An Internet of Things-based data processing method and device

By verifying device identification and authentication code on the Internet of Things platform and generating authorization licenses, the security and use control problems of IoT devices under limited resources and low-speed networks are solved, and lightweight device authorization management and content protection are achieved.

CN114598501BActive Publication Date: 2025-06-27ALIBABA CLOUD COMPUTING CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210129419.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-11
Publication Date
2025-06-27
Estimated Expiration
2042-02-11

AI Technical Summary

Technical Problem

In the field of the Internet of Things, some devices cannot perform complex computing and human-computer interaction due to limited resources and computing capabilities, and low-speed networks lead to poor real-time transmission, which makes it difficult to ensure and use control of core technologies integrated in Internet of Things devices.

Method used

After receiving the device's authorization request message through the Internet of Things platform, verifying the device's identification and authentication code, a first authorization license is generated and sent, so that the device can decrypt and use the target content, and realize lightweight device authorization management and content protection.

Benefits of technology

It realizes automated authorization management of massive IoT devices, protects content security through encryption, and reduces the impact on device performance and network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114598501B_ABST
    Figure CN114598501B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a data processing method and device based on the Internet of Things. The method includes: the Internet of Things platform receives an authorization request message sent by an Internet of Things device. The Internet of Things device deploys encrypted target content, and the authorization request message carries the device identifier and authentication code of the Internet of Things device; according to the device identifier and authentication code, verify the Internet of Things device, and after the verification of the Internet of Things device is passed, generate a first authorization license for the Internet of Things device; send the first authorization license to the Internet of Things device so that the Internet of Things device decrypts and uses the target content with the first authorization license. Through the embodiment of the present invention, lightweight authorization management and content protection of Internet of Things devices are realized. It can not only perform automated authorization management on Internet of Things devices, protect the security of content through encryption means, but also reduce the performance loss of Internet of Things devices and the impact on the network where they are located.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of the Internet of Things, and particularly to a data processing method and apparatus based on the Internet of Things. Background Art

[0002] Currently, in order to ensure the real-time nature of data processing and the privacy of data, more and more core technologies are integrated into Internet of Things (IoT) devices. Since they are integrated in IoT devices, to prevent illegal theft and leakage, it is necessary to ensure the security of core technologies and control their usage, such as controlling the effective time of use.

[0003] However, in the field of the Internet of Things, some IoT devices have limited resources and computing capabilities and are unable to perform complex operations and human-computer interactions. Moreover, due to the low-speed networks in which some IoT devices are located, the real-time nature of transmission is poor or even unavailable. These reasons make it difficult to ensure the security of core technologies integrated in IoT devices and control their usage. Summary of the Invention

[0004] In view of the above problems, a data processing method and apparatus based on the Internet of Things are proposed to overcome or at least partially solve the above problems, including:

[0005] A data processing method based on the Internet of Things, which is applied to an Internet of Things platform, and the method includes:

[0006] Receiving an authorization request message sent by an IoT device, where the IoT device deploys encrypted target content, and the authorization request message carries the device identifier and authentication code of the IoT device;

[0007] Verifying the IoT device according to the device identifier and authentication code, and generating a first authorization permission for the IoT device after the verification of the IoT device is passed;

[0008] Sending the first authorization permission to the IoT device so that the IoT device decrypts and uses the target content with the first authorization permission.

[0009] Optionally, before generating the first authorization permission for the IoT device, it further includes:

[0010] Generating a second authorization permission for the target content, where the second authorization permission includes key information for encrypting the target content;

[0011] Obtaining authorization permission configuration information, and generating a third authorization permission according to the second authorization permission and the authorization permission configuration information; wherein, the third authorization permission includes the second authorization permission and the authorization permission configuration information.

[0012] Generate a first authorization license for the Internet of Things device, including:

[0013] Generate a first authorization license for the Internet of Things device according to the third authorization license.

[0014] Optionally, before generating the second authorization license for the target content, it further includes:

[0015] Obtain the target content;

[0016] Encrypt the target content and deploy the encrypted target content to the Internet of Things device.

[0017] Optionally, the authorization license configuration information includes but is not limited to the following:

[0018] The information on the number of devices of the authorization license, the information on the valid duration of the authorization license.

