A device authentication method and related apparatus
By assisting the verification device in verifying the authentication information of the first device, the problem that the device authentication information cannot be updated in time is solved, and the security and legitimacy of the system are improved.
Patent Information
- Application Number
- CN202110437541.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-04-22
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2041-04-22
AI Technical Summary
In a near-field environment, device authentication information cannot be updated in a timely and proactive manner, resulting in unauthorized devices misusing authentication information and affecting system security.
The authentication information of the first device is verified by the assisting authentication device to ensure that it is consistent with the authentication information stored in the assisting authentication device. If it is inconsistent, the authentication information is obtained from the authentication server to control the execution of the function.
Improves system security, prevents unauthorized devices from tampering with authentication information, and ensures the legitimacy and security of device functions.
Smart Images

Figure CN115238259B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of electronic technology, and in particular to a device authentication method and related apparatus. Background Art
[0002] Currently, it's common for multiple devices to be networked and operate collaboratively in near-field environments. Collaborative operation refers to devices within the same local area network being able to invoke the capabilities of other devices, or to make their own capabilities available to other devices. For example, devices can implement a wide range of functions using open capability kits. For example, the device virtualization capability kit enables IoT devices like cameras and speakers to be virtualized as system functions on mobile phones and made available to them.
[0003] Before using the Kit, devices must undergo authentication and authorization. Connected devices can directly connect to the authentication server to obtain authentication information. Devices without internet access must obtain authentication information from the authentication server through a connected device and then store it in the device's memory. The device can use this locally stored authentication information while it's valid. However, because connected devices cannot proactively connect to the internet to update authentication information, stored authentication information is susceptible to tampering, leading to unauthorized devices misusing it and compromising system security. Summary of the Invention
[0004] An embodiment of the present application provides a device authentication method and related apparatus, in which an assisting verification device stores the authentication information of a first device, and the first device sends the locally stored authentication information to the assisting verification device. The assisting verification device verifies whether the authentication information locally stored on the first device is consistent with the authentication information of the first device stored on the assisting verification device. This can then detect whether the authentication information of the first device has been tampered with, thereby improving the security of the system.
[0005] The object and other objects are achieved by the features of the independent claims. Further implementations are revealed in the dependent claims, the description and the drawings.
[0006] In a first aspect, the present application provides a device authentication method applied to a first device, comprising: sending first authentication information to at least one assisting verification device when detecting a call request for a first function on the first device, wherein the first device and the at least one assisting verification device both store authentication information of the first function on the first device, and the first authentication information is the authentication information of the first function stored by the first device; receiving verification results from the at least one assisting verification device, wherein the verification result received from any assisting verification device indicates whether the first authentication information is the same as the authentication information stored by the assisting verification device; when determining that the authentication information is not reliable according to the verification results received from the at least one assisting verification device, obtaining the authentication information of the first function on the first device from an authentication server, and controlling the execution of the first function according to the authentication result in the authentication information obtained from the authentication server, wherein the authentication result indicates whether the first device is allowed to execute the first function.
[0007] The device authentication method provided by the present application sends the authentication information to the assisting verification device through the first device, so that the assisting verification device can verify the authentication information of the first device, and by determining whether the authentication information stored locally by the first device is consistent with the authentication information of the first device stored by the assisting verification device, it can be found whether the authentication information of the first device is tampered with.
[0008] In combination with the first aspect, in some embodiments, when the at least one assisting verification device includes only one assisting verification device, the manner of determining that the first authentication information is not reliable is: when it is determined according to the verification result received from the assisting verification device that the first authentication information is not the same as the authentication information stored by the assisting verification device, it is determined that the first authentication information is not reliable.
[0009] In combination with the first aspect, in some embodiments, when the at least one assisting verification device includes a plurality of assisting verification devices, the manner of determining that the first authentication information is not reliable includes: when it is determined according to the verification results received from the plurality of assisting verification devices that the number of assisting verification devices whose stored authentication information is not the same as the first authentication information is greater than or equal to a preset number, it is determined that the first authentication information is not reliable; or when it is determined according to the verification results received from the plurality of assisting verification devices that the proportion of the assisting verification devices whose stored authentication information is not the same as the first authentication information in the plurality of assisting verification devices is greater than or equal to a preset proportion, it is determined that the first authentication information is not reliable; or when it is determined according to the verification results received from the plurality of assisting verification devices that the number of the assisting verification devices whose stored authentication information is not the same as the first authentication information is greater than or equal to the number of the assisting verification devices whose stored authentication information is the same as the first authentication information, it is determined that the first authentication information is not reliable.
[0010] For example, if more than half of the authentication information of the assisting verification devices is different from the authentication information of the first device, it is considered that the authentication information in the first device is not trusted, or as long as there is one assisting verification device whose authentication information is different from the authentication information of the first device, it is considered that the authentication information in the first device is not trusted.
[0011] In combination with the first aspect, in some embodiments, the invocation request is from another device; or the invocation request is from a user operation on the first device.
[0012] For example, the other device needs to use the first function of the first device, and the other device needs to send an invocation request to the first device, so that the first device provides the first function to the other device for use.
[0013] In combination with the first aspect, in some embodiments, the at least one assisting verification device is located in the same local area network as the first device.
[0014] In combination with the first aspect, in some embodiments, before detecting the invocation request for the first function on the first device, the method further includes: the first device sends an authentication request to the authentication server, where the authentication request is used to request the authentication server to authenticate the first function on the first device; and the first device receives authentication information of the first function sent by the authentication server according to the authentication request, and saves the authentication information as first authentication information.
[0015] That is, whether the first device can use the first function is authenticated by the authentication server, the first device sends an authentication request to the authentication server, the authentication server generates authentication information on whether the first device can use the first function, and the first device receives the authentication information and saves the authentication information.
[0016] In combination with the first aspect, in some embodiments, after the first device receives the authentication information of the first function sent by the authentication server according to the authentication request, the method further includes: the first device sends the authentication information to the at least one assisting verification device.
[0017] That is, the authentication information of the first device saved by the assisting verification device can be sent by the first device.
[0018] In combination with the first aspect, in some embodiments, before detecting the invocation request for the first function on the first device, the method further includes: the first device sends an authentication request to the assisting authentication device, and instructs the assisting authentication device to forward the authentication request to the authentication server, where the authentication request is used to request the authentication server to authenticate the first function on the first device; and the first device receives authentication information of the first function sent by the authentication server according to the authentication request through the assisting authentication device, and saves the authentication information.
[0019] That is, the first device can also obtain the authentication information from the authentication server by assisting the authentication device, forward the authentication request to the authentication server by the assisting authentication device, send the authentication information to the assisting authentication device by the authentication server, and then forward the authentication information to the first device by the assisting authentication device. In some embodiments, the assisting authentication device saves the authentication information after obtaining the authentication information from the authentication server.
[0020] In combination with the first aspect, in some embodiments, the at least one assisting verification device includes an assisting authentication device.
[0021] That is, the assisting verification device and the assisting authentication device can be the same device.
[0022] In combination with the first aspect, in some embodiments, in response to the invocation request, the first device sends the first authentication information to the at least one assisting verification device, including: in response to the first invocation request, the first device detects whether the first authentication information is within a valid period; and when the first device detects that the first authentication information is within the valid period, the first device sends the first authentication information to the at least one assisting verification device.
[0023] That is, before the assisting verification, the first device authenticates the valid period of the first authentication information, and if the first authentication information is within the valid period, the assisting verification is performed, and if the first authentication information is not within the valid period, new authentication information is obtained from the authentication server.
[0024] In combination with the first aspect, in some embodiments, the first authentication information is encrypted by using a hash operation, and in response to the detection of the invocation request for the first function on the first device, the first authentication information is sent to the at least one assisting verification device, including: in response to the detection of the invocation request for the first function on the first device, the first device verifies the first authentication information by using a hash operation message authentication code; and when the first device passes the verification, the first device sends the first authentication information to the at least one assisting verification device.
[0025] That is, before the assisting verification, the first device authenticates the hash operation message authentication code of the first authentication information, and if the first authentication information passes the hash operation message authentication code authentication, the assisting verification is performed, and if the first authentication information does not pass the hash operation message authentication code authentication, new authentication information is obtained from the authentication server.
[0026] In combination with the first aspect, in some embodiments, before the first device sends the first authentication information to the at least one assisting verification device in response to the invocation request, the method further includes: the first device determines a device that meets a preset condition as the assisting verification device among the devices in a local area network to which the first device belongs, wherein the preset condition includes that the authentication information of the first function on the first device is stored.
[0027] That is, at least one assisting verification device needs to save the authentication information of the first function of the first device to assist in verifying the first device.
[0028] In combination with the first aspect, in some embodiments, in response to the first invocation request, the first device sends the first authentication information to the at least one assisting verification device, including: in response to the first invocation request, the first device sends an assisting verification request to each device in the local area network where the first device is located; the first device receives an assisting verification response sent by the at least one assisting verification device in response to the assisting verification request, the assisting verification response being used to indicate an agreement to assist in verification; and the first device sends the first authentication information to the at least one assisting verification device in response to the assisting verification response.
[0029] That is, the first device sends an assisting verification request to other devices in the local area network first, and then sends the first authentication information to the assisting verification device after the other devices agree to assist in verifying the first device.
[0030] In combination with the first aspect, in some embodiments, after receiving the verification result from the at least one assisting verification device, the method further includes: when it is determined according to the verification result received from the at least one assisting verification device that the first authentication information is authentic, controlling execution of the first function according to the authentication result in the first authentication information.
[0031] That is, if the authentication information saved by the assisting verification device is consistent with the first authentication information, the first device can control execution of the first function according to the authentication result.
[0032] The second aspect provides a device authentication method, applied to a second device, including: receiving first authentication information sent by a first device, wherein the first authentication information is authentication information of a first function of the first device saved by the first device; determining whether the first authentication information and second authentication information are the same, the second authentication information being authentication information of the first function of the first device saved by the second device; and sending, by the second device, a verification result to the first device, wherein the verification result is used to indicate whether the second authentication information and the first authentication information are the same.
[0033] In this way, the second device can assist in verifying whether the authentication information of other devices is tampered with by saving the authentication information of the other devices, thereby improving the security of the system.
[0034] With reference to the second aspect, in some embodiments, before the second device receives the first authentication information sent by the first device, the method further comprises: receiving, by the second device, a first authentication request sent by the first device, wherein the first authentication request is used to request the authentication server to authenticate the first function on the first device; forwarding, by the second device, the first authentication request to the authentication server according to the indication of the one device; receiving, by the second device, authentication information of the first function sent by the authentication server according to the first authentication request; and forwarding, by the second device, the authentication information to the first device.
[0035] That is, the second device can assist the first device in obtaining the authentication information from the authentication server by forwarding the authentication request of the first device to the authentication server and forwarding the authentication information sent by the authentication server to the first device.
[0036] With reference to the second aspect, in some embodiments, before the second device receives the first authentication information sent by the first device, the method further comprises: receiving, by the second device, a first authentication request sent by the first device; and in response to the first authentication request, sending, by the second device, a first authentication response to the first device, wherein the first authentication response is used to indicate an agreement to assist the authentication.
