Device Quantity Statistical Method, Identification Processing Method, Device and Storage Medium
By receiving the device identification and identification signature sent by the device end, and using the digital certificate public key for signature authentication and detection, the problem of low accuracy of the number of equipment statistics is solved and more accurate statistics of the number of equipment is achieved.
Patent Information
- Application Number
- CN202111045339.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-07
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-09-07
AI Technical Summary
In the prior art, when the device identification or key is the same, it is impossible to accurately distinguish multiple authentications of a single device from multiple authentications of multiple devices, resulting in a low accuracy rate of the number of devices statistics.
By receiving the device identification and identification signature sent by the device end, the preset digital certificate public key is used for signature authentication, and if legal, identification detection and key detection are performed, and the statistical value of the number of devices is calculated.
The accuracy of equipment quantity statistics is improved and the accuracy of equipment quantity statistics is ensured.
Smart Images

Figure CN113886801B_ABST
Abstract
Description
Technical Field
[0001] This application relates to, but is not limited to, the field of computers, and particularly relates to a method for counting the number of devices, a method for processing identifiers, a device, and a storage medium. Background Art
[0002] In the field of device security, sensitive data such as keys is burned into terminal physical devices and used by the verification party to verify whether the identity of the device is legal. During the verification process, the verification party can count the number of devices through device identifiers.
[0003] The burning of keys and device identifiers is completed on the production line. If some manufacturers burn the same device identifier or key into multiple terminal devices, since the verification party obtains the same device identifier or key, it is impossible to distinguish between multiple authentications of a single device and multiple authentications of multiple devices, resulting in a low accuracy rate of device number statistics. Summary of the Invention
[0004] This application aims to solve at least one of the technical problems existing in the prior art. For this reason, this application proposes a method for counting the number of devices, a method for processing identifiers, a device, and a storage medium, which can improve the accuracy rate of device number statistics.
[0005] The first aspect of the embodiments of this application provides a method for counting the number of devices, including: receiving a device identifier and an identifier signature sent by a device end; performing signature authentication on the identifier signature according to a public key of a preset digital certificate to obtain a signature authentication result; if the signature authentication result is that the device identifier is legal, performing identifier detection on the device identifier to obtain an identifier detection result; if the identifier detection result is that the device identifier has not been counted, performing key detection according to the public key of the preset digital certificate to obtain a key detection result; if the key detection result is that the public key has not been recorded, calculating to obtain a device number statistic value.
[0006] The method for counting the number of devices according to the embodiments of this application has at least the following technical effects: The method for counting the number of devices provided by this application performs signature authentication on the device identifier according to the public key of the digital certificate to determine the legality of the device identifier, and then performs identifier detection and key detection to obtain a device number statistic value, improving the accuracy rate of device number statistics.
[0007] According to some embodiments of this application, the method for counting the number of devices further includes: if the signature authentication result is that the device identifier is illegal, ending the number counting.
[0008] According to some embodiments of this application, the method for counting the number of devices further includes: if the identifier detection result is that the device identifier has been counted, generating a first log warning message.
[0009] According to some embodiments of the present application, the device quantity statistical method further includes: if the public key has been recorded in the key detection result, generating a second log warning message.
[0010] According to some embodiments of the present application, before receiving the device identifier and the identifier signature sent by the receiving device end, the device quantity statistical method further includes: sending a verification request message to the device end; receiving the verification response data sent by the device end according to the verification request message.
[0011] An embodiment of the second aspect of the present application provides a device identifier processing method, including: obtaining a preset digital certificate private key and a preset device identifier; performing a signature process on the preset device identifier according to the digital certificate private key to obtain an identifier signature; sending the device identifier and the identifier signature to the server end, so that the server end executes the device quantity statistical method provided in the embodiment of the first aspect according to the device identifier.
[0012] According to some embodiments of the present application, the device identifier processing method further includes: receiving a verification request message sent by the server end; performing a security operation on the verification request message according to a preset device key to obtain verification response data; sending the verification response data to the server end, so that the server end receives the device identifier and the identifier signature according to the verification response data.