[0019] Optionally, before receiving the authorization request message sent by the Internet of Things device, it further includes:

[0020] After the Internet of Things device is started, establish a message channel with the Internet of Things device.

[0021] Optionally, the authentication code is one-time authentication data generated based on the authentication key or the device trust root of the Internet of Things device, and the Internet of Things device generates an authentication code each time it uses the authentication code for authentication.

[0022] A data processing method based on the Internet of Things, applied to an Internet of Things device, where the Internet of Things device deploys encrypted target content. The method includes:

[0023] When triggering the use of the encrypted target content, send an authorization request message to the Internet of Things platform. The authorization request message carries the device identifier and the authentication code of the Internet of Things device;

[0024] Receive the first authorization license sent by the Internet of Things platform, and use the first authorization license to decrypt and use the target content; where the first authorization license is generated by the Internet of Things platform according to the device identifier and the authentication code, verify the Internet of Things device, and after verifying the Internet of Things device passes.

[0025] Optionally, it further includes:

[0026] Store the first authorization license locally and bind it to the Internet of Things device.

[0027] Optionally, any of the following abnormal situations occur during the loading or verification process:

[0028] There is no authorization license for the encrypted target content stored locally in the Internet of Things device, and the authorization license for the encrypted target content stored locally in the Internet of Things device has expired.

[0029] Optionally, when triggering the use of the encrypted target content, send an authorization request message to the Internet of Things platform, including:

[0030] When triggering the use of the encrypted target content, load and verify the authorization license for the encrypted target content, and when an abnormal situation occurs during the loading or verification process, send an authorization request message to the Internet of Things platform.

[0031] Optionally, the authentication code is one-time authentication data generated based on the authentication key or device trust root of the Internet of Things device, and the Internet of Things device generates an authentication code each time it uses the authentication code for authentication.

[0032] A data processing device based on the Internet of Things, applied to the Internet of Things platform, the device includes:

[0033] An authorization request message receiving module, configured to receive an authorization request message sent by an Internet of Things device. The Internet of Things device deploys encrypted target content, and the authorization request message includes the device identifier and authentication code of the Internet of Things device;

[0034] A first authorization license generation module, configured to verify the Internet of Things device according to the device identifier and authentication code, and generate a first authorization license for the Internet of Things device after the verification of the Internet of Things device is passed;

[0035] A first authorization license sending module, configured to send the first authorization license to the Internet of Things device, so that the Internet of Things device decrypts and uses the target content with the first authorization license.

[0036] A data processing device based on the Internet of Things, applied to an Internet of Things device. The Internet of Things device deploys encrypted target content, and the device includes:

[0037] An authorization request message sending module, configured to send an authorization request message to the Internet of Things platform when triggering the use of the encrypted target content. The authorization request message includes the device identifier and authentication code of the Internet of Things device;

[0038] A first authorization license receiving module, configured to receive the first authorization license sent by the Internet of Things platform, and decrypt and use the target content with the first authorization license; wherein, the first authorization license is generated by the Internet of Things platform according to the device identifier and authentication code, verifying the Internet of Things device, and after the verification of the Internet of Things device is passed.

[0039] The embodiments of the present invention have the following advantages:

[0040] In an embodiment of the present invention, the Internet of Things (IoT) platform receives an authorization request message sent by an IoT device. The IoT device deploys encrypted target content. The authorization request message carries the device identifier and authentication code of the IoT device. Then, based on the device identifier and authentication code, the IoT device is verified. After the verification of the IoT device is passed, a first authorization license for the IoT device is generated and sent to the IoT device, so that the IoT device decrypts and uses the target content with the first authorization license, realizing lightweight authorization management and content protection for IoT devices. It can not only perform automated authorization management on IoT devices and protect the security of content through encryption means, but also reduce the performance loss of IoT devices and the impact on the network where they are located. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions of the present invention, the drawings required for the description of the present invention will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0042] Figure 1a It is a schematic diagram of an IoT system architecture provided by an embodiment of the present invention;

[0043] Figure 1b It is a flowchart of the steps of an authorization license example provided by an embodiment of the present invention;

[0044] Figure 2 It is a flowchart of the steps of a data processing method based on the Internet of Things provided by an embodiment of the present invention;

[0045] Figure 3 It is a flowchart of the steps of another data processing method based on the Internet of Things provided by an embodiment of the present invention;

[0046] Figure 4 It is a flowchart of the steps of another data processing method based on the Internet of Things provided by an embodiment of the present invention;

[0047] Figure 5 It is a block diagram of the structure of a data processing device based on the Internet of Things provided by an embodiment of the present invention;

[0048] Figure 6 It is a block diagram of the structure of another data processing device based on the Internet of Things provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0049] To make the above objects, features, and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are part of the present invention, not all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0050] In the field of the Internet of Things, the security of core technologies and algorithms can be protected and their use can be controlled by means of a hardware encryption lock or a software registration code, but both of these methods have certain limitations.