[0037] That is, the second device accepts the first authentication request of the first device before authenticating the first authentication information, and the first device sends the first authentication information to the second device only after the second device agrees to the request.
[0038] With reference to the second aspect, in some embodiments, before the second device receives the first authentication information sent by the first device, the method further comprises: receiving, by the second device, authentication information of the first function on the first device sent by the first device; and saving, by the second device, the authentication information.
[0039] That is, the authentication information saved by the second device is sent by the first device.
[0040] With reference to the second aspect, in some embodiments, after the second device receives the authentication information of the first function sent by the authentication server according to the first authentication request, the method further comprises: saving, by the second device, the authentication information.
[0041] That is, the authentication information saved by the second device is before the second device forwards the authentication information to the first device after receiving the authentication information sent by the authentication server.
[0042] In a third aspect, the present application provides a device authentication system, comprising: a first device, at least one authentication assistance device.
[0043] The first device is configured to: upon detecting a call request for a first function on the first device, send first authentication information to at least one assisting verification device, wherein the first device and the at least one assisting verification device both store the authentication information of the first function on the first device, and the first authentication information is the authentication information of the first function stored by the first device; receive a verification result from the at least one assisting verification device, wherein the verification result received from any assisting verification device is used to indicate whether the first authentication information is the same as the authentication information stored by the assisting verification device; upon determining, based on the verification result received from the at least one assisting verification device, that the first authentication information is untrustworthy, obtain the authentication information of the first function on the first device from an authentication server, and control execution of the first function based on the authentication result in the authentication information obtained from the authentication server, wherein the authentication result is used to indicate whether the first device is allowed to execute the first function;
[0044] Any one of the at least one assisting verification device is configured to: receive the first authentication information sent by the first device, and send a verification result to the first device.
[0045] In this way, before using specific functions, devices within the local area network need other devices to assist in authentication, which can detect whether the authentication information has been tampered with, thereby improving the security of the system.
[0046] In combination with the third aspect, in some embodiments, the device authentication system further includes an authentication server, and the authentication server is used to authenticate the first function on the first device.
[0047] In a fourth aspect, an embodiment of the present application provides an electronic device, comprising: one or more processors, one or more memories; one or more memories are respectively coupled to one or more processors; one or more memories are used to store computer program code, and the computer program code includes computer instructions; when the computer instructions are run on the processor, the electronic device executes the device authentication method in any possible implementation of any of the above aspects.
[0048] In a fifth aspect, an embodiment of the present application provides a readable medium for storing one or more programs, wherein the one or more programs are configured to be executed by one or more processors, and the one or more programs include instructions for executing the device authentication method in any possible implementation of any of the above aspects.
[0049] In a sixth aspect, an embodiment of the present application provides a computer program product, which, when running on a computer, enables the computer to execute the device authentication method in any possible implementation of any of the above aspects.
[0050] The technical scheme provided in the application is implemented, and before a device uses a specific function and needs to be authenticated, the authentication information of the device needs to be verified by an assisted verification device in a local area network. Whether the authentication information of the device is reliable is determined by the assisted verification device, whether the authentication information of the device is tampered with is found, and then the situation that a device that has not passed authentication uses the function by force or the situation that an authorized device cannot be normally used is prevented, so that the security of the system is improved. BRIEF DESCRIPTION OF DRAWINGS
[0051] In order to more clearly illustrate the technical scheme in the embodiments of the application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced.
[0052] Figure 1 An application scenario schematic diagram of a device authentication system provided by the embodiments of the application is shown in the figure.
[0053] Figure 2 A structural schematic diagram of an electronic device provided by the embodiments of the application is shown in the figure.
[0054] Figure 3 A software structure framework schematic diagram provided by the embodiments of the application is shown in the figure.
[0055] Figure 4 A Kit framework structure schematic diagram provided by the embodiments of the application is shown in the figure.
[0056] Figure 5 An assisted authentication method flow process schematic diagram provided by the embodiments of the application is shown in the figure.
[0057] Figure 6 A device authentication method flow process schematic diagram in an application scenario provided by the embodiments of the application is shown in the figure.
[0058] Figure 7 A device authentication method flow process schematic diagram provided by the embodiments of the application is shown in the figure.
[0059] Figure 8 A network forming method flow process schematic diagram of the embodiments of the application is shown in the figure.
[0060] Figure 9 An assisted verification method flow process schematic diagram of the embodiments of the application is shown in the figure.
[0061] Figure 10 A device authentication method flow process schematic diagram of another embodiment of the application is shown in the figure.
[0062] Figure 11 A device authentication method flow process schematic diagram in another application scenario of the embodiments of the application is shown in the figure. DETAILED DESCRIPTION
[0063] The technical solutions in the embodiments of the present application will be described below with reference to the drawings. In the description of the embodiments of the present application, unless otherwise specified, " / " represents the meaning of or, for example, A / B can represent A or B; the "and / or" in the text only describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which means that there are three cases of A alone, A and B together, and B alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.
[0064] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and cannot be understood as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Therefore, the features defined with "first" and "second" can explicitly or implicitly include one or more features. In the description of the embodiments of the present application, unless otherwise specified, the meaning of "multiple" is two or more than two. The terms "intermediate", "left", "right", "upper", "lower" and the like indicate the orientation or positional relationship shown in the drawings, which is only for the purpose of facilitating the description of the present application and simplifying the description, and cannot be understood as indicating or suggesting that the indicated device or element must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as limiting the present application.
[0065] The application scenarios related to the present application will be described below.
[0066] At present, multiple devices can form a network in a near-field environment through Bluetooth or Wi-Fi and the like to realize collaborative operation between devices. Collaborative operation means that a device in the same local area network can call the capabilities of other devices, or can provide its own capabilities to other devices for calling. In some other embodiments, the device can also be connected to a soft bus and transmit data through the soft bus, thereby realizing collaborative operation.
[0067] As shown in Figure 1 The electronic device 101, the device 1, the device 2 and the device 3 are in the same local area network, in order to facilitate understanding, Figure 1 Taking the device 1 as a camera, the device 2 as a rice cooker and the device 3 as a sweeping robot as an example, the electronic device 101 can call the capabilities of the device 1, the device 2 or the device 3, or can provide its own capabilities to the device 1, the device 2 or the device 3 for calling. The capabilities of the device are realized through Kit, and the device needs to be authenticated before using Kit. The authentication information of the device is generated by the authentication server 200, and the device can obtain the authentication information from the authentication server 200 and save the authentication information to the device memory. Within the validity period of the authentication information, the device can directly use the locally saved authentication information.
[0068] The electronic device 100 involved in the embodiments of the present application is described in detail below.
[0069] Referring to Figure 2 , Figure 2 A structural schematic diagram of an example electronic device 100 provided by the embodiments of the present application is shown. The electronic device 100 can be the electronic device 101, the device 1, the device 2, the device 3, and the like in the above Figure 1 .
[0070] The electronic device 100 can include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a loudspeaker 170A, a receiver 170B, a microphone 170C, a headset interface 170D, a sensor module 180, a key 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, and the like. The sensor module 180 can include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, and the like.
[0071] It can be understood that the structure shown in the embodiments of the present application does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 can include more or fewer components than shown, or combine certain components, or split certain components, or different component arrangements. The components shown can be implemented in hardware, software, or a combination of software and hardware.
[0072] The processor 110 can include one or more processing units, for example: the processor 110 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units can be independent devices, or can be integrated in one or more processors.
[0073] The controller can be the nerve center and command center of the electronic device 100. The controller can generate operation control signals according to instruction operation codes and timing signals, and complete the control of fetching instructions and executing instructions.
[0074] The memory in the processor 110 can also be configured to store instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory can save instructions or data that the processor 110 has just used or repeatedly uses. If the processor 110 needs to use the instructions or data again, it can be directly called from the memory. Avoiding repeated access reduces the waiting time of the processor 110, thereby improving the efficiency of the system.
[0075] The charging management module 140 is configured to receive charging input from a charger. The charger can be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 can receive the charging input of the wired charger through the USB interface 130. In some wireless charging embodiments, the charging management module 140 can receive the wireless charging input through the wireless charging coil of the electronic device 100.
[0076] The power management module 141 is configured to connect the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives the input of the battery 142 and / or the charging management module 140, and supplies power to the processor 110, the internal memory 121, the external memory, the display screen 194, the camera 193, and the wireless communication module 160, etc. The power management module 141 can also be configured to monitor parameters such as battery capacity, battery cycle number, battery health status (leakage, impedance), etc.
[0077] The wireless communication function of the electronic device 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor, and the baseband processor, etc.
[0078] The antenna 1 and the antenna 2 are used for transmitting and receiving electromagnetic wave signals. Each antenna in the electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization of the antennas.
[0079] The mobile communication module 150 can provide a solution for wireless communication including 2G / 3G / 4G / 5G, etc. applied on the electronic device 100. The mobile communication module 150 can include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves by the antenna 1, and perform filtering, amplification, etc. on the received electromagnetic waves, and transmit the processed signals to the modem processor for demodulation.
[0080] The modem processor can include a modulator and a demodulator. The modulator is used to modulate a low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal.
[0081] The wireless communication module 160 can provide a solution for wireless communication including UWB, wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) network), blue-tooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR) technology, etc. applied on the electronic device 100. The wireless communication module 160 can be one or more devices integrated with at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, performs frequency modulation and filtering processing on the electromagnetic wave signals, and transmits the processed signals to the processor 110. The wireless communication module 160 can also receive signals to be transmitted from the processor 110, perform frequency modulation and amplification on the signals, and radiate the signals as electromagnetic waves via the antenna 2.
[0082] In some embodiments, the antenna 1 and the mobile communication module 150 of the electronic device 100 are coupled, and the antenna 2 and the wireless communication module 160 are coupled, so that the electronic device 100 can communicate with a network and other devices through wireless communication technology. The wireless communication technology can include wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc.
[0083] The electronic device 100 implements a display function through a GPU, a display screen 194, and an application processor, etc. The GPU is a microprocessor for image processing, connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 can include one or more GPUs that execute program instructions to generate or change display information.
[0084] The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. In some embodiments, the electronic device 100 can include 1 or N display screens 194, N being a positive integer greater than 1.
[0085] In some embodiments of the present application, the interface content currently output by the system is displayed in the display screen 194. For example, the interface content is an interface provided by an instant messaging application.
[0086] The electronic device 100 can implement a shooting function through an ISP, a camera 193, a video codec, a GPU, a display screen 194, and an application processor, etc.
[0087] The ISP is used to process data fed back by the camera 193.
[0088] The camera 193 is used to capture still images or videos. In some embodiments, the electronic device 100 can include 1 or N cameras 193, N being a positive integer greater than 1.
[0089] The digital signal processor is used to process digital signals, in addition to being able to process digital image signals, it can also process other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy, etc.
[0090] A video codec is used to compress or decompress digital video. The electronic device 100 can support one or more video codecs. In this way, the electronic device 100 can play or record videos in a variety of encoding formats, such as moving picture experts group (MPEG) 1, MPEG 2, MPEG 3, MPEG 4, and the like.
