Access authentication method, authentication server and system based on MQTT protocol
By introducing an access authentication method based on IDS4 authentication server in the MQTT protocol, the problem of illegal operation of devices and useless messages in public places is solved, and the security authentication of the client and effective management of message release is realized.
Patent Information
- Application Number
- CN202111248679.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-26
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2041-10-26
AI Technical Summary
In the prior art, devices are easily accessed by others in public places, resulting in random operations and useless spam messages, and do not support point-to-point communication and group management.
The access authentication method based on the MQTT protocol is adopted, and the MQTT client is authenticated and authorized through the IDS4 authentication server, and a token token containing role information is generated, the client role is judged to determine whether it has message publishing permissions, and the user list can be pushed through unique identification management.
Effectively control the random access and message release of clients, prevent spam information, ensure device security and controllability of message delivery, and solve the problem of equipment being illegally operated in public places.
Smart Images

Figure CN113965330B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of Internet technology, and specifically to an access authentication method, an authentication server and a system based on the MQTT protocol. Background Art
[0002] The Internet of Things is not just a network, but a new ecological environment. The essence of what it describes is that more and more objects are connected through the network and can be controlled and used in various ways by single or multiple terminal devices. As we all know, the Internet of Things is a concept that extends and expands on the basis of the traditional Internet. The user end extends and expands from traditional computers to any objects, and the objects collect information through various sensors, and then exchange and communicate network information through computing devices. However, the current mobile Internet is in its infancy and often cannot provide reliable network security. Therefore, the proposed MQTT protocol is committed to solving this problem.
[0003] The existing technology does not support point-to-point communication. It adopts the standard MQTT protocol. In theory, point-to-point communication can be achieved through mutual subscription, but the logic is relatively complex and there are concerns about the security of the device. When device B and device C are in the same topic, device A cannot know whether the message is sent by device B or device C, and it is also possible that the message is eavesdropped by device D. Group management is also not supported. The present invention realizes the management of group members, and group members can communicate with each other. This is particularly useful in scenarios where a device is controlled by multiple people, or multiple devices are controlled by one person. Summary of the invention
[0004] To this end, the embodiments of the present invention provide an access authentication method, an authentication server and a system based on the MQTT protocol to solve the problem in the prior art that the connection mode of devices placed in public places can be easily obtained by others and can be arbitrarily operated, resulting in a large number of useless junk messages.
[0005] In order to achieve the above purpose, the embodiment of the present invention provides the following technical solutions:
[0006] According to a first aspect of an embodiment of the present invention, an access authentication method based on the MQTT protocol is proposed, the method is executed by an authentication server, and the method includes:
[0007] Receive a token access authentication request sent by the MQTT client, where the token contains the client's unique identifier, token validity period, and client role information;
[0008] The MQTT client is authenticated according to the authentication request, the validity of the Token is verified according to the Token validity period, the unique identifier of the authentication request is compared with the client unique identifier in the Token to see if they match, and the role verification is performed. After the authentication is successful, a Token containing the role information is returned to the MQTT client so as to establish a connection with the MQTT client after the authentication is successful.
[0009] Furthermore, the method further comprises:
[0010] Determine whether the client has the permission to publish messages according to the role of the client, and if so, add the unique identifier of the client to the list of users who can push messages;
[0011] When receiving a message publishing request from a client, determine whether the client's unique identifier is in the list of users who can be pushed. If so, allow the client to publish the message to the specified topic.
[0012] Furthermore, the method also includes: allocating a unique identifier to the MQTT client device.
[0013] Furthermore, the access authentication request is generated based on the access key, the encryption key and the unique identification information.
[0014] Furthermore, the MQTT client includes a message publishing end and a message subscription end.
[0015] Furthermore, the authentication server is an IDS4 authentication server.
[0016] According to a second aspect of an embodiment of the present invention, an authentication server is provided, the authentication server comprising:
[0017] The authentication request receiving module is used to receive the Token access authentication request sent by the MQTT client, where the Token contains the client's unique identifier, the Token validity period, and the client's role information;
[0018] The client authentication module is used to authenticate the MQTT client according to the authentication request, verify whether the Token is valid according to the Token validity period, compare whether the unique identifier of the authentication request matches the client unique identifier in the Token, and perform role verification. After the authentication is passed, a Token containing role information is returned to the MQTT client and a connection is established with the MQTT client.
[0019] According to a third aspect of an embodiment of the present invention, an access authentication system based on the MQTT protocol is proposed. The system includes the authentication server and the MQTT client as described above.
[0020] According to a fourth aspect of an embodiment of the present invention, a computer storage medium is proposed, wherein the computer storage medium contains one or more program instructions, and the one or more program instructions are used to be executed by an access authentication system based on the MQTT protocol to perform any of the methods described above.
[0021] The embodiments of the present invention have the following advantages:
[0022] The embodiment of the present invention proposes an access authentication method, authentication server and system based on the MQTT protocol. After the client is authenticated and authorized by the IDS4 authentication server, it obtains the corresponding role, which controls the random access of the client on the one hand, and prevents the client from sending messages randomly on the other hand. It fundamentally solves the problem that the connection method is easily obtained by others because the device is placed in a public place. By adding an effective permission verification mechanism and sending role control, it prevents users from sending messages randomly and causing confusion in the MQTT service. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the implementation methods of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the implementation methods or the description of the prior art. Obviously, the drawings in the following description are only exemplary, and for ordinary technicians in this field, other implementation drawings can be derived from the provided drawings without creative work.
