Device Identity Authentication Method, Apparatus, Terminal, Authentication Node and Storage Medium
By using terminal device identification and decentralized keys in the Internet of Things system to generate authentication information and using hash tree verification, the problem of device authentication in the existing technology cannot be completed within the system, and efficient and secure Internet of Things device identity authentication is achieved.
Patent Information
- Application Number
- CN202110270934.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-12
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2041-03-12
AI Technical Summary
In the prior art, the device authentication process cannot be completed within the Internet of Things system, which limits the scalability of the authentication node and cannot meet the authentication requirements of IoT devices.
By reading the terminal device identifier in the user identification module of the terminal, sending an identity authentication request to the authentication node, and receiving random data, generating identity authentication information using the pre-stored scattered key and random data, sending it to the authentication node for hash tree verification, realizing identity authentication of the terminal device.
It realizes the completion of device authentication within the Internet of Things system, meets the authentication requirements of IoT devices, improves the scalability of authentication nodes and the ability to quickly copy and expand, and reduces the probability that identity authentication information is deciphered.
Smart Images

Figure CN115086958B_ABST
Abstract
Description
Background Art
[0002] The Internet of Things (IOT) refers to the use of various devices and technologies such as information sensors, radio frequency identification technology, global positioning system, infrared sensors, laser scanners, etc. to collect any objects or processes that need to be monitored, connected, and interacted with in real time. Through network access, it realizes the ubiquitous connection between things and things, and between things and people, and realizes the intelligent perception, identification, and management of items and processes. In the Internet of Things, identity authentication is one of the key factors in network security. In addition, as the information source of the Internet of Things, the security of Internet of Things devices (hereinafter referred to as devices) is also the core issue of Internet of Things security. Under normal working conditions, the Internet of Things should allow devices that have passed identity authentication to access the network and reject malicious access.
[0003] In related technologies, although identity authentication can be achieved by using a USIM card (Universal Subscriber Identity Module), this authentication method needs to be decrypted through a key system outside the Internet of Things. On the one hand, it limits the scalability of authentication nodes. On the other hand, it is also impossible to complete the authentication process within the system, so it does not meet the authentication requirements of Internet of Things devices.
[0004] It should be noted that the information disclosed in the above background art section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0005] The purpose of the present disclosure is to provide an identity authentication method, device, electronic device, and computer-readable storage medium for Internet of Things devices, which can at least to some extent improve the problem that the device authentication process cannot be completed within the system in related technologies.
[0006] Other features and advantages of the present disclosure will become apparent through the following detailed description, or will be partially learned through the practice of the present disclosure.
[0007] According to one aspect of the present disclosure, there is provided an identity authentication method for Internet of Things devices, including: reading a terminal device identifier in a user identification module of the terminal; sending an identity authentication request to an authentication node of the Internet of Things, where the identity authentication request includes the terminal device identifier; receiving random data fed back by the authentication node based on the identity authentication request; feeding back the random data to the user identification module so that the user identification module generates identity authentication information based on a pre-stored dispersion key and the random data; obtaining the identity authentication information and sending the identity authentication information to the authentication node so that the authentication node authenticates the identity authentication information based on a pre-stored hash tree and generates an identity authentication result of the terminal; and receiving the identity authentication result fed back by the authentication node.
[0008] In one embodiment, the generating, by the user identification module, the identity authentication information based on the pre-stored dispersion key and the random data includes: the user identification module performing a hash calculation on the dispersion key to obtain a first hash value; the user identification module performing a hash calculation on the random data to obtain a second hash value; and the user identification module performing a hash calculation on the sum of the first hash value and the second hash value to obtain the identity authentication information.
[0009] In one embodiment, the dispersion key and the terminal device identifier are filled into the user identification module based on a key filling system of a data center.
[0010] According to another aspect of the present disclosure, there is provided an identity authentication method for Internet of Things devices, including: receiving an identity authentication request sent by a terminal, generating random data based on the identity authentication request; sending the random data to the terminal and receiving identity authentication information generated by the terminal according to the random data; extracting a terminal device identifier carried in the identity authentication request; querying a preset hash value matching the terminal device identifier in a pre-stored hash tree; generating verification reference information based on the preset hash value and the random data; authenticating the identity authentication information based on the verification reference information and generating an identity authentication result of the terminal; and sending the identity authentication result to the terminal.
[0011] In one embodiment, the querying, in the pre-stored hash tree, the preset hash value matching the terminal device identifier includes: querying whether location information of the terminal device identifier is cached locally; and if the location information of the terminal device identifier is cached, querying, based on the location information, the preset hash value matching the terminal device identifier in the hash tree.
[0012] In one embodiment, it further includes: if the location information of the terminal device identifier is not cached, sending a location information query request to the root location server of the hash tree, so that the root location server performs a recursive query operation until the address of the authorized location server storing the hash tree is queried; downloading the hash tree based on the address of the authorized location server, so as to query the preset hash value matching the terminal device identifier in the hash tree based on the location information.
[0013] In one embodiment, it further includes: transmitting the preset hash value and the terminal device identifier with a corresponding relationship to the authorized location server through the root location server, so that the authorized location server converts the preset hash value and the terminal device with the corresponding relationship into leaf nodes; generating the hash tree based on the leaf nodes.
[0014] In one embodiment, the generating the verification reference information based on the preset hash value and the random data includes: performing a hash calculation on the random data to obtain a third hash value; performing a hash calculation on the sum of the preset hash value and the third hash value to obtain the verification reference information.