[0091] The NPU is a neural-network (NN) computing processor that quickly processes input information by drawing on the structure of a biological neural network and can also constantly self-learn.
[0092] The external memory interface 120 can be used to connect an external memory card to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 through the external memory interface 120 to implement a data storage function.
[0093] The internal memory 121 can be used to store computer executable program code, which includes instructions. The internal memory 121 can include a program storage area, a data storage area, a high-speed random access memory, and a nonvolatile memory.
[0094] The electronic device 100 can implement audio functions through an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone interface 170D, an application processor, and the like. For example, music playback, voice recording, and the like.
[0095] The audio module 170 is used to convert digital audio information into an analog audio signal output and is also used to convert an analog audio input into a digital audio signal. The audio module 170 can also be used to encode and decode audio signals.
[0096] The speaker 170A, also known as a "loudspeaker", is used to convert an audio electrical signal into a sound signal. The electronic device 100 can listen to music or listen to a hands-free call through the speaker 170A.
[0097] The receiver 170B, also known as an "earpiece", is used to convert an audio electrical signal into a sound signal. When the electronic device 100 is on a call or receiving a voice message, the receiver 170B can be held close to a person's ear to listen to the voice.
[0098] The microphone 170C, also known as a "microphone", "sound transducer", is used to convert a sound signal into an electrical signal. When making a call or sending a voice message, a user can speak into the microphone 170C by holding the person's mouth close to the microphone 170C to input a sound signal into the microphone 170C. The electronic device 100 can be provided with at least one microphone 170C.
[0099] The earphone interface 170D is used to connect wired earphones. The earphone interface 170D can be a USB interface 130, or a 3.5mm open mobile terminal platform (OMTP) standard interface, or a cellular telecommunications industry association of the USA (CTIA) standard interface.
[0100] The pressure sensor 180A is used to sense a pressure signal, and can convert the pressure signal into an electrical signal.
[0101] The pressure sensor 180A can be of various types, such as a resistive pressure sensor, an inductive pressure sensor, a capacitive pressure sensor, etc. The capacitive pressure sensor can include at least two parallel plates of conductive material. When a force is applied to the pressure sensor 180A, the capacitance between the electrodes changes, and the electronic device 100 detects the touch operation intensity according to the pressure sensor 180A. The electronic device 100 can also calculate the position of the touch according to the detection signal of the pressure sensor 180A.
[0102] The gyroscope sensor 180B can be used to determine the motion posture of the electronic device 100. In some embodiments, the angular velocity of the electronic device 100 around three axes (X, Y, and Z axes of the electronic device 100) can be determined by the gyroscope sensor 180B. The gyroscope sensor 180B can be used for shooting anti-shake, and can also be used for navigation and motion sensing game scenarios.
[0103] The barometric sensor 180C is used to measure air pressure. In some embodiments, the electronic device 100 calculates the altitude, assists positioning and navigation by measuring the air pressure value by the barometric sensor 180C.
[0104] The magnetic sensor 180D includes a Hall sensor. The electronic device 100 can detect the opening and closing of a flip cover by using the magnetic sensor 180D.
[0105] The acceleration sensor 180E can detect the magnitude of acceleration of the electronic device 100 in various directions (generally three axes). When the electronic device 100 is stationary, the magnitude and direction of gravity can be detected. The acceleration sensor 180E can also be used to identify the electronic device posture, and can be applied to landscape / portrait screen switching, pedometers, etc.
[0106] The distance sensor 180F is used to measure distance. The electronic device 100 can measure distance by infrared or laser.
[0107] The proximity light sensor 180G can include, for example, a light emitting diode (LED) and a light detector. The light emitting diode can be an infrared light emitting diode. The electronic device 100 emits infrared light outwardly through the light emitting diode. The electronic device 100 detects infrared reflected light from a nearby object using the photodiode. When sufficient reflected light is detected, it can be determined that there is an object near the electronic device 100.
[0108] The ambient light sensor 180L is used to sense ambient light brightness.
[0109] The fingerprint sensor 180H is used to collect a fingerprint.
[0110] The temperature sensor 180J is used to detect temperature.
[0111] The touch sensor 180K, also referred to as a "touch panel". The touch sensor 180K can be disposed on the display screen 194, and the touch sensor 180K and the display screen 194 together form a touch screen, also referred to as a "touch screen". The touch sensor 180K is used to detect a touch operation acting on or near it, which refers to a user's hand, elbow, stylus, etc. contacting the display screen 194.
[0112] The bone conduction sensor 180M can obtain a vibration signal.
[0113] The keys 190 include a power-on key, a volume key, etc. The electronic device 100 can receive a key input and generate a key signal input related to user settings and function control of the electronic device 100.
[0114] The motor 191 can generate a vibration prompt.
[0115] The indicator 192 can be an indicator light, which can be used to indicate a charging state, a power change, and can also be used to indicate a message, a missed call, a notification, etc.
[0116] Figure 3 A software structure framework diagram of the electronic device 100 of the embodiments of the present application is shown.
[0117] The layered architecture divides the software into several layers, each layer has a clear role and division of labor. Layers communicate with each other through software interfaces. In some embodiments, the system is divided into five layers, from top to bottom, the application layer, the framework layer, the system server layer, and the kernel layer.
[0118] The application layer can include a series of application packages. For example, Figure 3As shown, the application layer is divided into system applications and extended applications (i.e., third-party applications), the application packages in the system applications can include application programs of home screen (i.e., desktop), control bar, settings, call, etc.; the third-party applications can include application programs developed by other organizations or individuals other than the software compiler, the third-party applications include application programs integrated with open capability kits (Kit), the application programs connect Kit services through Kit interfaces, and users can call Kit services through Kit interfaces, such as Device Virtualization Kit (DV Kit), Local Authentication Kit (LA Kit), Basic Security Service Kit (BSS Kit), etc. Among them, the DV kit is used to provide and use the electronic device 100 as a mobile phone system general capability, such as virtualizing a television, a camera and a sound box as a screen, a camera and a loudspeaker of a mobile phone; the LA Kit provides a face recognition service, uses a camera to obtain a face feature image, and analyzes face features through an algorithm, which is used for face comparison identity authentication; the BSS Kit provides a short data security storage service, including the capabilities of securely storing, deleting, updating and querying short sensitive data.
[0119] The framework layer provides a user interface framework (User Interface, UI) for the application programs of the application layer, a user program framework, an open capability kit framework (Kit framework) and an application programming interface (application programming interface, API). The framework layer also includes some pre-defined functions.
[0120] The UI framework includes visual controls, such as controls for displaying text, controls for displaying pictures, etc. The UI framework can be used to build application programs. A display interface can be composed of one or more views. For example, a display interface including a short message notification icon can include a view for displaying text and a view for displaying pictures. In this application, the UI framework is used to display a shortcut area on the display screen 103 when the electronic device 100 meets a preset triggering condition, and the shortcut area includes one or more shortcut controls added by the electronic device 100. Among them, the position, layout of the shortcut area, and the icon, position, layout and function of the controls in the shortcut area are not limited in this application. The UI framework can be a Java UI framework suitable for Java language, or a JS UI framework suitable for JS, and the type of the UI framework is not limited in this application.
[0121] The user program framework can include an input manager, a window manager, a content provider, a view system, a phone manager, a resource manager, a notification manager, a display manager, an activity manager, and the like.
[0122] The Kit framework provides functions for managing and controlling Kit services, such as Figure 4 As shown, the Kit framework includes a data collection module, a Kit management module, an end-to-cloud authentication module, a device mutual assistance module, an assistance verification template, and a Hash-based Message Authentication Code (HMAC) module.
[0123] The data collection module is configured to collect data information from a memory of the electronic device 100. The data information is described below in Table 1. As shown in Table 1, the data information includes authentication information, activation information, and device information. The authentication information is generated by the authentication server 200 and is used to confirm whether the electronic device 100 has the right to use the Kit, which prevents unauthorized devices from using the Kit. The authentication information can include a unique identifier of the device to be authenticated, an authentication result, an authentication information update date, and an authentication status. The unique identifier of the device to be authenticated can be a device ID to be authenticated or an ID used by the device to be authenticated on a soft bus. The authentication result is an identifier of whether the device to be authenticated has the right to use the Kit. The authentication information update date is the date on which the authentication information is generated. The authentication status includes that the authentication information is within a valid period and that the device to be authenticated is being authenticated by the authentication server. The activation information is used for authentication and activation of the electronic device 100 and includes a certificate and a token. The device information is used to describe basic information of hardware and / or software of the device and can include a total size of RAM of the device, a remaining value of RAM, a usage rate of RAM, and whether the device has Wi-Fi and Bluetooth capabilities.
[0124] Table 1
[0125]
[0126] The Kit management module is configured to manage Kit authorization in the electronic device 100 and to complete verification of the authentication information. The Kit management module can manage Kit authorization in the electronic device 100 according to a Kit management policy issued by the authentication server 200. The Kit management policy can include implementing a pop-up or denying service when an unauthorized device (a device that fails authentication) uses the Kit, thereby achieving management of the unauthorized device.
[0127] The end-cloud authentication module is configured to connect the authentication server 200 for device authentication, i.e., the electronic device 100 with networking capability is provided with the end-cloud authentication module. Specifically, for the electronic device 100 with networking capability and capable of connecting the authentication server 200, if the electronic device 100 does not locally store authentication information or the authentication information is out of date, etc., the electronic device 100 will connect the authentication server 200 for device authentication to obtain authentication information of the authentication server 200.
[0128] The device mutual assistance module is configured to enable the to-be-authenticated device to connect the authentication server 200 to obtain authentication information by means of the assisting device, thereby enabling activation and Kit management of the to-be-authenticated device. The to-be-authenticated device is an electronic device 100 that needs to be authenticated, and the assisting device is an electronic device 100 that can assist the to-be-authenticated device in authentication. The device mutual assistance module exists in the to-be-authenticated device and the assisting device.
[0129] The assistance verification module is configured to enable the assisting device to assist the to-be-authenticated device in authentication, wherein the assisting device stores authentication information of the to-be-authenticated device. Specifically, after verifying the local authentication information, the to-be-authenticated device needs to enable the assisting device to verify the local authentication information by means of the assistance verification module. The assistance verification module can be divided into a server end and a client end. The server end is configured to enable the assisting device to provide assistance verification for the to-be-authenticated device, and the assisting device provides the assistance verification on a software bus by means of Bluetooth, Wi-Fi, etc., for use by the to-be-authenticated device. The client end is configured to enable the to-be-authenticated device to request the assisting device to perform assistance verification, and can also be configured to enable the to-be-authenticated device to screen the assisting device. The to-be-authenticated device can select multiple assisting devices for verification, thereby improving the security of verification.