[0013] An embodiment of the third aspect of the present application provides a device quantity statistical device, including: a receiving module, configured to receive a device identifier and an identifier signature sent by a device end; an authentication module, configured to perform signature authentication on the identifier signature according to a preset digital certificate public key to obtain a signature authentication result; an identifier detection module, configured to perform identifier detection on the device identifier if the signature authentication result is that the device identifier is legal to obtain an identifier detection result; a key detection module, configured to perform key detection according to the preset digital certificate public key if the identifier detection result is that the device identifier has not been counted to obtain a key detection result; a statistical module, configured to calculate a device quantity statistical value if the key detection result is that the public key has not been recorded.
[0014] An embodiment of the fourth aspect of the present application provides a device identifier processing device, including: an obtaining module, configured to obtain a preset digital certificate private key and a preset device identifier; a signature module, configured to perform a signature process on the preset device identifier according to the digital certificate private key to obtain an identifier signature; a sending module, configured to send the device identifier and the identifier signature to the server end, so that the server end executes the device quantity statistical method provided in the embodiment of the first aspect according to the device identifier.
[0015] A storage medium according to an embodiment of the fifth aspect of the present application stores computer-executable instructions for: executing the device quantity statistics method described in the embodiment of the first aspect above; or, executing the device identification processing method described in the embodiment of the second aspect above.
[0016] Additional aspects and advantages of the present application will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the application. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The present application will be further described below with reference to the drawings and embodiments, where:
[0018] Figure 1 is a flowchart of a device quantity statistics method provided by an embodiment of the present application;
[0019] Figure 2 is a flowchart of a device quantity statistics method provided by another embodiment of the present application;
[0020] Figure 3 is a flowchart of a device quantity statistics method provided by yet another embodiment of the present application;
[0021] Figure 4 is a flowchart of a device quantity statistics method provided by another embodiment of the present application;
[0022] Figure 5 is a flowchart of a device quantity statistics method provided by yet another embodiment of the present application;
[0023] Figure 6 is a flowchart of a device identification processing method provided by an embodiment of the present application;
[0024] Figure 7 is a flowchart of a device identification processing method provided by another embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0025] Embodiments of the present application will be described in detail below. Examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the drawings are exemplary only for explaining the present application and should not be construed as limiting the present application.
[0026] In the description of the present application, it should be understood that for the orientation description, such as the orientation or positional relationship indicated by up, down, front, back, left, right, etc., it is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation to the present application.
[0027] In the description of the present application, the meaning of several is more than one, and the meaning of multiple is more than two. Understandings such as greater than, less than, exceeding, etc. do not include the recited number, and understandings such as above, below, within, etc. include the recited number. If there is a description of first and second, it is only for the purpose of distinguishing technical features and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features or implicitly indicating the sequence relationship of the indicated technical features.
[0028] In the description of the present application, unless otherwise clearly defined, terms such as setting, installing, connecting, etc. should be understood in a broad sense, and those skilled in the art can reasonably determine the specific meanings of the above terms in the present application in combination with the specific content of the technical solution.
[0029] In the description of the present application, the description with reference to terms such as "one embodiment", "some embodiments", "schematic embodiments", "examples", "specific examples", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic descriptions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.
[0030] The embodiment of the present application provides a method for counting the number of devices, including: receiving the device identifier and the identifier signature sent by the device end; performing signature authentication on the identifier signature according to the public key of the preset digital certificate to obtain a signature authentication result; if the signature authentication result is that the device identifier is legal, performing identifier detection on the device identifier to obtain an identifier detection result; if the identifier detection result is that the device identifier has not been counted, performing key detection according to the public key of the preset digital certificate to obtain a key detection result; if the key detection result is that the public key has not been recorded, calculating to obtain the device number statistical value.
[0031] As Figure 1 shown, Figure 1 is a flowchart of the device number counting method provided by some embodiments, for the server side. The device number counting method includes but is not limited to steps S110 to S150, specifically including:
[0032] S110, receiving the device identifier and the identifier signature sent by the device end;
[0033] S120. Perform signature authentication on the identity signature according to the preset digital certificate public key to obtain a signature authentication result.