[0015] According to still another aspect of the present disclosure, there is provided an identity authentication device for an Internet of Things device, including: a reading module, configured to read the terminal device identifier in the user identification module of the terminal; a sending module, configured to send an identity authentication request to the authentication node of the Internet of Things, where the identity authentication request includes the terminal device identifier; a receiving module, configured to receive the random data fed back by the authentication node based on the identity authentication request; a generating module, configured to feed back the random data to the user identification module, so that the user identification module generates identity authentication information based on a pre-stored decentralized key and the random data; the sending module is further configured to obtain the identity authentication information and send the identity authentication information to the authentication node, so that the authentication node performs identity authentication on the identity authentication information based on a pre-stored hash tree and generates an identity authentication result of the terminal; the receiving module is further configured to receive the identity authentication result fed back by the authentication node.
[0016] According to another aspect of the present disclosure, there is provided an Internet of Things device identity authentication apparatus for Internet of Things devices, including: a receiving module, configured to receive an identity authentication request sent by a terminal and generate random data based on the identity authentication request; a sending module, configured to send the random data to the terminal and receive the identity authentication information generated by the terminal according to the random data; an extraction module, configured to extract the terminal device identifier carried in the identity authentication request; a query module, configured to query a preset hash value matching the terminal device identifier in a pre-stored hash tree; a generation module, configured to generate verification reference information based on the preset hash value and the random data; a verification module, configured to perform identity verification on the identity authentication information based on the verification reference information and generate an identity verification result of the terminal; and the sending module is further configured to send the identity verification result to the terminal.
[0017] According to another aspect of the present disclosure, there is provided a terminal, including: a processor; and a memory, configured to store executable instructions of the processor; wherein, the processor is configured to execute the Internet of Things device identity authentication method according to any one of the above first aspects by executing the executable instructions.
[0018] According to another aspect of the present disclosure, there is provided an authentication node, including: a processor; and a memory, configured to store executable instructions of the processor; wherein, the processor is configured to execute the Internet of Things device identity authentication method according to any one of the above second aspects by executing the executable instructions.
[0019] According to another aspect of the present disclosure, there is provided a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the Internet of Things device identity authentication method according to any one of the above is implemented.
[0020] The Internet of Things device identity authentication solution provided by the embodiments of the present disclosure is such that the Internet of Things device initiates an identity authentication request. After receiving the terminal device identifier, the authentication node generates random data and feeds it back to the USIM card in the Internet of Things device. The USIM card performs a hash operation based on the pre-stored dispersion key and the random data to generate identity authentication information, and the Internet of Things device sends the identity authentication information to the authentication node. The authentication node can generate verification reference information based on the hash tree and the received terminal device identifier, and use the verification reference information as a reference to compare with the received identity authentication information to implement the verification of the identity authentication information.
[0021] Based on this authentication method, on the one hand, there is no need for an external key system to perform encryption and decryption operations, and the identity authentication of Internet of Things devices can be completed within the Internet of Things, thus meeting the authentication requirements of Internet of Things devices. On the other hand, based on the characteristics of flexible generation, non-tampering, and fast searching of the hash tree, flexible configuration and rapid replication and expansion of authentication nodes can be achieved. On the further hand, by introducing random data into the identity authentication process and combining the confusion of the distributed key with the random data, the probability of the identity authentication information being deciphered during the identity authentication process can be reduced.
[0022] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit the present disclosure. Brief Description of the Drawings
[0023] The drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.
[0024] Figure 1 A schematic diagram showing the structure of an Internet of Things device identity authentication system in an embodiment of the present disclosure;
[0025] Figure 2 A flowchart showing an Internet of Things device identity authentication method in an embodiment of the present disclosure;
[0026] Figure 3 A flowchart showing another Internet of Things device identity authentication method in an embodiment of the present disclosure;
[0027] Figure 4 A flowchart showing a method for verifying the identity validity of an Internet of Things device in an embodiment of the present disclosure;
[0028] Figure 5 An interaction flowchart showing an Internet of Things device identity authentication method in an embodiment of the present disclosure;
[0029] Figure 6 An interaction flowchart showing another Internet of Things device identity authentication method in an embodiment of the present disclosure;
[0030] Figure 7 A structural diagram showing an Internet of Things device identity authentication system in an embodiment of the present disclosure;
[0031] Figure 8 A schematic diagram showing an Internet of Things device identity authentication system in an embodiment of the present disclosure;
[0032] Figure 9Schematic diagram showing an Internet of Things device identity authentication apparatus in an embodiment of the present disclosure;
[0033] Figure 10 Schematic diagram showing another Internet of Things device identity authentication apparatus in an embodiment of the present disclosure;
[0034] Figure 11 Schematic diagram showing an electronic device in an embodiment of the present disclosure. Detailed implementation manners
[0035] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments.
[0036] In addition, the drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in the form of software, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0037] For ease of understanding, several terms related to the present application will be explained first below.
[0038] SDK: Software Development Kit, which refers to a collection of development tools for software engineers to build application software for specific software packages, software frameworks, hardware platforms, operating systems, etc.
[0039] Hash, generally translated as hash, or transliterated as hash, is to transform an input of any length (also called pre-image) into an output of a fixed length through a hashing algorithm. This output is the hash value. This transformation is a compression mapping, that is, the space of the hash value is usually much smaller than the space of the input, and different inputs may be hashed into the same output, so it is impossible to determine the unique input value from the hash value. Simply put, it is a function that compresses a message of any length into a message digest of a certain fixed length.