[0130] Optionally, the Kit framework can further include an HMAC key module. The HMAC key module is configured to calculate a signature key of the authentication information. Specifically, for the authentication information obtained by the authentication server 200, before being stored locally, the HMAC key module is used to calculate a signature key of the authentication information, and the signature key and the authentication information are stored in the memory. Before authentication of the authentication information, the signature key needs to be verified. The signature key is dynamically generated by a secure random algorithm, and can prevent rainbow table attacks. Exemplarily, a manner in which the HMAC key module calculates the signature SIGN can be shown in the following formula 1:
[0131] SIGN = HMAC (INFO + CHALLENGE) (1)
[0132] wherein CHALLENGE is a random byte number, and INFO is calculated by the following formula 2:
[0133] INFO = uuid + token + version (2)
[0134] Wherein, the uuid is an electronic device ID, the token is a license of the electronic device 100, and the version is a version of the token. The uuid and the token are usually 48-bit characters, and the version may have different byte numbers according to different versions of the token. It should be understood that the scheme does not specifically limit the way in which the HMAC key module calculates the signature SIGN.
[0135] The system service layer is a collection of system core capabilities, and the layer includes a system basic capability subsystem set, a basic software service subsystem set, an enhanced software service subsystem set, and a hardware service subsystem set.
[0136] The system basic capability subsystem set provides basic capabilities for operations such as running, scheduling, and migration of the application layer on the electronic device 100, and is composed of a distributed software bus, a distributed data management, a distributed task scheduling, a public basic library subsystem, a multi-mode input, and a graphics subsystem. The distributed software bus provides a unified distributed communication capability for interconnection and intercommunication between the electronic devices 100, and is used for assisting verification between the electronic devices 100. The distributed data management is based on the capability of the distributed software bus, and realizes distributed management of application program data and user data, and is used for storing authentication information. The distributed task scheduling is used for remote starting, remote calling, remote connection, and migration of applications across devices.
[0137] The basic software service subsystem set provides software services for the system, and is composed of a Kit service subsystem, an event notification, a telephone, and a multimedia subsystem. The Kit service subsystem can include a DV Kit, an LA Kit, and the like. The Kit services in the Kit service subsystem are connected to the Kit management module through an interface, and the Kit management module can manage the Kit services through the interface.
[0138] The enhanced software service subsystem set provides capability-enhanced software services for different electronic devices 100, and is composed of an Internet of Things (IoT) special service, a smart screen special service, a wearable special service, and the like.
[0139] The hardware service subsystem set provides hardware services for the system, and is composed of an IoT special hardware service, a location service, a biometric identification, a wearable special hardware service, and the like.
[0140] The kernel layer is a layer between hardware and software, and is a peripheral access capability and a driving development and management framework. The kernel layer includes a kernel subsystem and a driving subsystem. The kernel subsystem includes a Linux kernel, a LiteOS, and the like, and provides a basic kernel capability to an upper layer, including process / thread management, memory management, a file system, network management, and peripheral management. The driving subsystem includes at least a hardware driving framework, such as a display driving, a camera driving, an audio driving, a sensor driving, a driving of a touch control chip, and an input system.
[0141] In the embodiment of the application, when the electronic device 100 is a to-be-authenticated device, the Kit framework of the electronic device 100 at least includes a data acquisition module, a Kit management module, and an assisting verification module; when the electronic device 100 is an assisting device, the electronic device 100 at least includes a data acquisition module, a Kit management module, a device mutual assistance module, and an assisting verification module. If the electronic device 100 has a networking capability, the electronic device 100 further includes an end-cloud authentication module, so that the electronic device 100 can be connected to the Internet to obtain data from the authentication server 200; if the electronic device 100 only has a Bluetooth or Wi-Fi capability, the electronic device 100 can only communicate with electronic devices in the same network.
[0142] When the electronic device 100 without a networking capability needs to use a Kit service, the electronic device 100 without the networking capability needs to be authenticated to have the capability to use the Kit. Since the electronic device 100 without the networking capability cannot obtain authentication information by being connected to the Internet, the electronic device 100 with the networking capability needs to be mutually assisted to obtain the authentication information from the authentication server 200. Please refer to Figure 5 , Figure 5 A device authentication method is shown in a flowchart, in which a to-be-authenticated device is an electronic device without a networking capability and needs to be authenticated, and an assisting device is an electronic device with a networking capability and can help the to-be-authenticated device to be authenticated.
[0143] As shown in Figure 5 , the scheme can include the following steps:
[0144] S501, the to-be-authenticated device sends an authentication request to the assisting device. Specifically, the to-be-authenticated device sends an authentication request to the assisting device by Bluetooth or Wi-Fi, and the authentication request at least includes a unique identifier of the to-be-authenticated device and a unique identifier of the Kit.
[0145] S502, the assisting device forwards the authentication request to the authentication server 200. Specifically, after receiving the authentication request, the assisting device with the networking capability forwards the authentication request of the to-be-authenticated device to the authentication server 200.
[0146] S503, the authentication server generates authentication information. Specifically, after receiving the authentication request, the authentication server performs authentication on the to-be-authenticated device according to the authentication request, confirms whether the to-be-authenticated device has the right to access the Kit, and generates authentication information according to the authentication result. The authentication information includes the device identifier of the to-be-authenticated device, the kit service that can be called by the device identifier, and the like. Optionally, the authentication server can set a limited period for the authentication information according to actual conditions.
[0147] S504, the authentication server forwards the authentication information to the assisting device.
[0148] S505, the assisting device forwards the authentication information to the to-be-authenticated device.
[0149] As can be seen from the above steps, through the electronic device mutual assistance authentication scheme, the to-be-authenticated device can obtain authentication information from the authentication server through the assisting device, and within the limited period of the authentication information, the to-be-authenticated device can directly use the authentication information; if the authentication information exceeds the limited period, the to-be-authenticated device will initiate an authentication request to the assisting device again, and then obtain valid authentication information.
[0150] In summary, in the above device authentication scheme, the assisting device can help the to-be-authenticated device obtain authentication information to complete authentication, and the to-be-authenticated device stores the authentication information, so that the to-be-authenticated device does not need to authenticate to the authentication server again until the authentication information exceeds the valid period. In some scenarios, the authentication information stored by the to-be-authenticated device may be tampered with, and because the to-be-authenticated device does not have networking capability, it cannot obtain correct authentication information in time, which may lead to a situation that an unauthorized device can use the Kit due to tampering of the authentication information, or an authorized device cannot use the Kit due to tampering of the authentication information, thereby affecting the normal operation of the device, and may also lead to a situation that an unauthorized device uses the authentication information, affecting the security of the system. If the frequency of the to-be-authenticated device requesting the assisting device to obtain authentication information is increased, the response speed during business use will also be affected, and the user experience will be reduced.
[0151] Therefore, the present application provides a device authentication method, in which the to-be-authenticated device obtains authentication information and sends the authentication information to the assisting device, wherein the assisting device can be one or more. By storing the authentication information of the to-be-authenticated device in the assisting device, the to-be-authenticated device verifies whether the locally stored authentication information is within the valid period, and then the assisting device verifies whether the authentication information stored by the to-be-authenticated device is consistent with the authentication information of the to-be-authenticated device stored in the assisting device, thereby determining whether the authentication information is tampered with and whether the authentication information needs to be updated. The re-verification by the assisting device can improve the security of the authentication process.
[0152] The above Figure 3a software structure diagram, and Figure 1 The application scenarios of the foregoing are used to exemplify the device authentication method provided in the embodiments of the present application. The device 1, the device 2 and the device 3 all store the authentication information of the device 1. When the electronic device 101 needs to call the kit of the camera function of the device 1, the device 1 needs to authenticate whether the device 1 can provide the function to the electronic device 101 for calling. As shown in FIG. 1, the detailed steps of the device authentication performed by the device 1 are as follows. Figure 6
[0153] 1. The electronic device 101 initiates a kit usage request.
[0154] Specifically, the user can call the camera function of the device 1 through the application program of the electronic device 101. After the application program obtains the operation of the user, the application program initiates a kit usage request to the device 1, and the kit usage request is used to request to use the DV kit of the Kit service subsystem in the device 1.
[0155] 2. The Kit service subsystem calls the Kit management module.
[0156] Specifically, the device 1 receives the kit usage request, and in response to the kit usage request, the Kit service subsystem in the device 1 calls the Kit management module, and the authentication of the kit is completed by the Kit management module.
[0157] 3. The Kit management module verifies the local authentication information.
[0158] Specifically, the Kit management module reads the authentication information of the DV kit stored locally in the device 1, and verifies whether the authentication information of the DV kit is within the valid period. If the authentication information of the DV kit exceeds the valid period, the device assistance module in the Kit management module sends an authentication request to the device 2 or the device 3, and the specific steps can be referred to the description of the device assistance module in the Kit management module, which will not be described herein again. If the authentication information of the device 1 does not exceed the valid period, the following steps 4-5 are executed. Figure 5
[0159] Optionally, if the authentication information stored in the device 1 is signed by the HMAC key, the HMAC key module in the Kit management module needs to be called to perform the signature verification before the verification.
[0160] 4. An assistance verification request is sent.
[0161] Specifically, the assistance verification module of the device 1 sends an assistance verification request to the device 2 and the device 3, and the assistance verification request includes the authentication information of the device 1. The authentication information of the device 1 stored in the device 2 and the device 3 is verified by the device 2 and the device 3 to determine whether the authentication information stored in the device 2 and the device 3 is the same as the authentication information sent by the device 1.
[0162] 5. Verify the local authentication information.
[0163] Specifically, the assisted verification module in the device 2 and the device 3 reads the authentication information of the device 1 stored locally, compares the authentication information sent by the device 1, judges whether the authentication information stored by the device 1 is trusted, and returns the verification result to the device 1.
[0164] If the authentication information stored in the device 2 and the device 3 is the same as the authentication information sent by the device 1, it is considered that the authentication information in the device 1 is trusted, the authentication information of the device 1 has not been tampered with, and the verification result is returned to the device 1. The Kit management module of the device 1 further confirms whether the Kit can be used according to the authentication result; if the authentication result is that the device 1 can use the Kit, the electronic device 101 can call the camera function of the device 1, and if the authentication result is that the device 1 cannot use the Kit, the device 1 will return a refusal to use the service to the electronic device 101.
[0165] If the device 1 detects that the authentication information stored in one of the device 2 and the device 3 in the received verification result is different from the authentication information stored in the device 1, the device 1 considers that the authentication information of the device 1 is not trusted, and the device 1 will perform the following step 6.
[0166] 6. Initiate end-to-cloud authentication.
[0167] Specifically, if the authentication information in the device 1 is determined to be untrusted, the device 1 needs to connect to the authentication server for end-to-cloud authentication to obtain the latest authentication information. If the device 1 does not have networking capability, the device 1 needs to request the device 2 or the device 3 to assist in initiating end-to-cloud authentication. For details, please refer to the description of the device 2 and the device 3 in the foregoing embodiment, which will not be described here. Figure 5
[0168] In some embodiments, if the authentication information in the device 1 is determined to be untrusted, the device 3 needs to connect to the authentication server for end-to-cloud authentication to obtain the latest authentication information, and return the authentication information to the device 1.
[0169] The above describes the authentication process when the electronic device 101 needs to call the DV kit of the device 1, and the device 1 authenticates whether it can provide the function to the electronic device 101. Through the assisted verification of the device 2 and the device 3, it can be found whether the authentication information of the device 1 is tampered with, thereby preventing unauthorized devices from using the Kit after tampering with the authentication information, or preventing authorized devices from being unable to use the Kit after being tampered with, thereby improving the security of the system.