[0034] S130. If the signature authentication result indicates that the device identity is legal, perform identity detection on the device identity to obtain an identity detection result.
[0035] S140. If the identity detection result indicates that the device identity has not been counted, perform key detection according to the preset digital certificate public key to obtain a key detection result.
[0036] S150. If the key detection result indicates that the public key has not been recorded, calculate the device quantity statistical value.
[0037] In step S110, the server - side receives the device identity and the identity signature sent by the device - side for the server - side to verify and count the quantity of the device - side. Among them, the identity signature is obtained by the device - side through signature processing with the private key of the digital certificate, which is used to ensure the unity of the key and the device identity, thereby improving the accuracy of quantity statistics.
[0038] In a specific embodiment, the device - side splices the device identity and the identity signature, and performs HAMC processing on the spliced whole, and then sends it to the server - side. Therefore, the data received by the server - side is "HAMC [device identity (plaintext)+signature value of the device identity]".
[0039] In step S120, the acquisition methods of the preset digital certificate public key include but are not limited to: (1) using the public key stored by the server - side itself; (2) receiving the public key sent by the device - side; (3) receiving the digital certificate sent by the device - side and extracting the public key from the digital certificate.
[0040] In step S120, corresponding to the signature process of the device - side, the signature authentication process of the server - side is to obtain a signature authentication result according to the identity signature. The signature authentication result is used to characterize whether the device identity of the device is legal. The device identity is used for subsequent device identity detection and key detection, and then realizes the process of counting the device quantity.
[0041] It should be noted that the digital certificate is also called a digital identity. The digital certificate ensures the integrity and security of information and data in the form of encryption or decryption for network users in computer network communication.
[0042] In step S130, if it is detected that the device identity is legal, perform identity detection on this device identity. Specifically, add the device identity to the task queue of the quantity control management in the quantity control management system.
[0043] The device quantity statistical method provided by this application performs signature authentication on the device identifier according to the public key of the digital certificate to determine the legitimacy of the device identifier, and then performs identifier detection and key detection to obtain the device quantity statistical value, improving the accuracy of device quantity statistics.
[0044] According to some embodiments of this application, the device quantity statistical method further includes: if the signature authentication result is that the device identifier is illegal, then end the quantity statistics.
[0045] As Figure 2 shown, Figure 2 is a flowchart of the device quantity statistical method provided by some other embodiments, for the server side. The device quantity statistical method includes but is not limited to steps S210 to S240, specifically including:
[0046] S210, perform signature authentication on the identifier signature according to the preset digital certificate public key to obtain the signature authentication result;
[0047] S220, determine whether the signature authentication result is that the device identifier is legal; if the determination result is yes, then execute step S230; if the determination result is no, then execute step S240;
[0048] S230, perform identifier detection on the device identifier to obtain the identifier detection result;
[0049] S240, end the quantity statistics.
[0050] In steps S210 to S240, if it is detected that the device identifier is illegal, then end the quantity statistics of this device and exclude this downstream terminal from the system. It should be noted that the situations where the device identifier is illegal include but are not limited to the device identifier being tampered with, etc.
[0051] According to some embodiments of this application, the device quantity statistical method further includes: if the identifier detection result is that the device identifier has been counted, then generate the first log warning information.
[0052] As Figure 3 shown, Figure 3 is a flowchart of the device quantity statistical method provided by some other embodiments, for the server side. The device quantity statistical method includes but is not limited to steps S310 to S340, specifically including:
[0053] S310, perform identifier detection on the device identifier to obtain the identifier detection result;
[0054] S320, determine whether the identifier detection result is that the device identifier has been counted; if the determination result is yes, then execute step S330; if the determination result is no, then execute step S340;
[0055] S330, generate the first log warning message;
[0056] S340, perform key detection according to the preset digital certificate public key to obtain the key detection result.
[0057] In steps S310 to S320, the identification detection process includes detecting whether the authentication device identification exists in the system through the quantity control management system.