[0040] A hash tree (hash tree; Merkle tree) is a tree - shaped data structure in cryptography and computer science. Each leaf node is labeled with the hash of a data block, while nodes other than leaf nodes are labeled with the cryptographic hash of the labels of their child nodes. A hash tree can efficiently and securely verify the content of large data structures. The concept of the hash tree was patented by Ralph Merkle in 1979, so it is also called the Merkle tree.
[0041] The top of the hash tree is the top hash, also known as the root hash or master hash. As long as any leaf node changes, the root hash will change. In a block, all transactions are organized in the format of a Merkle Tree and then corresponded with the hashMerkleTreeRoot in the block header, which can ensure the immutability of the transaction information in this block.
[0042] DNS (Domain Name System) is a system on the Internet for solving the naming of online machines. Just like you need to know how to get to a friend's house before visiting, when a host on the Internet wants to access another host, it must first know its address. The IP address in TCP / IP consists of four numbers separated by dots (here taking the IPv4 address as an example, and the IPv6 address is the same). It is always less convenient to remember than a name. Therefore, the domain name system is adopted to manage the correspondence between names and IPs.
[0043] Diversified key: The key diversification algorithm is abbreviated as Diversify. It means to perform a diversification process on a double - length (a key with a length of 8 bytes) master key (MK) for data to derive a double - length DES encryption key (DK) to generate a diversified key. Among them, the method for deriving the left half of DK is: using the right - most 8 bytes of the diversified data as the input data; using MK as the encryption key; performing 3DES operation on the input data with MK to obtain the left half of DK. The method for deriving the right half of DK is: inverting the right - most 8 bytes of the diversified data as the input data; using MK as the encryption key; performing 3DES operation on the input data with MK to obtain the right half of DK.
[0044] The solution provided in the embodiments of this application relates to technologies such as security authentication, and will be specifically described through the following embodiments.
[0045] Figure 1 Fig. shows a schematic structural diagram of an Internet of Things device identity authentication system in an embodiment of the present disclosure, including a plurality of terminals 120 and an authentication node 140.
[0046] The terminal 120 may be a mobile terminal such as a mobile phone, a game console, a tablet computer, an e - book reader, smart glasses, an MP4 (Moving Picture Experts Group Audio Layer IV) player, a smart home device, an AR (Augmented Reality) device, a VR (Virtual Reality) device, etc. Or, the terminal 120 may also be a personal computer (PC), such as a laptop computer and a desktop computer, etc.
[0047] Among them, an application program for providing identity authentication of Internet of Things devices may be installed in the terminal 120.
[0048] The terminal 120 is connected to the authentication node 140 through a communication network. Optionally, the communication network is a wired network or a wireless network.
[0049] The authentication node 140 is a server, or consists of several servers, or is a virtualization platform, or is a cloud computing service center. The authentication node 140 is used to provide background services for the application program for providing identity authentication of Internet of Things devices. Optionally, the authentication node 140 undertakes the main computing work and the terminal 120 undertakes the secondary computing work; or, the authentication node 140 undertakes the secondary computing work and the terminal 120 undertakes the main computing work; or, a distributed computing architecture is adopted between the terminal 120 and the authentication node 140 for collaborative computing.
[0050] In some alternative embodiments, the authentication node 140 is used to store the identity authentication model of Internet of Things devices, etc.
[0051] Optionally, the clients of the application programs installed in different terminals 120 are the same, or the clients of the application programs installed on two terminals 120 are clients of the same type of application program on different control system platforms. Based on the differences in terminal platforms, the specific form of the client of this application program may also be different. For example, the client of this application program may be a mobile phone client, a PC client, or a World Wide Web (Web) client, etc.
[0052] Those skilled in the art can know that the number of the above - mentioned terminals 120 can be more or less. For example, there may be only one of the above - mentioned terminals, or there may be dozens or hundreds of the above - mentioned terminals, or even more. The embodiments of this application do not limit the number and device types of the terminals.
[0053] Optionally, the system may further include a management device ( Figure 1(not shown), the management device is connected to the authentication node 140 through a communication network. Optionally, the communication network is a wired network or a wireless network.
[0054] Optionally, the above-mentioned wireless network or wired network uses standard communication technologies and / or protocols. The network is usually the Internet, but can also be any network, including but not limited to any combination of a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or a virtual private network). In some embodiments, technologies and / or formats including Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML), etc. are used to represent the data exchanged through the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPsec), etc. can be used to encrypt all or some of the links. In other embodiments, customized and / or proprietary data communication technologies can also be used to replace or supplement the above data communication technologies.
[0055] Next, each step in the Internet of Things device identity authentication method in this exemplary embodiment will be described in more detail with reference to the accompanying drawings and embodiments.
[0056] Figure 2 The flowchart of an Internet of Things device identity authentication method in an embodiment of the present disclosure is shown. The method provided by the embodiment of the present disclosure can be executed by any electronic device with computing and processing capabilities, such as Figure 1 the terminal 120 and / or the authentication node 140 in. In the following illustrative examples, the terminal 120 is used as the execution subject for illustration.
[0057] Such as Figure 2 shown, the terminal 120, specifically an Internet of Things device, executes the Internet of Things device identity authentication method, including the following steps:
[0058] Step S202, read the terminal device identifier in the user identification module of the terminal.
[0059] Among them, the user identification module may specifically be an IoT USIM card installed in the IoT device. The terminal device identifier and the distributed key bound to the terminal device identifier are stored in the user identification module.