[0170] Not limited to the above case, in other cases, the scheme is still applicable, for example, when the device 1 needs to use its own camera function, it needs to authenticate whether the device 1 has the Kit of the camera function. At this time, the Kit service subsystem of the device 1 calls the Kit management module, and the authentication of the Kit is completed by the Kit management module. If the authentication information of the device 1 passes the authentication, the device 2 and the device 3 assist in verifying whether the authentication information in the device 1 is tampered with, thereby preventing unauthorized devices from tampering with the authentication information and using the Kit beyond authority; or, preventing authorized devices from being tampered with information and not being able to use the Kit, thereby improving the security of the system.
[0171] The following will be described in combination with Figure 7 The steps of a device authentication method provided by the present application are introduced, wherein the device 1 is a to-be-authenticated device, and the device 1 has a networking function, and the device 1 can also be referred to as a first device; the device 2 is an assisting device, which can also be referred to as an assisting verification device or a second device, comprising:
[0172] S701, the device 1 and the device 2 complete networking.
[0173] Specifically, after the device 1 is started, it will join the local area network through the distributed soft bus, so that the device 1 can communicate with other electronic devices 100 under the local area network. In some embodiments, after the device 1 joins the networking, it will screen other electronic devices 100 under the local area network, and confirm the assisting device of the device 1 in the networking. For specific steps, see the description of Figure 8 below.
[0174] S702, the device 1 sends an authentication request to the authentication server 200.
[0175] Specifically, the device 1 enters a networking state and sends an authentication request to the authentication server 200. In some embodiments, the authentication request sent by the device 1 includes a request to obtain the authentication information of all electronic devices in the networking. In other embodiments, the device 1 can first initiate an authentication request to the authentication server 200, and then perform step S701 to complete networking with the device 2. It should be understood that the present scheme does not limit the order of the device 1 joining the networking and obtaining the authentication information.
[0176] S703, the authentication server 200 returns the authentication information.
[0177] Specifically, after authentication server 200 generates authentication information for device 1 based on the authentication request, it sends the authentication information to device 1. Device 1 receives and stores the authentication information. The authentication information stored locally by device 1 may also be referred to as first authentication information. In some embodiments, authentication server 200 generates authentication information for all devices in the network based on the authentication request and sends the authentication information to device 1. Device 1 receives and stores the authentication information for all devices in the network.
[0178] S704: Device 1 broadcasts authentication information.
[0179] Specifically, after device 1 obtains its authentication information, it broadcasts the authentication information to the remaining electronic devices 100 in the network, which then store the authentication information. In some embodiments, device 1 broadcasts the authentication information of all devices to the remaining devices in the network. After device 2 receives the authentication information, it updates the authentication information update time and authentication status. It should be understood that in addition to device 1 actively obtaining authentication information, when device 2 obtains authentication information from the authentication server, it also sends the authentication information to device 1.
[0180] The above describes the process of device 1 joining the network, obtaining authentication information from the authentication server 200, and broadcasting the authentication information. It should be noted that the authentication information obtained by device 1 from the authentication server 200 in step S703 can be its own authentication information; it can also be the authentication information of all electronic devices in the network. When device 1 obtains the authentication information of all electronic devices in the network, device 1 stores and broadcasts the authentication information of all electronic devices. At this time, other electronic devices can obtain authentication information through device 1 and can synchronously update their own authentication information. There is no need to obtain authentication information from the authentication server before the updated authentication information expires, thereby reducing the frequency of other electronic devices obtaining authentication information from the authentication server, reducing the delay caused by other electronic devices synchronizing authentication information with the authentication server during business use, and improving business response speed.
[0181] S705: Receive Kit usage request.
[0182] Specifically, other electronic devices can invoke functions of device 1 through applications. These other electronic devices initiate a Kit usage request to device 1 for a first function in device 1. This Kit usage request can also be referred to as a call request. For example, if device 1 is a camera and a mobile phone wants to invoke the camera's recording function, it can send a request message to the camera. This request message includes a DV Kit identifier, requesting the camera's DV Kit to be invoked.
[0183] In some embodiments, the Kit usage request is initiated by a user's operation on the first function in the first device.
[0184] In some embodiments, when the device 1 needs to use the Kit at runtime, the device 1 will initiate a Kit usage request to the Kit service subsystem of the device 1.
[0185] S706, authenticating the locally stored authentication information.
[0186] Specifically, after the device 1 receives the Kit usage request, the device 1 authenticates the Kit that needs to be called. At this time, the Kit service will call the Kit management module in the Kit framework through the interface, and the authentication of the authentication information will be completed by the Kit management module. The Kit management module will obtain the locally stored authentication information of the device 1 from the memory of the device 1, and judge whether the local authentication information passes the authentication through the authentication information update state in the authentication information.
[0187] Optionally, if the authentication information in the device 1 uses the HMAC key, the HMAC key needs to be verified before judging whether the local authentication information passes the verification.
[0188] S707, judging whether the locally stored authentication information is within the valid period.
[0189] Specifically, if the state of the locally stored authentication information in the device 1 is that the authentication information exceeds the valid period or the authentication information is pending authentication server authentication, it is considered that the locally stored authentication information does not pass the authentication, and the following step S708 is executed; if the update state of the locally stored authentication information is within the valid period, it is considered that the locally stored authentication information passes the authentication, and the following step S711 is executed.
[0190] In some embodiments, if the locally stored authentication information in the device 1 uses the HMAC key signature, the device 1 also needs to verify the HMAC key of the authentication information. If the locally stored authentication information does not pass the HMAC authentication, the following step S708 is executed, and the authentication information is reacquired from the authentication server.
[0191] If it is not within the valid period, S708 is executed, and the device 1 sends an authentication request to the authentication server 200.
[0192] Specifically, if the authentication information update state of the device 1 is that the authentication information exceeds the valid period or the authentication information is pending authentication server authentication, an authentication request needs to be sent to the authentication server 200 to acquire the latest authentication information. The specific steps can be referred to the description of step S702, which will not be described here.
[0193] S709, the authentication server 200 returns the authentication information.
[0194] Specifically, after the authentication server 200 generates the authentication information of the device 1 according to the authentication request, the authentication server 200 sends the authentication information to the device 1, and the device 1 accepts and stores the authentication information. For details, refer to the description of step S703, which will not be repeated here.
[0195] S710, the device 1 broadcasts the authentication information.
[0196] Specifically, after the device 1 obtains the authentication information of the device 1, the device 1 broadcasts the authentication information to the remaining electronic devices 100 in the network, which will store the authentication information. For details, refer to the description of step S704, which will not be repeated here.
[0197] In this case, after the device 1 receives the authentication information, the device 1 directly performs S717.
[0198] If within the validity period, perform S711, the device 1 sends a request for assistance verification to the device 2.
[0199] Specifically, the device 1 initiates a request for assistance verification through the assistance verification module, wherein the request for assistance verification includes the authentication information stored by the device 1. In other embodiments, the device 1 first sends a request for assistance verification to the device 2, and then sends the authentication information stored locally by the device to be authenticated to the device 2 after the device 2 agrees to the request.
[0200] Optionally, after the device 1 initiates assistance verification, the assistance device is screened, including: obtaining a list of electronic devices paired with the device to be authenticated from the local storage, and screening the assistance device that can assist the device to be authenticated from the paired device list according to the screening principle. The screening principle is that the assistance device at least needs to have the authentication information of the device 1, and the remaining screening principles can be referred to the description of step S804 below, which will not be described in detail here.
[0201] S712, verify the authentication information of the device 1.
[0202] Specifically, the device 2 finds the authentication information of the device 1 in the storage information of the device 2, compares the authentication information with the authentication information sent by the device 1, and returns a verification result, wherein if the comparison result is consistent, it is considered that the authentication information of the device 1 is authentic; if the comparison result is inconsistent, it is considered that the authentication information of the device 1 is not authentic, and the authentication information of the device 1 may be tampered with.
[0203] Exemplarily, if the authentication result of the device 1 is trusted, the verification passes, which can be indicated by a mark "PASS"; if the update date of the authentication information stored in the device 2 is earlier than that of the authentication information stored in the device 1, the verification result is out of date, which can be indicated by a mark "OUT_OF_DATE"; if the authentication result of the device 1 is not trusted, the verification fails, which can be indicated by a mark "FAKE".
[0204] Optionally, if the authentication information in the device to be authenticated or the authentication information stored in the assisting device uses an HMAC key, the HMAC key needs to be verified before the verification.
[0205] S713, the device 2 returns the verification result to the device 1.
[0206] Specifically, as shown in step S712, the verification result includes: the authentication information is trusted, and the authentication information is not trusted. Optionally, if the update date of the authentication information stored in the device 2 is earlier than that of the authentication information stored in the device 1, the authentication information stored in the assisting device is considered to be out of date, and then the device 2 needs to update the authentication information and assist the device 1 to verify before returning the verification result.
[0207] S714, it is judged whether the locally stored authentication information is trusted. Specifically, the device 1 receives the verification result returned by the device 2, and judges whether the locally stored authentication information of the device 1 is trusted according to the verification result. If yes, step S717 is performed; if not, step S715 is performed.
[0208] Optionally, if there are multiple assisting devices, if the authentication information stored in part of the assisting devices is different from the authentication information of the device to be authenticated, and the proportion of the assisting devices in which the authentication information stored is different from the authentication information of the device to be authenticated in all the assisting devices is greater than or equal to a preset proportion, it is considered that the first authentication information is not trusted, or the number of the assisting devices in which the authentication information stored is different from the authentication information of the device to be authenticated is greater than or equal to the number of the assisting devices in which the saved authentication information is the same as the first authentication information, it is considered that the first authentication information is not trusted. For example, if more than half of the authentication information of the assisting devices is the same as the authentication information of the device to be authenticated, it is considered that the authentication information in the device to be authenticated is trusted; if more than half of the authentication information of the assisting devices is different from the authentication information of the device to be authenticated, it is considered that the authentication information in the device to be authenticated is not trusted.
[0209] Optionally, if there are multiple assisting devices, the following method can also be used when judging whether the authentication information in the device to be authenticated is trustworthy: if the number of assisting verification devices whose saved authentication information is determined by the verification results received by the multiple assisting verification devices to be different from the first authentication information is greater than or equal to a preset number, it is considered that the authentication information in the device to be authenticated is untrustworthy. For example: as long as there is one assisting device whose authentication information is different from the authentication information of the device to be authenticated, it is considered that the authentication information in the device to be authenticated is untrustworthy.
[0210] If the device 1 judges that the locally stored authentication information is untrustworthy, the device 1 sends an authentication request to the authentication server 200, S715.
[0211] Specifically, in the case where the device 1 judges that the locally stored authentication information is untrustworthy, the device 1 sends an authentication request to the authentication server 200 to obtain the latest authentication information. The specific steps can be referred to the description of step S702, which will not be repeated here.
[0212] The authentication server 200 returns the authentication information, S716.