[0024] Figure 1 A flowchart of an access authentication method based on the MQTT protocol provided in Example 1 of the present invention. DETAILED DESCRIPTION
[0025] The following is a description of the implementation of the present invention by specific embodiments. People familiar with the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0026] Example 1
[0027] like Figure 1 As shown, this embodiment proposes an access authentication method based on the MQTT protocol, the method is executed by an authentication server, and the authentication server is an IDS4 authentication server. Specifically, the method includes:
[0028] S100: Receive a Token access authentication request sent by an MQTT client, where the Token includes a unique identifier of the client, a valid time of the Token, and role information of the client.
[0029] The MQTT client includes a message publisher and a message subscriber, which respectively publish messages according to subscription topics and obtain subscription messages pushed by the server.
[0030] Furthermore, the method further includes: the IDS4 authentication server assigning a unique identifier to the MQTT client device.
[0031] In this embodiment, the access authentication request is generated based on the access key, the encryption key and the unique identification information.
[0032] S200, authenticate the MQTT client according to the authentication request, verify whether the Token is valid according to the Token validity period, compare whether the unique identifier of the authentication request matches the client unique identifier in the Token, and perform role verification. After the authentication is passed, return the Token containing the role information to the MQTT client so as to establish a connection with the MQTT client after the authentication is passed. The server obtains the client role through the database. After the authentication and authorization are successful, the client determines the connection with the server device based on the authentication result fed back by the server device, completes the message publishing or obtains the push message.
[0033] Furthermore, the method further comprises:
[0034] Determine whether the client has the permission to publish messages according to the role of the client, and if so, add the unique identifier of the client to the list of users who can push messages;
[0035] When receiving a message publishing request from a client, determine whether the client's unique identifier is in the list of users who can be pushed. If so, allow the client to publish the message to the specified topic.
[0036] This embodiment proposes an access authentication method based on the MQTT protocol, which combines the IDS4 authentication server and the MQTT protocol client to specify the role and authority of each device. Only the token authenticated by the server can send messages, which solves the problem of spam in the prior art that as long as the device is connected, it can be initiated to the topic, resulting in the generation of spam.
[0037] Example 2
[0038] Corresponding to the above-mentioned embodiment 1, this embodiment proposes an authentication server, and the authentication server includes:
[0039] The authentication request receiving module is used to receive the Token access authentication request sent by the MQTT client, where the Token contains the client's unique identifier, the Token validity period, and the client's role information;
[0040] The client authentication module is used to authenticate the MQTT client according to the authentication request, verify whether the Token is valid according to the Token validity period, compare whether the unique identifier of the authentication request matches the client unique identifier in the Token, and perform role verification. After the authentication is successful, a Token containing role information is returned to the MQTT client so as to establish a connection with the MQTT client after the authentication is successful.
[0041] The functions performed by the various components in the authentication server provided in the embodiment of the present invention have been described in detail in the above embodiment 1, so they will not be described in detail here.
[0042] Example 3
[0043] Corresponding to the above embodiment, this embodiment proposes a computer storage medium, which contains one or more program instructions, and the one or more program instructions are used to be executed by an access authentication system based on the MQTT protocol as the method of Example 1.
[0044] Although the present invention has been described in detail above by general description and specific embodiments, it is obvious to those skilled in the art that some modifications or improvements can be made to the present invention. Therefore, these modifications or improvements made without departing from the spirit of the present invention all belong to the scope of protection claimed by the present invention.
Claims
1. An access authentication method based on the MQTT protocol, characterized in that: The method is performed by an authentication server, and comprises: Receive a token access authentication request sent by the MQTT client, where the token contains the client's unique identifier, token validity period, and client role information; Authenticate the MQTT client according to the authentication request, verify whether the Token is valid according to the Token validity period, compare whether the unique identifier of the authentication request matches the client unique identifier in the Token, and perform role verification. After the authentication is successful, return a Token containing role information to the MQTT client so as to establish a connection with the MQTT client after the authentication is successful; The method further comprises: Determine whether the client has the permission to publish messages according to the role of the client, and if so, add the unique identifier of the client to the list of users who can push messages; When receiving a message publishing request from a client, determine whether the client's unique identifier is in the list of users who can be pushed. If so, allow the client to publish the message to the specified topic.
2. The access authentication method based on the MQTT protocol according to claim 1, characterized in that: The method further includes: allocating a unique identifier to the MQTT client device.
3. The access authentication method based on the MQTT protocol according to claim 1, characterized in that: The access authentication request is generated based on the access key, the encryption key and the unique identification information.
4. The access authentication method based on the MQTT protocol according to claim 1, characterized in that: The MQTT client includes a message publishing end and a message subscription end.
5. The access authentication method based on the MQTT protocol according to claim 1, characterized in that: The authentication server is an IDS4 authentication server.
6. An authentication server, characterized in that: The authentication server comprises: The authentication request receiving module is used to receive the Token access authentication request sent by the MQTT client, where the Token contains the client's unique identifier, the Token validity period, and the client's role information; The client authentication module is used to authenticate the MQTT client according to the authentication request, verify whether the Token is valid according to the Token validity period, compare whether the unique identifier of the authentication request matches the client unique identifier in the Token, and perform role verification. After the authentication is successful, a Token containing role information is returned to the MQTT client so as to establish a connection with the MQTT client after the authentication is successful.
7. An access authentication system based on the MQTT protocol, characterized in that: The system comprises the authentication server as claimed in claim 6 and an MQTT client.
8. A computer storage medium, characterized in that: The computer storage medium includes one or more program instructions, and the one or more program instructions are used to be executed by an access authentication system based on the MQTT protocol to perform the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Role token issuing method, access control method and related equipment
CN106656942A
Access authentication method and access authentication equipment based on MQTT
CN106657130A
Method and system for network access authentication of intelligent device
CN113285807A