[0060] The terminal device identifier may specifically be the serial number of the terminal device encoded based on the device type, device manufacturer, and production batch of the IoT device.
[0061] Step S204: Send an identity authentication request to the authentication node of the IoT. The identity authentication request includes the terminal device identifier.
[0062] Among them, an identity authentication request is generated based on the terminal device identifier to initiate the identity authentication process of the IoT device by sending the identity authentication request. The identity authentication process is completed through information interaction with the authentication node.
[0063] Step S206: Receive the random data fed back by the authentication node based on the identity authentication request.
[0064] Among them, by receiving the random data sent by the authentication node and making the random data participate in the identity authentication process, it can play a confusing role.
[0065] Step S208: Feed back the random data to the user identification module so that the user identification module generates identity authentication information based on the pre-stored distributed key and the random data.
[0066] Among them, by generating identity authentication information based on the distributed key and the random data, combined with the confusion of the random data by the distributed key, the probability of the identity authentication information being deciphered during the identity authentication process can be reduced.
[0067] Step S210: Obtain the identity authentication information and send the identity authentication information to the authentication node so that the authentication node authenticates the identity authentication information based on the pre-stored hash tree and generates the identity authentication result of the terminal.
[0068] Step S212: Receive the identity authentication result fed back by the authentication node.
[0069] As Figure 3 shown, the authentication node 140 executes the IoT device identity authentication method, including the following steps:
[0070] Step S302: Receive the identity authentication request sent by the terminal and generate random data based on the identity authentication request.
[0071] Step S304: Send the random data to the terminal and receive the identity authentication information generated by the terminal according to the random data.
[0072] Step S306: Extract the terminal device identifier carried in the identity authentication request.
[0073] Step S308: Query in the pre-stored hash tree for a preset hash value that matches the terminal device identifier.
[0074] Step S310: Generate verification reference information based on the preset hash value and random data.
[0075] Step S312: Authenticate the identity authentication information based on the verification reference information and generate an identity authentication result for the terminal.
[0076] Step S314: Send the identity authentication result to the terminal.
[0077] In this embodiment, the Internet of Things includes terminals, i.e., Internet of Things devices, and authentication nodes. The Internet of Things devices are installed with Internet of Things USIM cards, and the USIM cards store dispersion keys and terminal device identifiers representing the Internet of Things devices. An identity authentication request is initiated by the Internet of Things device. After receiving the terminal device identifier, the authentication node generates random data and feeds it back to the USIM card in the Internet of Things device. The USIM card performs a hash operation based on the pre-stored dispersion key and the random data to generate identity authentication information, and the Internet of Things device sends the identity authentication information to the authentication node. The authentication node can generate verification reference information based on the hash tree and the received terminal device identifier, and use the verification reference information as a reference to compare with the received identity authentication information to achieve the verification of the identity authentication information.
[0078] Based on this identity authentication method, on the one hand, there is no need for an external key system to perform encryption and decryption operations, and the identity authentication of Internet of Things devices can be completed only within the Internet of Things, thus meeting the authentication requirements of Internet of Things devices. On the other hand, based on the characteristics of flexible generation, non-tamperability, and fast search of the hash tree, flexible configuration and fast replication and expansion of authentication nodes can be achieved. On the other hand, by introducing random data into the identity authentication process and combining the confusion of the dispersion key and random data, the probability of the identity authentication information being deciphered during the identity authentication process can be reduced.
[0079] In one embodiment, in step S208, a specific implementation manner for the user identification module to generate identity authentication information based on the pre-stored dispersion key and the random data includes: the user identification module performs a hash calculation on the dispersion key to obtain a first hash value; the user identification module performs a hash calculation on the random data to obtain a second hash value; the user identification module performs a hash calculation on the sum of the first hash value and the second hash value to obtain the identity authentication information.
[0080] In one embodiment, step S310, a specific implementation manner of generating verification reference information based on a preset hash value and random data includes: performing a hash calculation on the random data to obtain a third hash value; performing a hash calculation on the sum of the preset hash value and the third hash value to obtain the verification reference information.
[0081] Specifically, during device authentication, the authentication information is generated on the USIM card side as hash(hash(spreading key)+hash(random data)), and on the authentication node side, the position of the preset hash value corresponding to the serial number is queried using the location resolution system in the hash tree, and the verification reference information is generated as hash(preset hash value + hash(random data)). The authentication information is compared with the verification reference information, and if they are consistent, the authentication passes.
[0082] In this embodiment, the present invention uses the hash algorithm, which requires very few resources for operation. The Hash algorithm has the characteristic of being irreversible. At the same time, a random number is added as "salt" for confusion during the authentication process. Even if the hash value is intercepted, it is impossible to reverse-deduce the hash value of the card spreading key, let alone the card spreading key. The authentication node can complete the device authentication process as long as it has the hash value, without going through the key system, which greatly facilitates the expansion of the authentication node.
[0083] In one embodiment, the spreading key and the terminal device identifier are loaded into the user identification module based on the key loading system of the data center.
[0084] Specifically, the key loading device uses the corresponding serial number as the terminal device identifier and loads it into each IoT USIM card together with the spreading key.
[0085] Specifically, a serial number is generated for each IoT device as the terminal device identifier. By binding the serial number to the card, within the validity period of the card, authenticating the card can achieve the authentication of the bound device.
[0086] The authentication system utilizes the computing resources of the USIM card, adopts a lightweight hash algorithm, and draws on the location query method similar to DNS. The system is easy to expand and can theoretically support an unlimited number of IoT devices.