[0051] Among them, the method of using a hardware encryption lock is to manage the authorization of the hardware encryption lock software to prevent unauthorized use or resist piracy threats and protect the source code and algorithms. It has the following disadvantages:

[0052] 1. It is suitable for traditional one-time permanent authorization and cannot easily implement trial versions and usage on demand.

[0053] 2. It requires an additional separate peripheral hardware, increasing the usage and maintenance costs.

[0054] 3. It is not suitable for the fragmented scenarios of Internet of Things devices and cannot achieve a unified hardware interface.

[0055] Among them, the method of using a software registration code is to use the unique serial number of the device hardware as the registration source, and generate a registration code through an algorithm in combination with product information and usage restrictions to ensure that the software is not pirated. It has the following disadvantages:

[0056] 1. Operations such as device hardware information collection, registration, and registration code activation are required, and real-time automatic activation and authorization cannot be achieved.

[0057] 2. To ensure security, the algorithm for generating the registration code is generally relatively complex, and the requirements for device performance are relatively high.

[0058] 3. Many IoT devices do not provide a human-computer interaction interface, and the software registration code method has low universality.

[0059] In the embodiments of the present invention, a lightweight device authorization management and content protection for the Internet of Things is designed to provide automated authorization management for a large number of IoT devices, protect the security of content through certain encryption means, and at the same time reduce performance loss and network impact.

[0060] Such as Figure 1a , the IoT management platform (i.e., the Internet of Things platform) can establish a message channel with the IoT terminal device (i.e., the Internet of Things terminal) and can call the authorization management service to issue permissions.

[0061] Among them, the IoT management platform has the following functions:

[0062] 1. Provide content management (encryption, deployment).

[0063] 2. Provide authorization management corresponding to the content (permission configuration).

[0064] 3. Provide IoT device management and a unified message channel between the cloud and the device end.

[0065] The authorization management service has the following functions:

[0066] 1. Provide basic interfaces for content encryption and permission management.

[0067] 2. Provide an interface for processing device authorization messages.

[0068] 3. Provide integrated security protection (such as device authentication, message encryption).

[0069] The IoT terminal device has the following functions:

[0070] 1. Use the content to achieve specific functional purposes.

[0071] 2. Carry an authorization SDK (Software Development Kit), and be responsible for license application, secure storage, license verification, and content decryption.

[0072] Such as Figure 1b , specifically, it may include the following steps:

[0073] 1.1. The IoT management platform calls the encryption interface of the authorization management service;

[0074] 1.2. The authorization management service encrypts the original content (i.e., the target content), and at the same time generates a corresponding original license file (i.e., the second authorization license).

[0075] 1.3. The authorization management service sends the encrypted content and the license identifier of the original license file to the IoT management platform.

[0076] 2.1. The IoT management platform calls the authorization management service for content license configuration.

[0077] 2.2. The authorization management service generates a formal content license (i.e., the third authorization license) according to the configured content (i.e., the authorization license configuration information).

[0078] 3.1. Establish a message transmission channel (i.e., the message channel) between the IoT terminal device and the IoT management platform.

[0079] 3.2. The IoT terminal device triggers the use of the encrypted content.

[0080] 3.3. The IoT terminal device calls the authorization SDK to load and verify the local license.

[0081] 3.4.1. The authorization SDK obtains the terminal identification ID (i.e., the device identification) and the authentication code.

[0082] 3.4.2. The authorization SDK generates the device authorization request data (i.e., the authorization request message).

[0083] 3.4.3. The authorization SDK uploads the device authorization request data to the IoT management platform.

[0084] 3.4.4. The IoT management platform sends the device authorization request data to the authorization management service.

[0085] 3.4.5. The authorization management service performs the authorization message authentication and verification (i.e., verifies the IoT device).