[0058] In step S330, the first log warning message includes, but is not limited to, the log warning message indicating that the device identification has been counted, so as to alarm and record possible errors and faults.
[0059] In steps S330 to S340, if the device identification has not been counted, then further perform key detection according to the preset digital certificate public key.
[0060] According to some embodiments of the present application, the device quantity statistics method further includes: if the key detection result is that the public key has been recorded, then generate the second log warning message.
[0061] As Figure 4 shown, Figure 4 is a flowchart of the device quantity statistics method provided by other embodiments, for the server side. The device quantity statistics method includes, but is not limited to, steps S410 to S440, specifically including:
[0062] S410, perform key detection according to the preset digital certificate public key to obtain the key detection result;
[0063] S420, determine whether the key detection result is that the public key is recorded; if the determination result is yes, then execute step S430; if the determination result is no, then execute step S440;
[0064] S430, generate the second log warning message;
[0065] S440, calculate the device quantity statistical value.
[0066] In steps S410 to S420, specifically, it is to determine whether the public key corresponding to the private key for signing the device identification is stored in the database of the server side to obtain the key monitoring result.
[0067] In steps S430 to S440, the second log warning message includes, but is not limited to, the log warning message indicating that the identification certificate private key has been burned into multiple devices. Furthermore, according to the second log warning message, possible errors and faults are alarmed and recorded.
[0068] Specifically, if it is detected that the public keys of the server side and the device side are the same, it means that the public key has been counted, that is, the number of devices has been accumulated, and the number of devices is not accumulated again; if it is detected that the public keys of the server side and the device side are different, it means that the device has not been collected before, and the number of devices can be counted.
[0069] In step S440, the process of calculating the device quantity statistical value includes: adding one to the device quantity statistical value as the new device quantity statistical value, and then completing the accumulation of the device quantity through the detection of each device identifier, thereby accurately completing the statistics of the device quantity.
[0070] According to some embodiments of the present application, before receiving the device identifier and the identifier signature sent by the device side, the device quantity statistical method further includes: sending a verification request message to the device side; receiving the verification response data sent by the device side according to the verification request message.
[0071] As Figure 5 shown, Figure 5 is a flowchart of the device quantity statistical method provided by some other embodiments. Before receiving the device identifier and the identifier signature sent by the device side, the device quantity statistical method further includes:
[0072] S510, sending a verification request message to the device side;
[0073] S520, receiving the verification response data sent by the device side according to the verification request message.
[0074] In step S510, when the server side needs to approve the quantity of the device side, it is necessary to first obtain the device identifier and the identifier signature of the device side. Before that, the identity authentication between the server side and the device side needs to be completed. Therefore, the server sends a verification request message to the device side.
[0075] Specifically, the verification method of the sent verification request message includes but is not limited to the random number challenge method. Specifically, it includes: the identity authentication system of the challenge / response method is that each time the authentication server side sends a different "challenge" string to the client side. After receiving this "challenge" string, the client program makes a corresponding "response". The authentication process of the system developed based on this mechanism is:
[0076] (1) The device side sends a request to the server side to request identity authentication;
[0077] (2) The server side queries in the user database whether the user is a legitimate user. If not, no further processing is done;
[0078] (3) The server side internally generates a random number as a "question" and sends it to the device side;
[0079] (4) The device side combines the user name and the random number, and uses a one-way Hash function (such as the MD5 algorithm) to generate a byte string as the response.
[0080] (5) The server side compares the response string with its own calculation result. If the two are the same, the authentication is passed once; otherwise, the authentication fails.
[0081] (6) The server side notifies the device side whether the authentication is successful or failed.
[0082] In step S520, after receiving the verification response data, the server side verifies the signed message body in the verification response data. After successful verification, it collects the signed device identifier, and then conducts the statistics of the number of devices.
[0083] The embodiment of the present application provides a method for processing device identifiers, including: obtaining a preset digital certificate private key and a preset device identifier; performing a signature process on the preset device identifier according to the digital certificate private key to obtain an identifier signature; sending the device identifier and the identifier signature to the server side, so that the server side executes the method for counting the number of devices provided in the embodiment of the first aspect according to the device identifier.