[0087] In one embodiment, querying for a preset hash value that matches the terminal device identifier in the pre-stored hash tree includes: querying whether the location information of the terminal device identifier is cached locally; if the location information of the terminal device identifier is cached, querying for the preset hash value that matches the terminal device identifier in the hash tree based on the location information.
[0088] In one embodiment, it further includes: if the location information of the terminal device identifier is not cached, a location information query request is sent to the root location server of the hash tree, so that the root location server performs a recursive query operation until the address of the authorized location server storing the hash tree is queried; the hash tree is downloaded based on the address of the authorized location server, so as to query the preset hash value matching the terminal device identifier in the hash tree based on the location information.
[0089] Specifically, a serial number location resolution system similar to DNS is established. The serial number is similar to the domain name, and the position of the hash value corresponding to the serial number in the hash tree is similar to the domain name record.
[0090] Referring to the architecture of DNS, the resolution system is also divided into a root location server and an authorized location server. If the authentication node cannot query the position of a certain serial number in the hash tree, it can query the root server. The root server will recursively query the authorized location server where the serial number is located, and the root location server will return the address of the authorized location server to the authentication node.
[0091] The authentication node queries the location record from the authorized location server, and the authorized server returns the location record information to the authentication node. The authentication node can establish its own cache server with reference to the DNS system and save the queried serial number location record.
[0092] When receiving the device identifier, the authentication node will first check whether the location record mapping of the device identifier is cached locally. If so, it will first call this location record mapping to obtain the hash value corresponding to the device identifier.
[0093] If the location record mapping is not cached, a location query is made to the root server. The root server recursively queries the authorized location server where the serial number is located and feeds back the address of the authorized location server to the authentication node. The authentication node accesses the authorized location server based on the address of the authorized location server to query, which helps to reduce the number of lookups and improve the authentication speed.
[0094] In one embodiment, it further includes: transmitting the preset hash value and the terminal device identifier with a corresponding relationship to the authorized location server through the root location server, so that the authorized location server converts the preset hash value and the terminal device with a corresponding relationship into leaf nodes; generating a hash tree based on the leaf nodes.
[0095] Specifically, the encryption machine in the data center uses the root key to generate the dispersion key of the Internet of Things USIM card, and the dispersion key is then subjected to a hash operation to generate a hash value.
[0096] Establish a serial number for each Internet of Things device as the terminal identity identifier according to the Internet of Things device type, device manufacturer, production batch, etc. as the coding rule, and use this serial number as the only identity identifier for Internet of Things USIM card authentication. The data center establishes a mapping table between the serial number and the hash value of the decentralized key.
[0097] The data center transmits the corresponding list of the serial numbers of a certain batch of Internet of Things devices and the hash values of USIM cards to the authorized location server through the root location server. The authorized location server generates a hash tree, and the hash values serve as the leaves of the hash tree. The size of the hash tree can be flexibly set. The hash value of a certain USIM card can be placed on any hash tree, but it can only be placed on a unique hash tree at the same time. The authorized location server establishes a correspondence table between the serial number and the position of the hash tree where the card hash value is located.
[0098] The authenticated authentication node downloads the hash tree from the authorized location server.
[0099] In one embodiment, it further includes: transmitting the preset hash value and the terminal device identifier with a corresponding relationship to the authorized location server through the root location server, so that the authorized location server generates leaf nodes based on the preset hash value and the terminal device with a corresponding relationship, and a hash tree based on the leaf nodes.
[0100] As Figure 4 shown, before performing the identity authentication operation of the terminal device, it is necessary to authenticate the validity of the identities of the Internet of Things device 402 and the authentication platform 404, that is, to detect whether the terminal 402 and the authentication platform 404 have the ability of identity authentication. The Internet of Things device 402 includes an Internet of Things USIM card 4022 and a device SDK 4024, and the authentication platform 404 includes a data center 4042 and an authentication node 4044. Specifically, the authentication process includes:
[0101] Step S406, the Internet of Things device initiates a platform identity authentication challenge, and the sent challenge information includes the terminal device identifier and the first random data of the card.
[0102] Step S408, the authentication node searches for the decentralized key that matches the terminal device identifier, encrypts the first random data based on the decentralized key that matches the terminal device identifier to obtain the first encrypted data, and generates the second random data.
[0103] Step S410, the authentication node responds to the platform identity authentication, sends the first encrypted data to the Internet of Things device, and initiates an Internet of Things device identity authentication challenge, sending the second random data to the Internet of Things device.
[0104] Step S412, the USIM card decrypts the first encrypted data using the decentralized key and performs an identity authentication response based on the decryption result.
[0105] Step S414: The USIM card encrypts the second random data using a distributed key to generate second encrypted data.
[0106] Step S416: The Internet of Things device sends the second encrypted data to the authentication node.
[0107] Step S418: The authentication node decrypts the second encrypted data based on the distributed key matching the terminal device identifier, and determines the authentication result initiated by the authentication node based on the decryption result.
[0108] Specifically, the USIM card stores a card distributed key and a device serial number. The distributed key in the card is only used to authenticate the identity validity of the card and the authentication node before the first device authentication, and is used for direct encryption and decryption during the mutual authentication between the card and the data center.
[0109] As Figure 5 shown, the Internet of Things device includes a USIM card 502 and an Internet of Things device 504. The USIM card 502 is installed in the Internet of Things device 504. The Internet of Things device 504 interacts with the authentication node 506 to implement identity authentication. A method for implementing Internet of Things device identity authentication based on a hash tree built by the authentication node 506 includes:
[0110] Step S502: Initiate an identity authentication request.