[0086] 3.4.6. The authorization management service executes the device authorization and generates the device authorization license (i.e., the first authorization license).

[0087] 3.4.7. The authorization management service distributes the device authorization license to the authorization SDK through the IoT management platform.

[0088] 3.4.8. The authorization SDK encrypts and stores the device authorization license, binds it to the IoT terminal device, and provides it for the IoT terminal device to use.

[0089] Compared with the hardware encryption lock method, the technical solution provided by the embodiment of the present invention has the following advantages:

[0090] 1. It can provide various forms of authorization, such as trial authorization, authorization by time period, etc.

[0091] 2. There is no need to add and maintain additional hardware, and the cost is low.

[0092] 3. It only needs to be integrated at the software level and can be applied to various IoT devices.

[0093] Compared with the software registration code method, the technical solution provided by the embodiment of the present invention has the following advantages:

[0094] 1. It can complete real-time automatic activation and authorization through networking.

[0095] 2. It is protected by lightweight encryption through ID2 (Internet Device ID, the trusted identity identifier of the IoT device) and is suitable for various IoT devices.

[0096] 3. When the device is in use, it automatically judges and executes without the need for human-computer interaction.

[0097] Reference Figure 2 , showing a step flow chart of a data processing method based on the Internet of Things provided by an embodiment of the present invention, which can be applied to the Internet of Things platform.

[0098] Specifically, the following steps may be included:

[0099] Step 201: receiving an authorization request message sent by an IoT device, where the IoT device is deployed with encrypted target content, and the authorization request message carries a device identification and authentication code of the IoT device.

[0100] The target content may be an algorithm or code of a related technology integrated into an IoT device, such as an algorithm or code of a speech recognition technology or an image recognition technology.

[0101] The device identification may include the device hardware ID, which is a unique identification solidified in the hardware during the production process and cannot be tampered with or erased.

[0102] The authentication code can be a one-time authentication data generated based on the authentication key or device trust root of the IoT device. An authentication code must be generated each time it is used for authentication. The authentication key or device trust root is data that is always stored in the IoT device. When the IoT device does not have an authentication key / device information root, it can be sent to the device through the IoT platform (when the device is used for the first time).

[0103] The authentication key or device root of trust can be used to generate an authentication code. For example, the authentication key or device root of trust can be ID2, which is a trusted identity identifier of an IoT device and has the security attributes of being tamper-proof, unforgeable, and globally unique.

[0104] When the IoT device triggers the use of encrypted target content, it is necessary to load and verify the authorization license for the encrypted target content. If an abnormal situation occurs during the loading or verification process, the IoT device can authorize the preset SDK to automatically trigger the license application and update process, and then obtain the device identification and authentication code of the IoT device. Then, based on the device identification and authentication code of the IoT device, an authorization request message for the target content can be generated and sent to the IoT platform. The IoT platform can receive the authorization request message.

[0105] It should be noted that when the authentication code does not exist, the authentication code can be sent empty.

[0106] As an example, abnormal conditions that occur during loading or verification include any of the following:

[0107] There is no authorization license for the encrypted target content stored locally in the Internet of Things device (such as when the Internet of Things device is used for the first time or the local cache of the Internet of Things device is damaged), or the authorization license for the encrypted target content stored locally in the Internet of Things device has expired (such as the authorization license time has expired).

[0108] In one example, when there is no abnormal situation during the loading or verification process, that is, the Internet of Things device locally stores an authorization license for the encrypted target content and the authorization license is valid, the encrypted target content can be directly encrypted based on the locally stored authorization license, and the capabilities provided by the target content can be used within the authorization scope of the first authorization license to complete the corresponding functions.

[0109] In an embodiment of the present invention, before receiving the authorization request message sent by the Internet of Things device, the following steps may further be included:

[0110] After the Internet of Things device is started, a message channel with the Internet of Things device is established.

[0111] In order to realize the message interaction between the Internet of Things device and the Internet of Things platform, after the Internet of Things device is started, a message channel between the Internet of Things platform and the Internet of Things device can be established.

[0112] Step 202: Verify the Internet of Things device according to the device identifier and the authentication code, and after the verification of the Internet of Things device is passed, generate a first authorization license for the Internet of Things device.