[0084] As Figure 6 shown, Figure 6 is a flowchart of a method for processing device identifiers provided by some embodiments, which is used for the device side. The method for processing device identifiers includes but is not limited to steps S610 to S630, specifically including:
[0085] S610, obtaining a preset digital certificate private key and a preset device identifier;
[0086] S620, performing a signature process on the preset device identifier according to the digital certificate private key to obtain an identifier signature;
[0087] S630, sending the device identifier and the identifier signature to the server side.
[0088] In step S610, the digital certificate private key is the private key of the key in the digital certificate of the device side, which is used for signing the identity identifier. The preset digital certificate private key is burned into the specific device on the production line for the server side to identify and use the private key to authenticate the device; the device identifier is generated by a random number generator after the device is powered on, and this random number is used as the unique identity identifier of the device, that is, the device identifier.
[0089] Specifically, the device identifier includes, but is not limited to, a 128-bit random number generated by the terminal initialization through RFC 4122. RFC4122 has a fixed size (128 bits). The device identifier is an identifier that is unique in both space and time, with a fixed size and including a time field. The specific calculation includes:
[0090] UUID = "time-low"-"time-mid"-"time-high-and-version"-"clock-seq-and-reserved clock-seq-low"-"node";
[0091] Among them, UUID is the device identifier, time_low is the low-order timestamp, time-mid is the middle-order timestamp, time-high-and-version is the high-order timestamp and version number, clock_seq_hi_and_reserved is the high-order clock sequence and custom serial number, clock-seq-low is the low-order clock sequence, and node is the node identifier.
[0092] It should be noted that in a specific embodiment, the data type of time-mid is 32 bits and is generated from a random number; the data type of time-mid is 16 bits and is generated from a random number; the data type of time-high-and-version is 16 bits; the data type of clock_seq_hi_and_reserved is 8 bits, and its high-order bits 6 and 7 are 0 and 1 respectively, and the rest are generated from a random number; the data type of clock-seq-low is 8 bits and is generated from a random number; the data type of node is 48 bits and is generated from a random number. A specific example is as follows: UUID = f81d4fae-7dec-11d0-a765-00a0c91e6bf6.
[0093] In step S620, the signature algorithms used for signature processing include, but are not limited to, the Sha256withEcdsa signature algorithm and the ECVQ signature algorithm.
[0094] In step S630, the server-side collects the device identifier signed by the device-side for verification.
[0095] The device identifier processing method provided by this application performs signature processing on a preset device identifier according to the digital certificate private key to obtain an identifier signature, which is used for device identification and quantity statistics. It defines an authentication identifier with uniqueness, so that even when multiple certificates are burned into multiple devices, accurate quantity control management can be performed, improving the accuracy rate of device quantity statistics.
[0096] In addition, device key burning and device identity identification often belong to different entities. Therefore, the device identity processing method provided in this application can also be used to identify the problem of repeated burning of device keys.
[0097] According to some embodiments of the present application, the device identity processing method further includes: receiving a verification request message sent by the server side; performing a security operation on the verification request message according to a preset device key to obtain verification response data; sending the verification response data to the server side so that the server side receives the device identity and identity signature according to the verification response data.
[0098] As Figure 7 shown, Figure 7 is a flowchart of a device identity processing method provided by other embodiments. The device identity processing method further includes:
[0099] S710, receiving a verification request message sent by the server side;
[0100] S720, performing a security operation on the verification request message according to a preset device key to obtain verification response data;
[0101] S730, sending the verification response data to the server side.
[0102] In steps S570 to S570, the device side performs a security operation on the verification request message through the device key to obtain verification response data, and returns the verification response data to the server side. Among them, the verification response data includes, but is not limited to, the HMAC value or digital signature of the device identity.
[0103] It should be noted that the device key includes, but is not limited to, the public key and private key of the digital certificate, the session key derived from the device key, etc.