[0213] Specifically, after the authentication server 200 generates the authentication information of the device 1 according to the authentication request, the authentication server 200 sends the authentication information to the device 1, and the device 1 accepts the authentication information and stores the authentication information. The specific steps can be referred to the description of step S703, which will not be repeated here.
[0214] If the device 1 judges that the locally stored authentication information is trustworthy, it is determined whether the device 1 can use the Kit based on the authentication result, S717.
[0215] Specifically, in the case where the device 1 judges that the locally stored authentication information is trustworthy, the device 1 determines whether the device 1 can use the Kit according to the authentication result in the authentication information. If the authentication result is that the device 1 cannot use the Kit, step S718 is performed; if the authentication result is that the device 1 can use the Kit, step S719 is performed.
[0216] The Kit use request is rejected, S718.
[0217] Specifically, if the authentication result in the authentication information of the device 1 is that the device 1 cannot use the Kit, the device 1 rejects the Kit use request. Optionally, the device 1 can pop up a window to prompt the user that the device 1 does not have the right to use the Kit.
[0218] The Kit is used, S719.
[0219] Specifically, if the authentication result in the authentication information of device 1 indicates that device 1 can use the Kit, the Kit framework of device 1 will return the authentication result to the Kit service subsystem, and the Kit service subsystem will provide Kit services to the sender of the Kit usage request.
[0220] To summarize, if the authentication information of device 1 indicates that the Kit cannot be used, but is tampered with to indicate that the Kit can be used, the device authentication method provided in this application can detect that the authentication information of device 1 is inconsistent with the authentication information of device 2 and / or device 3, and then detect that the authentication information of device 1 has been tampered with, thereby preventing unauthorized devices from using the Kit beyond their authority; if the authentication information of device 1 indicates that the Kit can be used, but is tampered with to indicate that the Kit cannot be used, the device authentication method provided in this application can detect that the authentication information of device 1 is inconsistent with the authentication information of device 2 and / or device 3, and then detect that the authentication information of device 1 has been tampered with, thereby preventing authorized devices from being unable to use normally.
[0221] The device authentication method provided in this application can detect whether the authentication information of an electronic device has been tampered with, thereby improving the security of the system; moreover, the method can also synchronize authentication information through other electronic devices in a timely manner, reducing the frequency with which electronic devices obtain authentication information from an authentication server, reducing the delay caused by synchronizing authentication information with an authentication server during business use, and improving business response speed.
[0222] The following combination Figure 8 The above step S701 is supplemented as follows: Figure 8 FIG. 1 shows the steps of networking of electronic device 100, wherein device 2 is in pairing state, including:
[0223] S801: Device 1 enters pairing state.
[0224] Specifically, after being started, the device 1 may enter a pairing state, where the pairing mode may be Bluetooth, Wi-Fi, etc. The device 1 in the pairing state will search for a device 2 in the pairing state within a certain range.
[0225] S802: Device 1 is paired with device 2.
[0226] Specifically, device 1 is paired with device 2, and the pairing principle may adopt a verification code mechanism or a same account mechanism.
[0227] The verification code mechanism means that device 2 that needs to be paired randomly generates or manually sets a verification code, and device 1 enters the verification code to successfully pair; or, device 1 randomly generates or manually sets a verification code, and device 2 enters the verification code to successfully pair.
[0228] The same account mechanism refers to that device 1 and device 2 log in the same system account, and the system will be paired through the distributed software bus. The specific steps are as follows: device 1 sends a pairing request to device 2; device 2 reads the local account information; device 2 verifies whether the local account information is consistent with the account information of device 1. For example, device 2 verifies whether the local account information is consistent with the account information of device 1, which can be verified by using a security token service (STS); if the verification is successful, device 1 and device 2 are successfully paired. In some embodiments, before device 2 verifies the local account information and the account information of device 1, it can also be determined whether device 1 and device 2 are first paired; if device 1 and device 2 are first paired, device 2 can use password authentication key exchange (PAKE) to authenticate device 1; if device 1 and device 2 are not first paired, it is necessary to check whether there is device 1 information in the local registry information of device 2, wherein the local registry information includes the information of the devices that have been paired with device 2. It should be understood that the present scheme does not specifically limit the pairing principle of electronic device 100.
[0229] S803, determine whether the pairing is successful.
[0230] Specifically, after device 1 and device 2 complete the pairing verification, it is determined whether the pairing is successful. If the pairing is successful, step S804 is performed; if the pairing fails, step S805 is performed.
[0231] S804, device 1 joins the networking.
[0232] Specifically, after device 1 is successfully paired, device 1 will join the networking of device 2, and device 1 and other devices in the networking will update the networking information, wherein the networking information at least includes the unique identifier of all electronic devices 100 in the networking.
[0233] Optionally, after device 1 joins the networking, the electronic devices 100 in the networking can be screened to confirm the assisting devices of the electronic devices 100. The assisting devices can be one or more, and the number of the assisting devices is not specifically limited by the present scheme. The assisting devices obtained by screening the electronic devices 100 can be screened according to the device information of the assisting devices, for example, the electronic devices 100 with better RAM, CPU or networking performance state are screened as assisting devices.
[0234] S805, continue to wait for pairing.
[0235] Specifically, after device 1 fails to pair, it will continue to wait for the devices in the pairing state in the networking and initiate pairing again.
[0236] The above describes the process of pairing the device 1 with the device 2 and the device 1 joining the network of the device 2. Through the above process, the device 1 can communicate with other electronic devices in the network after joining the network of the device 2, and the devices in the network can assist the device 1 in verification when the device 1 needs to use the Kit.
[0237] The above describes the process of pairing the device 1 with the device 2 and the device 1 joining the network of the device 2. Through the above process, the device 1 can communicate with other electronic devices in the network after joining the network of the device 2, and the devices in the network can assist the device 1 in verification when the device 1 needs to use the Kit. Figure 9 The above describes the process of pairing the device 1 with the device 2 and the device 1 joining the network of the device 2. Through the above process, the device 1 can communicate with other electronic devices in the network after joining the network of the device 2, and the devices in the network can assist the device 1 in verification when the device 1 needs to use the Kit. Figure 9 The above describes the process of pairing the device 1 with the device 2 and the device 1 joining the network of the device 2. Through the above process, the device 1 can communicate with other electronic devices in the network after joining the network of the device 2, and the devices in the network can assist the device 1 in verification when the device 1 needs to use the Kit.
[0238] S901, the device 1 screens the assisting device from the electronic devices in the same network, wherein the device 1 screens the electronic device 100 with better RAM, CPU or networking performance state as the assisting device. Specifically, after the device 1 joins the network, the device 1 obtains the device information of all devices in the local area network. After the device 1 receives the Kit use request and judges that the local authentication information is within the valid period, the device 1 selects the device with networking function as the assisting device of the device 1 according to the device information of all devices in the local area network. In other embodiments, the device 1 also selects the device with low latency, large bandwidth, large memory, high memory frequency, high CPU working frequency and large CPU cache as the assisting device according to the network latency, network bandwidth, memory size, memory frequency, CPU working frequency and CPU cache size.
[0239] S902, the device 1 sends the assisting verification request to the assisting device.
[0240] S903, the device 2 confirms whether to agree to the assisting verification request of the device 1 according to the actual situation. For example, if the processor of the device 2 is in the busy green state, the device 2 can refuse the assisting verification request of the device 1. For another example, if the authentication information of the device 1 is not stored in the device 2, the device 2 can refuse the assisting verification request of the device 1. If all assisting devices refuse the assisting verification request, the device 1 will enter the waiting verification state until there is an assisting device that can assist the verification, and then send an agreement request to the device 1. If the device 2 can assist the verification, the device 2 sends an agreement request to the device to be authenticated.
[0241] S904, after receiving the agreement request, the device 1 sends the authentication information of the device 1 to the device 2.
[0242] S905, the device 2 finds the authentication information of the device 1 in the storage information of the device 2, compares the authentication information with the authentication information sent by the device 1, and returns the verification result.
[0243] In some embodiments, the authentication information can also be sent to the device 2 when the device 1 sends the assistance verification request to the device 2. That is, the device 1 sends the assistance verification request and the authentication information to the assistance device in step S902, if the device 2 agrees to the assistance verification request of the device 1, step S905 is performed, the device 2 finds the authentication information of the device 1 in the storage information of the device 2, compares the authentication information with the authentication information sent by the device 1, and returns the verification result, without performing steps S903 and S904.
[0244] In some embodiments, after the device 1 sends the assistance verification request to the device 2, if the device 2 agrees to the assistance verification request of the device 1, the device 2 sends the authentication information of the device 1 stored by the device 2 to the device 1, the authentication information sent by the device 2 is compared with the authentication information stored by the device 1, and the verification result is generated.
[0245] The steps of the device authentication method provided in the present application are described below. Figure 10 The device 1 is a device to be authenticated, and the device 1 does not have networking function, which can also be referred to as a first device. The device 2 is an assistance device, which can also be referred to as an assistance verification device, an assistance authentication device or a second device, and includes the following steps.
[0246] S1001, the device 1 and the device 2 complete networking.
[0247] Specifically, after the device 1 is started, it will join the local area network through the distributed soft bus, so that the device 1 can communicate with other electronic devices 100 under the local area network. In some embodiments, after the device 1 joins the networking, it will screen other electronic devices 100 under the local area network, and select the devices with networking capability as the assistance devices of the device 1. For specific steps, refer to the description of the above-mentioned Figure 8 .
[0248] S1002, the device 1 sends an authentication request to the device 2.
[0249] Specifically, the device 1 sends an authentication request to the device 2 through Bluetooth or Wi-Fi, etc., wherein the authentication request at least includes the unique identifier of the device to be authenticated and the unique identifier of the Kit. In some embodiments, the authentication request sent by the device 1 includes a request to obtain the authentication information of all electronic devices in the networking.
[0250] S1003, the device 2 forwards the authentication request to the authentication server 200.
[0251] Specifically, the assistance device with networking capability sends the authentication request of the device 1 to the authentication server 200.
[0252] S1004, the authentication server sends the authentication information to the device 2
[0253] Specifically, after receiving the authentication request, the authentication server authenticates the device to be authenticated according to the authentication request, confirms whether the device to be authenticated has the right to access the Kit, and generates authentication information and sends it to the device 2. The authentication information includes the device identifier of the device to be authenticated, the kit service that can be called by the device identifier, and the like. Optionally, the authentication server can set a limited period for the authentication information according to the actual situation.
[0254] S1005, the device 2 stores the authentication information.
[0255] Specifically, after receiving the authentication information of the device 1, the device 2 will store the authentication information. Optionally, if the device 1 has multiple assisting devices, the device 2 will send the authentication information to each assisting device, and each assisting device will store the authentication information of the device 1.