[0113] After obtaining the device identifier and the authentication code, the Internet of Things platform can call the preset authorization management service to verify the Internet of Things device. Specifically, it can be verified through the device identifier and the authentication code. The authentication code generated based on the authentication key or the device trust root (ID2) of the Internet of Things device provides a one-device-one-secret device authentication mechanism.

[0114] In the case where the verification of the Internet of Things device fails, the authorization license can be directly refused, and a verification failure message can be returned to the Internet of Things device without performing subsequent operations. In the case where the verification of the Internet of Things device is passed, a first authorization license for the Internet of Things device can be generated for specific device authorization operations.

[0115] In an embodiment of the present invention, before generating the first authorization license for the Internet of Things device, the following steps may further be included:

[0116] Generate a second authorization license for the target content. The second authorization license includes the key information for encrypting the target content; obtain the authorization license configuration information, and generate a third authorization license according to the second authorization license and the authorization license configuration information.

[0117] Among them, the third authorization license includes the second authorization license and authorization license configuration information.

[0118] As an example, the authorization license configuration information may include, but is not limited to, the following:

[0119] The number of devices of the authorization license, the valid duration information of the authorization license.

[0120] When encrypting the target content, the key information for encrypting the target content can be obtained, and then according to the key information, the second authorization license for the target content can be generated.

[0121] Since for specific products and requirements, corresponding authorization license configurations can be made, the input authorization license configuration information can be received, and then according to the second authorization license and the authorization license configuration information, the third authorization license for the target content can be generated. The third authorization license may include the second authorization license and the authorization license configuration information.

[0122] In an embodiment of the present invention, generating the first authorization license for an Internet of Things device may include the following steps:

[0123] Generate the first authorization license for the Internet of Things device according to the third authorization license.

[0124] In practical applications, the second authorization license may be the original license, and the third authorization license may be the formal license after adding the authorization license configuration information. It may be a template for the authorization license. Then, based on the third authorization license, the first authorization license for a specific Internet of Things device can be generated, and this first authorization license can only be used by this specific Internet of Things device.

[0125] In an embodiment of the present invention, before generating the second authorization license for the target content, the following steps may further be included:

[0126] Obtain the target content; encrypt the target content and deploy the encrypted target content to the Internet of Things device.

[0127] For the target content that needs security protection and usage control, since it will be integrated and run in the Internet of Things device, the pre-set authorization management service can be called to encrypt the target content, and then according to the actual scenario, it can be deployed in the Internet of Things device.

[0128] Step 203, send the first authorization license to the Internet of Things device so that the Internet of Things device decrypts and uses the target content with the first authorization license.

[0129] After obtaining the first authorization license, the first authorization license can be sent to the Internet of Things device. Specifically, the key of the Internet of Things device can be used to encrypt the first authorization license and then distribute it. After receiving the encrypted first authorization license, the Internet of Things device can decrypt it to obtain the first authorization license.

[0130] After obtaining the first authorization license, the Internet of Things device can use the first authorization license to encrypt the encrypted target content, and can use the capabilities provided by the target content within the authorization scope of the first authorization license to complete corresponding functions.

[0131] In one example, after receiving the first authorization license, the Internet of Things device can store the first authorization license locally and bind the first authorization license to the Internet of Things device. Specifically, it can be bound based on the authentication key of the Internet of Things device or the device trust root (ID2). Through the one-device-one-key feature based on the authentication key of the Internet of Things device or the device trust root (ID2), it is ensured that the authorization license stored locally cannot be copied to other devices for misuse, providing high-security protection for the entire life cycle of the authorization license.

[0132] In the embodiment of the present invention, the Internet of Things platform receives an authorization request message sent by the Internet of Things device. The Internet of Things device deploys encrypted target content. The authorization request message includes the device identifier and authentication code of the Internet of Things device. Then, according to the device identifier and authentication code, the Internet of Things device is verified. After the verification of the Internet of Things device is passed, a first authorization license for the Internet of Things device is generated and sent to the Internet of Things device, so that the Internet of Things device uses the first authorization license to decrypt and use the target content, realizing lightweight authorization management and content protection for the Internet of Things device. It can not only perform automated authorization management on the Internet of Things device, protect the security of the content through encryption means, but also reduce the performance loss of the Internet of Things device and the impact on the network where it is located.