[0104] The embodiments of the present application provide a device quantity statistics device, including: a receiving module, configured to receive the device identity and identity signature sent by the device side; an authentication module, configured to perform signature authentication on the identity signature according to a preset digital certificate public key to obtain a signature authentication result; an identity detection module, configured to perform identity detection on the device identity to obtain an identity detection result if the signature authentication result is that the device identity is legal; a key detection module, configured to perform key detection according to the preset digital certificate public key to obtain a key detection result if the identity detection result is that the device identity has not been counted; a statistics module, configured to calculate a device quantity statistics value if the key detection result is that the public key has not been recorded.
[0105] The device quantity statistical device provided by this application implements a device quantity statistical method. It performs signature authentication on the device identifier according to the public key of the digital certificate to determine the legality of the device identifier, and then conducts identifier detection and key detection to obtain the device quantity statistical value, improving the accuracy of device quantity statistics.
[0106] An embodiment of this application provides a device identifier processing device, including: an acquisition module for acquiring a preset digital certificate private key and a preset device identifier; a signature module for performing signature processing on the preset device identifier according to the digital certificate private key to obtain an identifier signature; a sending module for sending the device identifier and the identifier signature to the server side, so that the server side executes the device quantity statistical method provided in any of the above embodiments according to the device identifier.
[0107] The device identifier processing device provided by this application implements a device identifier processing method. It performs signature processing on the preset device identifier according to the digital certificate private key to obtain an identifier signature, which is used for device identification and quantity statistics. It defines a unique authentication identifier, enabling accurate quantity control and management even when multiple certificates are burned into multiple devices, and improving the accuracy of device quantity statistics.
[0108] According to the storage medium of the embodiment of this application, computer-executable instructions are stored, and the computer-executable instructions are used for: executing the device quantity statistical method in any of the above embodiments; or, executing the device identifier processing method in any of the above embodiments.
[0109] The device embodiment described above is merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0110] Those of ordinary skill in the art will understand that all or some of the steps and devices disclosed in the above methods can be implemented as software, firmware, hardware, and appropriate combinations thereof. Some physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those of ordinary skill in the art, communication media typically includes computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery medium.
[0111] The embodiments of the present application have been described in detail above with reference to the accompanying drawings. However, the present application is not limited to the above embodiments, and various changes can be made without departing from the spirit of the present application within the scope of knowledge possessed by those of ordinary skill in the relevant art. In addition, the embodiments of the present application and the features in the embodiments can be combined with each other without conflict.
Claims
1. Method for counting the number of devices, characterized in that, it includes: Receiving the device identifier and the identifier signature sent by the device end; Performing signature authentication on the identifier signature according to the public key of the preset digital certificate to obtain a signature authentication result; If the signature authentication result is that the device identifier is legal, then performing identifier detection on the device identifier to obtain an identifier detection result; If the identifier detection result is that the device identifier has not been counted, then performing key detection according to the public key of the preset digital certificate to obtain a key detection result; If the identifier detection result is that the device identifier has been counted, then generating a first log warning message; wherein, the first log warning message includes a log warning message indicating that the device identifier has been counted; If the key detection result is that the public key has been recorded, then generating a second log warning message; wherein, the second log warning message includes a log warning message that the private key of the identification certificate has been burned into multiple devices; If the key detection result is that the public key has not been recorded, then calculating the device quantity statistical value; The performing identifier detection on the device identifier includes: detecting and authenticating whether the device identifier exists in the system through a quantity control management system; The performing key detection according to the public key of the preset digital certificate includes: determining whether the public key corresponding to the private key for signing the device identifier is stored in the database of the server side; Before receiving the device identifier and the identifier signature sent by the device end, the method for counting the number of devices further includes: Sending a verification request message to the device end; Receiving the verification response data sent by the device end according to the verification request message; The verification method for sending the verification request message includes: implementing, through an authentication system using the challenge / response method, sending a different challenge string to the device end each time for authentication, and receiving the response string made by the device end to the challenge string.
2. The method for counting the number of devices according to claim 1, characterized in that, the method for counting the number of devices further includes: If the signature authentication result is that the device identifier is illegal, then ending the quantity counting.
