and the processor executes the computer program code, so that the terminal device performs the device authentication method according to claim 1.

Citation Information

Patent Citations

  • Cloud service access method and device, equipment and medium

    CN111262866A