[0133] Refer to Figure 3 , which shows the step flowchart of another data processing method based on the Internet of Things provided by an embodiment of the present invention. This method can be applied to the Internet of Things platform.

[0134] Specifically, it can include the following steps:

[0135] Step 301, obtain the target content.

[0136] Step 302, encrypt the target content to deploy the encrypted target content to the Internet of Things device.

[0137] Step 303, generate a second authorization license for the target content. The second authorization license includes the key information for encrypting the target content.

[0138] Step 304: Obtain the authorization license configuration information, and generate a third authorization license according to the second authorization license and the authorization license configuration information; wherein, the third authorization license includes the second authorization license and the authorization license configuration information.

[0139] Step 305: After the IoT device is started, establish a message channel with the IoT device.

[0140] Step 306: Receive an authorization request message sent by the IoT device. The IoT device deploys encrypted target content, and the authorization request message includes the device identifier and authentication code of the IoT device.

[0141] Step 307: Verify the IoT device according to the device identifier and the authentication code, and after the verification of the IoT device is passed, generate a first authorization license for the IoT device according to the third authorization license.

[0142] Step 308: Send the first authorization license to the IoT device so that the IoT device decrypts and uses the target content with the first authorization license.

[0143] Refer to Figure 4 , which shows a flowchart of steps of another data processing method based on the Internet of Things provided by an embodiment of the present invention. This method can be applied to an IoT device, and the IoT device deploys encrypted target content.

[0144] Specifically, it may include the following steps:

[0145] Step 401: When triggering the use of encrypted target content, send an authorization request message to the IoT platform. The authorization request message carries the device identifier and authentication code of the IoT device.

[0146] Wherein, the authentication code is one-time authentication data generated based on the authentication key or device trust root of the IoT device, and the IoT device generates an authentication code once every time it uses the authentication code for authentication.

[0147] Wherein, an abnormal situation occurring during the loading or verification process includes any one of the following:

[0148] The IoT device does not locally store an authorization license for the encrypted target content, and the authorization license for the encrypted target content locally stored by the IoT device has expired.

[0149] In an embodiment of the present invention, when triggering the use of encrypted target content and sending an authorization request message to the IoT platform, it may include:

[0150] When triggering the use of encrypted target content, load and verify the authorization license for the encrypted target content, and when an abnormal situation occurs during the loading or verification process, send an authorization request message to the IoT platform.

[0151] Step 402: Receive the first authorization license sent by the Internet of Things platform, and use the first authorization license to decrypt and use the target content; wherein, the first authorization license is generated by the Internet of Things platform for the Internet of Things device after verifying the Internet of Things device according to the device identifier and the authentication code.

[0152] In an embodiment of the present invention, the following steps may further be included:

[0153] Store the first authorization license locally and bind it to the Internet of Things device.

[0154] It should be noted that for the method embodiments, for simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequence, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0155] Refer to Figure 5 , which shows a schematic structural diagram of a device for data processing based on the Internet of Things provided by an embodiment of the present invention. The device can be applied to the Internet of Things platform.

[0156] Specifically, the following modules may be included:

[0157] An authorization request message receiving module 501, configured to receive an authorization request message sent by an Internet of Things device. The Internet of Things device deploys encrypted target content, and the authorization request message carries the device identifier and the authentication code of the Internet of Things device.

[0158] A first authorization license generating module 502, configured to verify the Internet of Things device according to the device identifier and the authentication code, and generate a first authorization license for the Internet of Things device after the verification of the Internet of Things device passes.

[0159] A first authorization license sending module 503, configured to send the first authorization license to the Internet of Things device, so that the Internet of Things device decrypts and uses the target content with the first authorization license.

[0160] In an embodiment of the present invention, the following may further be included:

[0161] A second authorization license generating module, configured to generate a second authorization license for the target content. The second authorization license includes key information for encrypting the target content.

[0162] A third authorization license generation module, configured to obtain authorization license configuration information, and generate a third authorization license according to the second authorization license and the authorization license configuration information; wherein, the third authorization license includes the second authorization license and the authorization license configuration information.

[0163] The first authorization license generation module 502 may include:

[0164] A first license generation sub-module for generating a first authorization license for the Internet of Things device according to the third authorization license.

[0165] In an embodiment of the present invention, it may further include:

[0166] A target content acquisition module, configured to acquire target content.