3. Method for processing device identifiers, characterized in that, it includes: Obtaining the private key of the preset digital certificate and the preset device identifier; Performing signature processing on the preset device identifier according to the digital certificate private key to obtain an identifier signature; Sending the device identifier and the identifier signature to the server side so that the server side executes the method for counting the number of devices according to any one of claims 1 to 2 based on the device identifier; The device identifier includes: a 128-bit random number generated by the terminal initialization through RFC4122, wherein the 128-bit random number includes fixed size and time fields; The calculation of the device identifier includes: UUID = "time - low"-"time - mid"-"time - high - and - version"-"clock - seq - and - reserved":"clock - seq - low "-" node; where UUID is the device identifier, time - low is the low - order timestamp, time - mid is the middle - order timestamp, time - high - and - version is the high - order timestamp and version number, clock - seq - and - reserved is the high - order clock sequence and custom serial number, clock - seq - low is the low - order clock sequence, and node is the node identifier.
4. The device identifier processing method according to claim 3, characterized in that, the device identifier processing method further includes: receiving a verification request message sent by the server - side; performing a security operation on the verification request message according to a preset device key to obtain verification response data; sending the verification response data to the server - side so that the server - side receives the device identifier and the identifier signature according to the verification response data.
5. Device quantity statistical device, characterized in that, comprising: a receiving module for receiving the device identifier and the identifier signature sent by the device - side; an authentication module for performing signature authentication on the identifier signature according to a preset digital certificate public key to obtain a signature authentication result; an identifier detection module for, if the signature authentication result indicates that the device identifier is legal, performing identifier detection on the device identifier to obtain an identifier detection result; a key detection module for, if the identifier detection result indicates that the device identifier has not been counted, performing key detection according to the preset digital certificate public key to obtain a key detection result; a statistical module for, if the key detection result indicates that the public key has not been recorded, calculating a device quantity statistical value; the identifier detection module includes: if the identifier detection result indicates that the device identifier has been counted, generating a first log warning message; wherein, the first log warning message includes a log warning message indicating that the device identifier has been counted; the identifier detection module further includes: detecting and authenticating whether the device identifier exists in the system through a quantity control management system; the key detection module includes: if the key detection result indicates that the public key has been recorded, generating a second log warning message; wherein, the second log warning message includes a log warning message indicating that the private key of the identification certificate has been burned into multiple devices; the key detection module further includes: judging whether the public key corresponding to the private key for signing the device identifier is stored in the database of the server - side; the device quantity statistical device further includes: sending a verification request message to the device - side; receiving the verification response data sent by the device - side according to the verification request message; the device quantity statistical device further includes: implementing, through an identity authentication system in a challenge / response manner, sending a different challenge string to the device - side at each authentication and receiving the response string made by the device - side to the challenge string.
6. Device identifier processing device, It is characterized in that It includes: An acquisition module, configured to acquire a preset digital certificate private key and a preset device identifier; A signature module, configured to perform signature processing on the preset device identifier according to the digital certificate private key to obtain an identifier signature; A sending module, configured to send the device identifier and the identifier signature to a server side, so that the server side executes the device quantity statistics method according to any one of claims 1 to 2 based on the device identifier; The acquisition module includes: The terminal initializes a 128-bit random number generated by RFC4122, where the 128-bit random number includes fixed size and time fields; The calculation of the device identifier includes: UUID = "time-low"-"time-mid"-"time-high-and-version"-"clock-seq-and-reservedclock-seq-low "-" node; where UUID is the device identifier, time-low is the low-order timestamp, time-mid is the middle-order timestamp, time-high-and-version is the high-order timestamp and version number, clock-seq-and-reserved is the high-order clock sequence and custom sequence number, clock-seq-low is the low-order clock sequence, and node is the node identifier.
7. A storage medium It is characterized in that The storage medium stores computer-executable instructions, and the computer-executable instructions are used to cause a computer to execute: The device quantity statistics method according to any one of claims 1 to 2; or, the device identifier processing method according to any one of claims 3 to 4.
Citation Information
Patent Citations
Equipment identity authentication method and device
CN106899410A