[0111] Step S504: Determine the address of the authentication node according to the configuration information.
[0112] Step S506: Send an identity authentication request based on the address of the authentication node. The identity authentication request includes the terminal device identifier.
[0113] Step S508: Generate random data based on the identity authentication request.
[0114] Step S510: Send the random data.
[0115] Step S512: Perform a hash operation on the random data and the distributed key to generate identity verification information.
[0116] Step S514: Send the identity verification information.
[0117] Step S516: Query the location information of the hash tree corresponding to the terminal device identifier locally to determine the matching pre-stored hash value.
[0118] Step S518: Perform a hash operation on the pre-stored hash value and the random data to generate verification reference information.
[0119] Step S520: Compare whether the identity verification information and the verification reference information are consistent. If they are consistent, the verification passes.
[0120] Step S522, return the verification result.
[0121] As Figure 6 shown, the terminal includes a USIM card 602 and an Internet of Things device 604. The USIM card 602 is installed in the Internet of Things device 604. The Internet of Things device 604 interacts with an authentication node 606 to implement identity authentication. A method for using a hash tree established by a root location server 608 and an authorized location server 610 for Internet of Things device identity authentication includes:
[0122] Step S602, initiate an identity authentication request, specifically including:
[0123] Determine the address of the authentication node according to the configuration information.
[0124] Send an identity authentication request based on the address of the authentication node. The identity authentication request includes the terminal device identifier.
[0125] Step S604, generate random data based on the identity authentication request.
[0126] Step S606, send the random data.
[0127] Step S608, perform a hash operation on the random data and the dispersion key to generate identity verification information.
[0128] Step S610, send the identity verification information.
[0129] Step S612, the authentication node queries the local location cache record.
[0130] Step S614, if not found, send a location information query request to the root server.
[0131] Step S616, recursively query to the authorized location server.
[0132] Step S618, return the address information of the authorized location server.
[0133] Step S620, send a location resolution request and a hash tree data download request to the authorized location server.
[0134] Step S622, return the hash tree data to obtain the correspondence table between the terminal device identifier and the preset hash value.
[0135] Step S624, perform a hash operation on the pre-stored hash value and the random data to generate verification reference information.
[0136] Step S626, compare whether the identity verification information and the verification reference information are consistent. If they are consistent, the verification passes.
[0137] Step S628, return the verification result.
[0138] Step S630, allocate corresponding Internet of Things permissions according to the terminal device identifier.
[0139] As Figure 7 shown, the device SDK 702 is an authentication program in the Internet of Things device to perform authentication interaction with the authentication node 704 through the Internet of Things device. The authentication node 704 can communicate with the root location server 708 through the authentication center 706. The storage structure of the hash tree is as Figure 7 shown. The root location server 708 includes L first-level nodes, including the first-level location server Zone1, the first-level location server Zone2, and the first-level location server ZoneL, etc. Taking the first-level location server Zone2 as an example, the first-level location server Zone2 includes m second-level nodes, including the second-level location server Forest1, the second-level location server Forest2, and the second-level location server Forestm, etc. Taking the second-level location server Forestm as an example, the second-level location server Forestm includes n third-level nodes, including the third-level location server Wood1, the third-level location server Wood2, and the third-level location server Woodn, etc. Taking the third-level location server Treen as an example, it includes q authorized location servers storing hash trees, including the authorized location server Tree1 and the authorized location server Treeq, etc.
[0140] After obtaining the address information of the authorized location server, the authentication node 706 sends a location resolution request and a hash tree data download request to the authorized location server to obtain the hash tree data.
[0141] It should be noted that the above-mentioned drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present invention, rather than for limiting purposes. It is easy to understand that the processes shown in the above-mentioned drawings do not indicate or limit the time sequence of these processes. Additionally, it is also easy to understand that these processes can be executed synchronously or asynchronously, for example, in multiple modules.
[0142] Those skilled in the art of the relevant technical field can understand that various aspects of the present invention can be implemented as a system, a method, or a program product. Therefore, various aspects of the present invention can be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to herein as "circuit", "module", or "system".
[0143] As Figure 8 shown, the Internet of Things device identity authentication system includes the Internet of Things:
[0144] The Internet of Things device 802 includes a USIM card 802A and an application system 802B. The USIM card 802A is filled with a decentralized key and a terminal device identifier with a binding relationship through a key filling system 804. The decentralized key in the key filling system 804 is generated by using a root key based on an encryptor in a data center 806.
[0145] The decentralized key and the terminal device identifier generated by the data center 806 generate a hash tree, which is stored based on a root location server 808 and an authorized location server 810.
[0146] One of the authentication nodes 812A to 812N requests the hash tree from the root location server 808 and / or the authorized location server 810, and completes the identity authentication of the Internet of Things device 802 based on the hash tree.
[0147] The following refers to Figure 9 to describe the Internet of Things device identity authentication apparatus 900 according to this embodiment of the present invention. Figure 9 The shown Internet of Things device identity authentication apparatus 900 is merely an example and should not impose any limitation on the functions and the scope of use of the embodiments of the present invention.