[0167] A target content encryption module, configured to encrypt the target content and deploy the encrypted target content to the Internet of Things device.

[0168] In an embodiment of the present invention, the authorization license configuration information may include but is not limited to the following:

[0169] The device quantity information of the authorization license, the valid duration information of the authorization license.

[0170] In an embodiment of the present invention, it may further include:

[0171] A message channel establishment module, configured to establish a message channel with the Internet of Things device after the Internet of Things device is started.

[0172] In an embodiment of the present invention, the authentication code is one-time authentication data generated based on the authentication key or the device trust root of the Internet of Things device, and the Internet of Things device generates an authentication code each time it uses the authentication code for authentication.

[0173] Refer to Figure 6 , which shows a schematic structural diagram of a data processing device based on the Internet of Things provided by an embodiment of the present invention. The device can be applied to the Internet of Things device, and the encrypted target content is deployed to the Internet of Things device.

[0174] Specifically, it may include the following modules:

[0175] An authorization request message sending module 601, configured to send an authorization request message to the Internet of Things platform when triggering the use of the encrypted target content. The authorization request message includes the device identifier and the authentication code of the Internet of Things device.

[0176] The first authorization permission receiving module 602 is configured to receive the first authorization permission sent by the Internet of Things platform, decrypt and use the target content with the first authorization permission; wherein, the first authorization permission is generated by the Internet of Things platform for the Internet of Things device after verifying the Internet of Things device according to the device identifier and the authentication code and passing the verification of the Internet of Things device.

[0177] In an embodiment of the present invention, it may further include:

[0178] The storage and binding module is configured to store the first authorization permission locally and bind it to the Internet of Things device.

[0179] In an embodiment of the present invention, the abnormal situations occurring during the loading or verification process include any one of the following:

[0180] The authorization permission for the encrypted target content is not stored locally in the Internet of Things device, and the authorization permission for the encrypted target content stored locally in the Internet of Things device has expired.

[0181] In an embodiment of the present invention, the authorization request message sending module 601 may include:

[0182] The abnormal detection sub-module is configured to load and verify the authorization permission for the encrypted target content when triggering the use of the encrypted target content, and send an authorization request message to the Internet of Things platform when an abnormal situation occurs during the loading or verification process.

[0183] In an embodiment of the present invention, the authentication code is one-time authentication data generated based on the authentication key or the device trust root of the Internet of Things device, and the Internet of Things device generates an authentication code each time it uses the authentication code for authentication.

[0184] An embodiment of the present invention further provides an electronic device, which may include a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, the above-mentioned data processing method based on the Internet of Things is implemented.

[0185] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by the processor, the above-mentioned data processing method based on the Internet of Things is implemented.

[0186] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For the relevant parts, please refer to the partial description of the method embodiment.

[0187] Each embodiment in this specification is described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other.

[0188] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, an apparatus, or a computer program product. Therefore, the embodiments of the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) that contain computer-usable program code.

[0189] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in one or more flows in the flowchart and / or one or more blocks in the block diagram.

[0190] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in one or more flows in the flowchart and / or one or more blocks in the block diagram.

[0191] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one or more flows in the flowchart and / or one or more blocks in the block diagram.

[0192] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.

[0193] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or terminal device comprising said element.

[0194] The above provides a detailed introduction to a data processing method and device based on the Internet of Things. Specific examples are used in this article to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A data processing method based on the Internet of Things, characterized in that Applied to the Internet of Things platform, the method includes: Receiving an authorization request message sent when an abnormal situation occurs during the process of loading or verifying the authorization permission for the encrypted target content triggered by the Internet of Things device. The Internet of Things device deploys the encrypted target content, and the authorization request message carries the device identifier and authentication code of the Internet of Things device; wherein, the target content is an algorithm or code integrated in the Internet of Things device; Verifying the Internet of Things device according to the device identifier and the authentication code, and generating a first authorization permission for the Internet of Things device after the verification of the Internet of Things device passes; Sending the first authorization permission to the Internet of Things device so that the Internet of Things device decrypts and uses the target content with the first authorization permission.