[0256] S1006, the device 2 forwards the authentication information to the device 1. After receiving the authentication information, the device 1 will store the authentication information. The authentication information saved locally by the device 1 can also be referred to as the first authentication information
[0257] The above describes the process of device 1 joining the networking and obtaining authentication information from the authentication server 200 through the device 2. It needs to be noted that the authentication information obtained by the device 1 from the authentication server 200 through the device 2 in step S1006 can be the authentication information of the device 1 itself; or the authentication information of all electronic devices in the networking. At this time, the device 2 will store the authentication information of other electronic devices before forwarding the authentication information to the device 2. That is to say, other electronic devices can update their own authentication information synchronously when the device 1 obtains the authentication information, without the need to obtain authentication information from the authentication server before the updated authentication information expires, thereby reducing the frequency of other electronic devices obtaining authentication information from the authentication server, reducing the delay generated by other electronic devices synchronizing authentication information from the authentication server during business use, and improving the business response speed.
[0258] In some embodiments, after receiving the authentication information sent by the authentication server, the device 2 does not store the authentication information, but directly forwards the authentication information to the device 1, that is, does not perform step S1005, and directly performs step S1006 after step S1004. In this case, after receiving the authentication information, the device 1 will forward the authentication information to all devices in the networking, and other devices in the networking will store the authentication information.
[0259] S1007, receiving a Kit use request.
[0260] Specifically, the other electronic device can invoke the function of the device 1 through an application, and the other electronic device initiates a Kit usage request to the device 1 for the first function in the device 1, which can also be referred to as an invocation request. For example, the device 1 is a camera, and a mobile phone wants to invoke the camera function of the camera. The mobile phone can send a request message to the camera, and the request message includes the identifier of the DV Kit, to request to invoke the DV Kit of the camera.
[0261] In some embodiments, the Kit usage request is initiated by an operation of a user for the first function in the first device.
[0262] In some embodiments, when the device 1 needs to use the Kit during runtime, the device 1 initiates a Kit usage request to the Kit service subsystem of the device 1.
[0263] S1008, authenticating the locally stored authentication information.
[0264] Specifically, after the device 1 receives the Kit usage request, the device 1 authenticates the Kit that needs to be invoked. At this time, the Kit service invokes the Kit management module in the Kit framework through an interface, and the Kit management module can complete the authentication of the authentication information. The Kit management module obtains the locally stored authentication information of the device 1 from the memory of the device 1, and judges whether the local authentication information passes the authentication through the authentication information update state in the authentication information. Optionally, if the authentication information in the device 1 uses an HMAC key, the HMAC key needs to be verified before judging whether the local authentication information passes the verification.
[0265] S1009, judging whether the locally stored authentication information is within a valid period.
[0266] Specifically, if the update state of the locally stored authentication information in the device 1 is that the authentication information exceeds the valid period or the authentication information is to be authenticated by the server, the following step S1010 is performed; if the update state of the authentication information is within the valid period, the following step S1015 is performed. In some embodiments, if the locally stored authentication information in the device 1 is signed by an HMAC key, the device 1 also needs to verify the HMAC key of the authentication information.
[0267] If it is not within the valid period, S1010 is performed, and the device 1 sends an authentication request to the device 2.
[0268] Specifically, the device 1 sends an authentication request to the device 2 through Bluetooth or Wi-Fi, and the specific process is described in the above step S1002, which will not be described here.
[0269] S1011, the device 2 forwards the authentication request to the authentication server 200.
[0270] Specifically, the authentication server receives the authentication request from the device 1 and sends the authentication information to the device 2.
[0271] S1012, the authentication server sends the authentication information to the device 2.
[0272] Specifically, the authentication server receives the authentication request from the device 1 and sends the authentication information to the device 2.
[0273] S1013, the device 2 stores the authentication information.
[0274] Specifically, the authentication server receives the authentication request from the device 1 and sends the authentication information to the device 2.
[0275] S1014, the device 2 forwards the authentication information to the device 1. After receiving the authentication information, the device 1 stores the authentication information.
[0276] In this case, after receiving the authentication information, the device 1 directly executes S717.
[0277] If the validity period is within the validity period, the device 1 sends a request for assistance verification to the device 2.
[0278] Specifically, the device 1 initiates a request for assistance verification through the assistance verification module and obtains a list of assistance devices for the device 1 from local storage, wherein the request for assistance verification includes the authentication information stored by the device 1. In other embodiments, the device to be authenticated first sends a request for assistance verification to the assistance device, and then sends the authentication information stored locally by the device to be authenticated to the assistance device after the assistance device agrees to the request.
[0279] Optionally, after initiating assistance verification, the device to be authenticated further screens the assistance authentication, including: obtaining a list of electronic devices paired with the device to be authenticated from local storage, and screening the assistance devices that can assist the device to be authenticated from the list of paired devices according to the screening principle. The screening principle can be referred to the description of step S804, which will not be repeated here.
[0280] S1016, the authentication information of the device 1 is verified.
[0281] Specifically, the device 2 will find the authentication information of the device 1 in the storage information of the device 2, compare the authentication information with the authentication information sent by the device 1, and return the verification result, wherein if the comparison result is consistent, it is considered that the authentication information of the device 1 is trusted; if the comparison result is inconsistent, it is considered that the authentication information of the device 1 is untrusted, and the authentication information of the device 1 may be tampered; if the update date of the authentication information stored in the device 2 is before the authentication information stored in the device 1, it is considered that the authentication information of the assisting device is expired, and the authentication information stored in the device 2 needs to be updated before verification.
[0282] Exemplarily, when the authentication result of the device 1 is trusted, the verification is passed, which can be indicated by the identifier "PASS"; if the update date of the authentication information stored in the device 2 is before the authentication information stored in the device 1, the verification result is expired, which can be indicated by the identifier "OUT_OF_DATE"; if the authentication result of the device 1 is untrusted, the verification is failed, which can be indicated by the identifier "FAKE".
[0283] Optionally, if the authentication information in the device to be authenticated or the authentication information stored in the assisting device uses the HMAC key, the HMAC key needs to be verified before verification.
[0284] S1017, the device 2 returns the verification result to the device 1.
[0285] Specifically, as shown in step S1016, the verification result includes: the authentication information is trusted, and the authentication information is untrusted. Optionally, if the verification result of the device 2 is that the authentication information of the device 2 is expired, the device 2 updates the authentication information and assists the device 1 to verify, and then returns the verification result.
[0286] S1018, the device 1 judges whether the local authentication information is trusted.
[0287] Specifically, the device 1 receives the verification result returned by the device 2, and judges whether the local authentication information of the device 1 passes the verification according to the verification result, if the device 1 judges that the local authentication information is trusted, the following step S1024 is executed; if the device 1 judges that the local authentication information is untrusted, the following step S1019 is executed.
[0288] Optionally, if there are multiple assisting devices, if the authentication information stored in part of the assisting devices is different from the authentication information of the device to be authenticated, and the proportion of the assisting devices in which the stored authentication information is different from the authentication information of the device to be authenticated is greater than or equal to a preset proportion among all the assisting devices, it is considered that the first authentication information is not trusted, or the number of assisting devices in which the stored authentication information is different from the authentication information of the device to be authenticated is greater than or equal to the number of assisting devices in which the stored authentication information is the same as the first authentication information, it is considered that the first authentication information is not trusted. For example, if more than half of the authentication information of the assisting devices is the same as the authentication information of the device to be authenticated, it is considered that the authentication information in the device to be authenticated is trusted; if more than half of the authentication information of the assisting devices is different from the authentication information of the device to be authenticated, it is considered that the authentication information in the device to be authenticated is not trusted.
[0289] Optionally, if there are multiple assisting devices, when judging whether the authentication information in the device to be authenticated is trusted, the following method can also be used: when the number of assisting verification devices receiving verification results that determine that the stored authentication information is different from the first authentication information is greater than or equal to a preset number, it is considered that the authentication information in the device to be authenticated is not trusted. For example: as long as there is one assisting device whose authentication information is different from the authentication information of the device to be authenticated, it is considered that the authentication information in the device to be authenticated is not trusted.
[0290] If the device 1 judges that the locally stored authentication information is not trusted, S1019 is executed, and the device 1 sends an authentication request to the device 2.
[0291] Specifically, in the case where the device 1 judges that the locally stored authentication information is not trusted, the device 1 sends an authentication request to the device 2 through Bluetooth or Wi-Fi or the like, and specific details can be referred to in the above step S1002, which will not be repeated here.
[0292] S1020, the device 2 forwards the authentication request to the authentication server 200.
[0293] Specifically, the assisting device with networking capability sends the authentication request of the device 1 to the authentication server 200.
[0294] S1021, the authentication server sends authentication information to the device 2.
[0295] Specifically, after receiving the authentication request, the authentication server performs authentication on the device to be authenticated according to the authentication request, confirms whether the device to be authenticated has the right to access the Kit, and generates authentication information and sends it to the device 2. Specific details can be referred to in the above step S1004, which will not be repeated here.
[0296] S1022, the device 2 stores the authentication information.
[0297] Specifically, after receiving the authentication information of the device 1, the device 2 stores the authentication information. For details, please refer to the above step S1005, which will not be repeated here.
[0298] S1023, the device 2 forwards the authentication information to the device 1.
[0299] If the device 1 judges that the locally stored authentication information is authentic, it performs S1024, judges whether the device 1 can use the Kit based on the authentication result.
[0300] Specifically, in the case where the device 1 judges that the locally stored authentication information is authentic, the device 1 determines whether the device 1 can use the Kit according to the authentication result in the authentication information. If the authentication result is that the device 1 cannot use the Kit, step S1025 is performed; if the authentication result is that the device 1 can use the Kit, step S1026 is performed.
[0301] S1025, reject the Kit use request.
[0302] Specifically, if the authentication result in the authentication information of the device 1 is that the device 1 cannot use the Kit, the device 1 rejects the Kit use request. Alternatively, the device 1 can pop up a window to prompt the user that the device 1 does not have the right to use the Kit.
[0303] S1026, use the Kit.
[0304] Specifically, if the authentication result in the authentication information of the device 1 is that the device 1 can use the Kit, the Kit framework of the device 1 returns the authentication result to the Kit service subsystem, and the Kit service subsystem provides the Kit service to the sender of the Kit use request.
[0305] In some embodiments, alternatively, when the device 1 performs step S1002, step S1010, and step S1019, the device 1 can send the authentication request to any device in the network that can be connected to the network, and the device forwards the authentication request to the authentication server and forwards the authentication information to the device 1. That is, the device that forwards the authentication request to the authentication server and forwards the authentication information to the device 1 can not be the device 2.
[0306] To summarize, if the authentication information of device 1 indicates that the Kit cannot be used, but is tampered with to indicate that the Kit can be used, the device authentication method provided in this application can detect that the authentication information of device 1 is inconsistent with the authentication information of device 2 and / or device 3, and then detect that the authentication information of device 1 has been tampered with, thereby preventing unauthorized devices from using the Kit beyond their authority; if the authentication information of device 1 indicates that the Kit can be used, but is tampered with to indicate that the Kit cannot be used, the device authentication method provided in this application can detect that the authentication information of device 1 is inconsistent with the authentication information of device 2 and / or device 3, and then detect that the authentication information of device 1 has been tampered with, thereby preventing authorized devices from being unable to use normally.