[0148] The Internet of Things device identity authentication apparatus 900 is presented in the form of a hardware module. The components of the Internet of Things device identity authentication apparatus 900 may include but are not limited to: a reading module 902 for reading the terminal device identifier in the user identification module of the terminal; a sending module 904 for sending an identity authentication request to an authentication node of the Internet of Things, the identity authentication request including the terminal device identifier; a receiving module 906 for receiving random data fed back by the authentication node based on the identity authentication request; a generating module 908 for feeding the random data back to the user identification module so that the user identification module generates identity authentication information based on a pre-stored decentralized key and the random data; the sending module 904 is further used for obtaining the identity authentication information and sending the identity authentication information to the authentication node so that the authentication node authenticates the identity authentication information based on a pre-stored hash tree and generates an identity authentication result of the terminal; the receiving module 906 is further used for receiving the identity authentication result fed back by the authentication node.
[0149] The following refers to Figure 10 to describe the Internet of Things device identity authentication apparatus 1000 according to this embodiment of the present invention. Figure 10 The shown Internet of Things device identity authentication apparatus 1000 is merely an example and should not impose any limitation on the functions and the scope of use of the embodiments of the present invention.
[0150] The Internet of Things device identity authentication apparatus 1000 is embodied in the form of a hardware module. The components of the Internet of Things device identity authentication apparatus 1000 may include, but are not limited to: a receiving module 1002, configured to receive an identity authentication request sent by a terminal and generate random data based on the identity authentication request; a sending module 1004, configured to send the random data to the terminal and receive the identity authentication information generated by the terminal according to the random data; an extraction module 1006, configured to extract the terminal device identifier carried in the identity authentication request; a query module 1008, configured to query a preset hash value matching the terminal device identifier in a pre-stored hash tree; a generation module, configured to generate verification reference information based on the preset hash value and the random data; a verification module 1010, configured to perform identity authentication on the identity authentication information based on the verification reference information and generate an identity authentication result of the terminal; and the sending module is further configured to send the identity authentication result to the terminal.
[0151] The following refers to Figure 11 to describe the electronic device 1100 according to this embodiment of the present invention, including the above-mentioned terminal and node device, Figure 11 The shown electronic device 1100 is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present invention.
[0152] As Figure 11 shown, the electronic device 1100 is embodied in the form of a general-purpose computing device. The components of the electronic device 1100 may include, but are not limited to: the above-mentioned at least one processing unit 1110, the above-mentioned at least one storage unit 1120, and a bus 1130 connecting different system components (including the storage unit 1120 and the processing unit 1110).
[0153] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 1110, so that the processing unit 1110 executes the steps according to various exemplary embodiments of the present invention described in the above "Exemplary Method" section of this specification. For example, the processing unit 1110 may execute steps S202, S204 to S212 as Figure 2 shown, and other steps defined in the Internet of Things device identity authentication method of the present disclosure.
[0154] The storage unit 1120 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 11201 and / or a cache storage unit 11202, and may further include a read-only storage unit (ROM) 11203.
[0155] The storage unit 1120 may also include a program / utilities 11204 having a set (at least one) of program modules 11205. Such program modules 11205 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment.
[0156] The bus 1130 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor, or a local bus using any of a variety of bus structures.
[0157] The electronic device 1100 may also communicate with one or more external devices 1160 (such as a keyboard, a pointing device, a Bluetooth device, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device, and / or may communicate with any device that enables the electronic device 1100 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication may be carried out through an input / output (I / O) interface 1150. Moreover, the electronic device 1100 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 1150. As shown in the figure, the network adapter 1150 communicates with other modules of the electronic device 1100 through the bus 1130. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0158] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software, or can be implemented by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which may be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which may be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.
[0159] In an exemplary embodiment of the present disclosure, there is also provided a computer-readable storage medium, on which a program product capable of implementing the above-described method of this specification is stored. In some possible implementation manners, various aspects of the present invention can also be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to cause the terminal device to execute the steps according to various exemplary embodiments of the present invention described in the above "Exemplary Method" section of this specification.
[0160] The program product for implementing the above method according to an embodiment of the present invention may be a portable compact disc read-only memory (CD-ROM) and includes program code, and can run on a terminal device, such as a personal computer. However, the program product of the present invention is not limited thereto. In this document, the readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device.
[0161] The computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable signal medium may also be any readable medium other than the readable storage medium, and this readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device.
[0162] The program code contained on the readable medium can be transmitted by any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination of the above.
[0163] The program code for performing the operations of the present invention can be written in any combination of one or more programming languages. The programming languages include object-oriented programming languages, such as Java, C++, etc., and also include conventional procedural programming languages, such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, executed as an independent software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, by using an Internet service provider to connect through the Internet).
[0164] It should be noted that although several modules or units of a device for action execution are mentioned in the above detailed description, such division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more of the above-described modules or units can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0165] In addition, although the steps of the methods in the present disclosure are described in a specific order in the drawings, this does not require or imply that these steps must be performed in that specific order, or that all the steps shown must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.
[0166] From the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (such as a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the methods according to the embodiments of the present disclosure.
[0167] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. This application is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and the embodiments are only regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the appended claims.
Claims
1. An Internet of Things device identity authentication method, applied to a terminal, characterized in that, including: reading the terminal device identifier in the user identification module of the terminal; sending an identity authentication request to the authentication node of the Internet of Things, where the identity authentication request includes the terminal device identifier; receiving the random data fed back by the authentication node based on the identity authentication request; feeding back the random data to the user identification module so that the user identification module performs a hash operation based on a pre-stored dispersion key and the random data to generate identity authentication information; obtaining the identity authentication information and sending the identity authentication information to the authentication node so that the authentication node authenticates the identity authentication information based on a pre-stored hash tree and generates an identity authentication result of the terminal, where a preset hash value matching the terminal device identifier is queried in the pre-stored hash tree; verification reference information is generated based on the preset hash value and the random data; the identity authentication information is authenticated based on the verification reference information; receiving the identity authentication result fed back by the authentication node.