2. The method according to claim 1, wherein Before generating the first authorization permission for the Internet of Things device, it further includes: Generating a second authorization permission for the target content, and the second authorization permission includes key information for encrypting the target content; Obtaining authorization permission configuration information, and generating a third authorization permission according to the second authorization permission and the authorization permission configuration information; wherein, the third authorization permission includes the second authorization permission and the authorization permission configuration information; The generating of the first authorization permission for the Internet of Things device includes: Generating a first authorization permission for the Internet of Things device according to the third authorization permission.

3. The method according to claim 2, wherein Before generating the second authorization permission for the target content, it further includes: Obtaining the target content; Encrypting the target content and deploying the encrypted target content to the Internet of Things device.

4. The method according to claim 2 or 3, characterized in that, The authorization permission configuration information includes but is not limited to the following: Device quantity information of the authorization permission, valid duration information of the authorization permission.

5. The method according to claim 1, wherein Before the authorization request message sent when an abnormal situation occurs during the process of receiving the Internet of Things device triggering the use of the encrypted target content and loading or verifying the authorization permission for the encrypted target content, it further includes: After the Internet of Things device is started, establishing a message channel with the Internet of Things device.

6. The method according to claim 1, characterized in that, The authentication code is one-time authentication data generated based on the authentication key or device trust root of the Internet of Things device, and the Internet of Things device generates an authentication code each time it uses the authentication code for authentication.

7. A data processing method based on the Internet of Things, characterized in that, Applied to the Internet of Things device, the Internet of Things device deploys the encrypted target content, and the method includes: When an abnormal situation occurs during the process of triggering the use of the encrypted target content and loading or verifying the authorization permission for the encrypted target content, sending an authorization request message to the Internet of Things platform, and the authorization request message carries the device identifier and authentication code of the Internet of Things device; wherein, the target content is an algorithm or code integrated in the Internet of Things device; Receive the first authorization license sent by the Internet of Things platform, and use the first authorization license to decrypt and use the target content; wherein, the first authorization license is generated by the Internet of Things platform for the Internet of Things device after verifying the Internet of Things device according to the device identifier and the authentication code.

8. The method according to claim 7, wherein It further includes: Store the first authorization license locally and bind it to the Internet of Things device.

9. The method according to claim 7 or 8, characterized in that, Any of the following abnormal situations occur during the loading or verification process: The Internet of Things device does not locally store an authorization license for the encrypted target content, or the authorization license for the encrypted target content stored locally on the Internet of Things device has expired.

10. The method according to claim 7, wherein The authentication code is one-time authentication data generated based on the authentication key or device trust root of the Internet of Things device, and the Internet of Things device generates an authentication code each time it uses the authentication code for authentication.

11. A data processing device based on the Internet of Things, characterized in that, Applied to the Internet of Things platform, the device includes: An authorization request message receiving module, configured to receive an authorization request message sent when an abnormal situation occurs during the process of triggering the use of encrypted target content by the Internet of Things device and loading or verifying the authorization license for the encrypted target content. The Internet of Things device deploys encrypted target content, and the authorization request message carries the device identifier and authentication code of the Internet of Things device; wherein, the target content is an algorithm or code integrated in the Internet of Things device. A first authorization license generating module, configured to verify the Internet of Things device according to the device identifier and the authentication code, and generate a first authorization license for the Internet of Things device after verifying the Internet of Things device. A first authorization license sending module, configured to send the first authorization license to the Internet of Things device, so that the Internet of Things device uses the first authorization license to decrypt and use the target content.

12. A data processing device based on the Internet of Things, characterized in that, Applied to the Internet of Things device, the Internet of Things device deploys encrypted target content, and the device includes: An authorization request message sending module, configured to send an authorization request message to the Internet of Things platform when an abnormal situation occurs during the process of triggering the use of encrypted target content and loading or verifying the authorization license for the encrypted target content. The authorization request message includes the device identifier and authentication code of the Internet of Things device; wherein, the target content is an algorithm or code integrated in the Internet of Things device. A first authorization license receiving module, configured to receive the first authorization license sent by the Internet of Things platform, and use the first authorization license to decrypt and use the target content; wherein, the first authorization license is generated by the Internet of Things platform for the Internet of Things device after verifying the Internet of Things device according to the device identifier and the authentication code.

Citation Information

Patent Citations

  • Burning verification method and device of Internet of Things device and identity authentication method and device of Internet of Things device

    CN108156126A

  • Technologies for internet of things key management

    US20210203491A1