[0307] The device authentication method provided in this application can detect whether the authentication information of an electronic device has been tampered with, thereby improving the security of the system; moreover, the method can also synchronize authentication information through other electronic devices in a timely manner, reducing the frequency with which electronic devices obtain authentication information from an authentication server, reducing the delay caused by synchronizing authentication information with an authentication server during business use, and improving business response speed.
[0308] The following is an example of the device authentication method provided by this application, combined with application scenarios.
[0309] like Figure 11 As shown, a mobile phone, TV, rice cooker, and camera are in the same network. The TV's unique device identifier is ID1, the rice cooker's is ID2, and the camera's is ID3. After a certain end-cloud authentication, the TV, rice cooker, and camera in the network all cached their authentication information. The TV, because it failed the audit, was not allowed to use the DV Kit, resulting in a DENY authentication result. However, Device 4 tampered with the authentication information stored in the TV, changing the DENY to PASS.
[0310] At this point, if the user wants to use the DV Kit service, they need to go through the following process:
[0311] S1101. Send a Kit usage request.
[0312] Specifically, the user can cast the screen to the TV through the application of the electronic device 101, that is, call the display function of the TV. After the application obtains the user's operation, it will initiate a Kit usage request to the TV. The Kit usage request is used to request the use of the DV Kit of the TV Kit service subsystem.
[0313] S1102. The TV authenticates local authentication information.
[0314] Specifically, the DV Kit service initiates device authentication to the Kit management module of the television, the Kit management module reads and authenticates the authentication information stored by the television, and the authentication result is "PASS", and the authentication information is within the valid period.
[0315] S1103, the television initiates assisted verification to the electric cooker and the camera.
[0316] Specifically, the television initiates an assisted verification request to the camera and the electric cooker in the network; the camera and the electric cooker compare the stored television authentication information with the authentication information of the television, wherein the DV kit authentication result of the television stored by the camera and the electric cooker is "DENY", and the result of not matching the authentication information of the television is obtained.
[0317] S1104, return the verification result.
[0318] Specifically, the camera and the electric cooker return the verification result "FAKE" to the television, and the television integrates the authentication information of the two assisting devices to determine that the authentication information of the television is tampered.
[0319] S1105, the television initiates end-to-cloud authentication.
[0320] Specifically, the television connects the authentication server 200 to remember the end-to-cloud authentication to obtain the latest authentication information.
[0321] S1106, the authentication server 200 returns the authentication result.
[0322] Specifically, the authentication server 200 returns the authentication result to the television, wherein the authentication result is "DENY".
[0323] S1107, a pop-up window prompts that the device authentication information has been tampered.
[0324] Optionally, if the television fails to connect to the network and cannot obtain authentication information from the authentication server 200, the television returns verification failure information to the electronic device 101, and the electronic device 101 receives the information and pops up a window to remind the user that the authentication information has been tampered.
[0325] In summary, through the device authentication method provided in the present application, it is found that the authentication information of the camera and the electric cooker stored by the television does not match the authentication information of the television, and it is further found that the television authentication information has been tampered, which prevents unauthorized television from using the Kit beyond the authority, and improves the security of the system.
[0326] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk) and the like. Those skilled in the art can understand that all or part of the processes in the above embodiments can be instructed by a computer program to complete the relevant hardware, and the program can be stored in a computer readable storage medium, and the program can include the processes of the above embodiments when executed. The foregoing storage medium includes ROM or random access memory RAM, magnetic disk or optical disk and various media capable of storing program codes.
Claims
1. A device authentication method, characterized in that: Applied to a first device, comprising: Upon detecting a call request for a first function on the first device, sending first authentication information to at least one assisting verification device, wherein both the first device and the at least one assisting verification device store the authentication information of the first function on the first device, and the first authentication information is the authentication information of the first function stored by the first device; receiving a verification result from the at least one assisting verification device, wherein the verification result received from any assisting verification device is used to indicate whether the first authentication information is the same as the authentication information stored by the assisting verification device; When it is determined that the first authentication information is not trustworthy based on the verification result received from the at least one assisting verification device, authentication information of the first function on the first device is obtained from an authentication server, and execution of the first function is controlled based on the authentication result in the authentication information obtained from the authentication server, wherein the authentication result is used to indicate whether the first device is allowed to execute the first function.
2. The method according to claim 1, characterized in that The at least one authentication assisting device comprises only one authentication assisting device; Determining that the first authentication information is unreliable based on the verification result received from the at least one assisting verification device includes: determining that the first authentication information is unreliable when it is determined that the first authentication information is different from the authentication information stored by the assisting verification device based on the verification result received from the assisting verification device.
3. The method according to claim 1, characterized in that The at least one authentication assisting device includes a plurality of authentication assisting devices; The determining, based on the verification result received from the at least one assisting verification device, that the first authentication information is untrustworthy includes: When it is determined based on the verification results received from the multiple assisting verification devices that the number of assisting verification devices whose stored authentication information is different from the first authentication information is greater than or equal to a preset number, determining that the first authentication information is unreliable; or When it is determined based on the verification results received from the multiple assisting verification devices that the proportion of assisting verification devices whose stored authentication information is different from the first authentication information among the multiple assisting verification devices is greater than or equal to a preset proportion, determining that the first authentication information is unreliable; or When it is determined based on the verification results received from the multiple assisting verification devices that the number of assisting verification devices whose stored authentication information is different from the first authentication information is greater than or equal to the number of assisting verification devices whose stored authentication information is the same as the first authentication information, it is determined that the first authentication information is unreliable.
4. The method according to claim 1, wherein The calling request comes from another device; or, the calling request comes from a user operation on the first device.
5. The method according to claim 1, wherein The at least one authentication assisting device and the first device are located in the same local area network.
6. The method according to claim 5, characterized in that Before detecting a call request for a first function on the first device, the method further includes: The first device sends an authentication request to the authentication server, wherein the authentication request is used to request the authentication server to authenticate the first function on the first device; The first device receives authentication information of the first function sent by the authentication server according to the authentication request, and saves the authentication information as first authentication information.
7. The method according to claim 6, characterized in that After the first device receives the authentication information of the first function sent by the authentication server according to the authentication request, the further step includes: The first device sends the authentication information to the at least one assisting verification device.
8. The method according to claim 5, characterized in that Before detecting a call request for a first function on the first device, the method further includes: The first device sends an authentication request to the assisting authentication device, and instructs the assisting authentication device to forward the authentication request to the authentication server, wherein the authentication request is used to request the authentication server to authenticate the first function on the first device; The first device receives, through the auxiliary authentication device, authentication information of the first function sent by the authentication server according to the authentication request, and saves the authentication information.
9. The method according to claim 8, characterized in that The at least one assisting verification device comprises the assisting authentication device.
10. The method according to any one of claims 1 to 9, characterized in that: Sending first authentication information to at least one assisting verification device includes: In response to the calling request, the first device detects whether the first authentication information is within a validity period; When the first device detects that the first authentication information is within the validity period, the first device sends the first authentication information to the at least one assisting verification device.
11. The method according to any one of claims 1 to 9, characterized in that: The first authentication information is encrypted using a hash operation, and when a call request for a first function on the first device is detected, sending the first authentication information to at least one assisting verification device includes: When detecting a call request for a first function on the first device, the first device verifies the first authentication information using a hash operation message authentication code; When the first device passes the verification, the first device sends first authentication information to the at least one assisting verification device.
12. The method according to any one of claims 1 to 9, characterized in that: Before sending the first authentication information to at least one assisting verification device, the method further includes: The first device determines a device that meets a preset condition among devices in the local area network to which the first device belongs as the assisting verification device, wherein the preset condition includes authentication information of the first function stored on the first device.
13. The method according to any one of claims 1 to 9, characterized in that: Sending first authentication information to at least one assisting verification device includes: In response to the call request, the first device sends an assistance verification request to each device in the local area network where the first device is located; The first device receives an assisted verification response sent by the at least one assisted verification device in response to the assisted verification request, indicating consent to the assisted verification; The first device sends the first authentication information to the at least one assisted verification device in response to the assisted verification response.
14. The method according to any one of claims 1 to 9, characterized in that: After receiving the verification result from the at least one verification assisting device, the method further includes: When it is determined that the first authentication information is authentic according to the authentication result received from the at least one assisting authentication device, execution of the first function is controlled according to the authentication result in the first authentication information.
15. A device authentication method, characterized in that: Applied to the second device, comprising: The second device receives a first authentication request sent by the first device, wherein the first authentication request is used to request an authentication server to authenticate a first function on the first device; The second device forwards the first authentication request to the authentication server according to an instruction of the first device; The second device receives authentication information of the first function sent by the authentication server according to the first authentication request; The second device forwards the authentication information to the first device; receiving first authentication information sent by the first device, wherein the first authentication information is authentication information of the first function on the first device stored by the first device; determining whether the first authentication information and second authentication information are the same, where the second authentication information is authentication information of the first function on the first device stored by the second device; The second device sends a verification result to the first device, where the verification result is used to indicate whether the second authentication information is the same as the first authentication information.
16. The method according to claim 15, characterized in that Before the second device receives the first authentication information sent by the first device, the method further includes: The second device receives the verification assistance request sent by the first device; In response to the assisted verification request, the second device sends an assisted verification response to the first device, indicating agreement to the assisted verification.
17. The method according to claim 15, characterized in that Before the second device receives the first authentication information sent by the first device, the method includes: The second device receives authentication information of the first function on the first device sent by the first device; The second device stores the authentication information.
18. The method according to claim 16, characterized in that After the second device receives the authentication information of the first function sent by the authentication server according to the first authentication request, the method further includes: The second device stores the authentication information.
19. A device authentication system, characterized in that: include: a first device, at least one assisting verification device; The first device is used for: Upon detecting a call request for a first function on the first device, sending first authentication information to the at least one assisting authentication device, wherein both the first device and the at least one assisting authentication device store the authentication information of the first function on the first device, and the first authentication information is the authentication information of the first function stored by the first device; receiving a verification result from the at least one assisting verification device, wherein the verification result received from any assisting verification device is used to indicate whether the first authentication information is the same as the authentication information stored by the assisting verification device; When it is determined that the first authentication information is not credible based on the verification result received from the at least one assisting verification device, obtaining authentication information of the first function on the first device from an authentication server, and controlling execution of the first function based on the authentication result in the authentication information obtained from the authentication server, wherein the authentication result indicates whether the first device is allowed to execute the first function; Any one of the at least one authentication assisting device is configured to: Receive the first authentication information sent by the first device, and send the verification result to the first device.
20. The device authentication system according to claim 19, wherein: The authentication server is also included, and the authentication server is used to authenticate the first function on the first device.
21. An electronic device, characterized in that: include: One or more processors, one or more memories; the one or more memories are respectively coupled to the one or more processors; the one or more memories are used to store computer program code, and the computer program code includes computer instructions; when the computer instructions are executed on the processor, the electronic device executes the method according to any one of claims 1-14 or 15-18.
22. A computer-readable medium for storing one or more programs, wherein the one or more programs are configured to be executed by the one or more processors, the one or more programs comprising instructions for executing the method according to any one of claims 1-14 or 15-18.
Citation Information
Patent Citations
Method for implementing network access authentication
CN1703004A