2. The method for authenticating the identity of an Internet of Things device according to claim 1, wherein The generating, by the user identification module, identity authentication information based on a pre-stored dispersion key and the random data includes: performing a hash calculation on the dispersion key by the user identification module to obtain a first hash value; performing a hash calculation on the random data by the user identification module to obtain a second hash value; performing a hash calculation on the sum of the first hash value and the second hash value by the user identification module to obtain the identity authentication information.
3. The method for authenticating the identity of an Internet of Things device according to claim 1 or 2, wherein the dispersion key and the terminal device identifier are filled into the user identification module based on a key filling system of a data center.
4. An Internet of Things device identity authentication method, applied to an authentication node, characterized in that, including: receiving an identity authentication request sent by a terminal and generating random data based on the identity authentication request; sending the random data to the terminal and receiving the identity authentication information generated by the terminal according to the random data, where the identity authentication information is generated by performing a hash operation based on a pre-stored dispersion key and the random data; extracting the terminal device identifier carried in the identity authentication request; querying a preset hash value matching the terminal device identifier in a pre-stored hash tree; generating verification reference information based on the preset hash value and the random data; authenticating the identity authentication information based on the verification reference information and generating an identity authentication result of the terminal; sending the identity authentication result to the terminal.
5. The method for authenticating the identity of an Internet of Things device according to claim 4, wherein The querying, in a pre-stored hash tree, a preset hash value matching the terminal device identifier includes: querying whether the location information of the terminal device identifier is cached locally; if the location information of the terminal device identifier is cached, querying the preset hash value matching the terminal device identifier in the hash tree based on the location information.
6. The method for authenticating the identity of an Internet of Things device according to claim 5, characterized in that, further including: if the location information of the terminal device identifier is not cached, sending a location information query request to the root location server of the hash tree so that the root location server performs a recursive query operation until the address of the authorized location server storing the hash tree is queried; Download the hash tree based on the address of the authorized location server, and query the preset hash value matching the terminal device identifier in the hash tree based on the location information.
7. The method for authenticating the identity of an Internet of Things device according to claim 6, wherein It further includes: Transmit the preset hash value and the terminal device identifier with a corresponding relationship to the authorized location server through the root location server, so that the authorized location server converts the preset hash value and the terminal device with the corresponding relationship into leaf nodes; Generate the hash tree based on the leaf nodes.
8. The method for authenticating the identity of an Internet of Things device according to any one of claims 4 to 7, characterized in that The generating the verification reference information based on the preset hash value and the random data includes: Perform a hash calculation on the random data to obtain a third hash value; Perform a hash calculation on the sum of the preset hash value and the third hash value to obtain the verification reference information.
9. An Internet of Things device identity authentication device, applied to a terminal, characterized in that, It includes: A reading module, configured to read the terminal device identifier in the user identification module of the terminal; A sending module, configured to send an identity authentication request to the authentication node of the Internet of Things, where the identity authentication request includes the terminal device identifier; A receiving module, configured to receive the random data fed back by the authentication node based on the identity authentication request; A generating module, configured to feed back the random data to the user identification module, so that the user identification module generates identity authentication information based on a pre-stored dispersion key and the random data through a hash operation; The sending module is further configured to obtain the identity authentication information and send the identity authentication information to the authentication node, so that the authentication node authenticates the identity authentication information based on a pre-stored hash tree and generates an identity authentication result of the terminal, where a preset hash value matching the terminal device identifier is queried in the pre-stored hash tree; verification reference information is generated based on the preset hash value and the random data; the identity authentication information is authenticated based on the verification reference information; The receiving module is further configured to receive the identity authentication result fed back by the authentication node.
10. An Internet of Things device identity authentication device, applied to an authentication node, characterized in that, It includes: A receiving module, configured to receive an identity authentication request sent by a terminal, and generate random data based on the identity authentication request; A sending module, configured to send the random data to the terminal and receive the identity authentication information generated by the terminal according to the random data, where the identity authentication information is generated through a hash operation based on a pre-stored dispersion key and the random data; An extraction module, configured to extract the terminal device identifier carried in the identity authentication request; A query module, configured to query a preset hash value matching the terminal device identifier in a pre-stored hash tree; A generating module, configured to generate verification reference information based on the preset hash value and the random data; A verification module, configured to authenticate the identity authentication information based on the verification reference information and generate an identity authentication result of the terminal; The sending module is further configured to send the identity authentication result to the terminal.
11. A terminal, characterized in that, It includes: A processor; And A memory, configured to store executable instructions of the processor; Wherein, the processor is configured to execute the Internet of Things device identity authentication method according to any one of claims 1 to 3 by executing the executable instructions.
12. An authentication node, characterized in that, Comprising: A processor; And A memory for storing executable instructions of the processor; Wherein, the processor is configured to execute the Internet of Things device identity authentication method according to any one of claims 4 to 8 by executing the executable instructions.
13. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the Internet of Things device identity authentication method according to any one of claims 1 to 3 and / or 4 to 8.
Citation Information
Patent Citations
Light-weight node and gateway two-way identity authentication method
CN103701797A
Identity information verification method, server and storage medium
CN110990827A