Network access authentication method, image reading device and terminal device
The described method generates authentication information from a displayed image to securely encrypt and decrypt configuration information, addressing the cumbersome and insecure nature of existing camera network access methods, thereby enhancing security and convenience.
Patent Information
- Application Number
- CN202210857227.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-20
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-07-20
AI Technical Summary
The existing camera network access method is cumbersome and has security risks, especially the broadcast/multicast method that discloses privacy information and malfunctions.
The terminal device displays the authentication image and generates the corresponding authentication information, and the image reading device scans and obtains the authentication information. The terminal device encrypts the configuration information and sends it. The image reading device decrypts the configuration information and obtains the configuration information and performs network configuration and identity authentication.
It improves the security and convenience of authentication information transmission, reduces operational links, and enhances the convenience and security of access to the network.
Smart Images

Figure CN115297472B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of Internet technologies, and in particular, to a network access authentication method, an image reading device, and a terminal device. Background Art
[0002] As a video image acquisition device, a camera has a great demand for network transmission, sharing, and storage of video images. Therefore, the network access function is very important for the camera. Currently, there are various ways to achieve the wireless network access of the camera, but these ways have certain problems in terms of access operations, security, etc., and there is still room for optimization and improvement. For example, Method 1: The network camera turns on the AP mode to create a wireless hotspot; the mobile phone connects to the hotspot and sends target configuration information (SSID / PASSWORD) and credential information (TOKEN) to be bound through the network. After receiving the complete information, the network camera disconnects the wifi hotspot, switches to the station mode, and connects to the router with the specified SSID and PASSWORD. After the mobile phone disconnects the original hotspot, it connects to the same router and transmits the TOKEN through the network for the device to authenticate and bind to the specified server. Method 2: The mobile phone connects to the router and broadcasts SSID / PASSWORD / TOKEN on the wifi channel through broadcast / multicast. The network camera scans and switches channels, locks the channel and receives the complete information after discovering the relevant information. Subsequently, after connecting to the router with the specified SSID and PASSWORD, it uses the TOKEN to authenticate and bind to the specified server. Among them, the disadvantage of Method 1 is that the operation is cumbersome and the user needs to switch the network connection method of the mobile phone. The disadvantage of Method 2 is that there are certain security risks. The broadcast / multicast method will disclose privacy information such as PASSWORD / TOKEN, and there is a risk that the device may be misconfigured when multiple people operate simultaneously.
[0003] Regarding the problems of cumbersome operation and security risks in the camera accessing the network in the related art, no effective solution has been proposed yet. Summary of the Invention
[0004] In this embodiment, a network access authentication method, an image reading device, and a terminal device are provided to solve the problems of cumbersome operation and security risks in the camera accessing the network in the related art.
[0005] In a first aspect, in this embodiment, a network access authentication method for an image reading device is provided, and the method includes:
[0006] Generating corresponding authentication information based on an authentication image displayed by a terminal device, where the authentication image is generated by the terminal device based on its corresponding account information; and
[0007] Receive the encrypted information sent by the terminal device, where the encrypted information is generated by the terminal device encrypting the configuration information of the target access device based on the authentication information;
[0008] Based on the authentication information, decrypt the encrypted information to obtain the configuration information;
[0009] Perform network configuration based on the configuration information and perform identity authentication based on the authentication information.
[0010] In some embodiments, the generating corresponding authentication information based on the authentication image displayed by the terminal device includes:
[0011] Scan and obtain the authentication image displayed by the terminal device;
[0012] Convert the authentication image into corresponding authentication information based on the conversion rule.
[0013] In some embodiments, the receiving the encrypted information sent by the terminal device includes:
[0014] Scan the wireless communication channel and receive the broadcast packet sent by the terminal device;
[0015] Extract the encrypted information in the broadcast packet.
[0016] In some embodiments, the performing identity authentication based on the authentication information includes:
[0017] Send the authentication information to the cloud server based on the network;
[0018] When the account information obtained based on the authentication information is consistent with the account information in the cloud server, receive the authentication passed instruction sent by the cloud server to complete the identity authentication.
[0019] In a second aspect, in this embodiment, a network access authentication method for a terminal device is provided, and the method includes:
[0020] Obtain the authentication information corresponding to the account information, and generate and display an authentication image based on the authentication information;
[0021] Obtain the configuration information of the target access device, and encrypt the configuration information based on the authentication information to generate encrypted information;
[0022] Send the encrypted information to an image reading device that generates authentication information based on the authentication image and decrypts the encrypted information based on the authentication information.
[0023] In some embodiments, the generating and displaying an authentication image based on the authentication information includes:
[0024] Convert the authentication information into a corresponding authentication image based on the conversion rule;
[0025] Display the authentication image.
[0026] In some embodiments, the image reading device that sends the encrypted information to generate authentication information based on the authentication image and decrypts the encrypted information based on the authentication information includes:
[0027] Generate a broadcast packet based on the encrypted information;
[0028] Broadcast the broadcast packet in a wireless communication channel.
[0029] In some embodiments, the obtaining the authentication information corresponding to the account information includes:
[0030] Send the account information to a cloud server based on the network;
[0031] Receive the authentication information sent by the cloud server, where the authentication information is generated by the cloud server based on the account information.
[0032] In a third aspect, an image reading device is provided in this embodiment, including:
[0033] A generation module, configured to generate corresponding authentication information based on an authentication image displayed by a terminal device, where the authentication image is generated by the terminal device based on its corresponding account information; and
[0034] A receiving module, configured to receive encrypted information sent by the terminal device, where the encrypted information is generated by the terminal device based on the authentication information to encrypt configuration information of a target access device;
[0035] A decryption module, configured to decrypt the encrypted information based on the authentication information to obtain the configuration information;
[0036] An authentication module, configured to perform network configuration based on the configuration information and perform identity authentication based on the authentication information.
[0037] In a fourth aspect, a terminal device is provided in this embodiment, including:
[0038] A display module, configured to obtain authentication information corresponding to account information, and generate and display an authentication image based on the authentication information;
[0039] An encryption module, configured to obtain configuration information of a target access device, and encrypt the configuration information based on the authentication information to generate encrypted information;
[0040] A sending module, configured to send the encrypted information to an image reading device that generates authentication information based on the authentication image and decrypts the encrypted information based on the authentication information.
[0041] Compared with the related art, in the network access authentication method for an image reading device provided in this embodiment, the corresponding authentication information is generated through the authentication image displayed by the terminal device, without the need for the terminal device to broadcast and send it, nor to establish a network connection with the terminal device through a hotspot to obtain the authentication information, enhancing the security and convenience of the transmission of the authentication information; by receiving the encrypted information sent by the terminal device, the configuration information of the target access device after encryption is obtained, and other devices cannot decrypt it due to the lack of authentication information, improving the security of the transmission of the configuration information; the encrypted information is decrypted through the authentication information to obtain the configuration information, and network configuration is performed based on the configuration information, and identity authentication is performed based on the authentication information, reducing the operation links for the image reading device to access the network, enhancing the convenience and efficiency of access, and improving the security of access and authentication.
[0042] Details of one or more embodiments of this application are set forth in the following drawings and description to make other features, objects, and advantages of this application more concise and understandable. Description of the Drawings
[0043] The drawings described herein are used to provide a further understanding of this application, and constitute a part of this application. The illustrative embodiments and descriptions thereof of this application are used to explain this application and do not constitute an improper limitation of this application. In the drawings:
[0044] Figure 1 is a schematic diagram of the application environment of the network access authentication method according to an embodiment of this application;
[0045] Figure 2 is a flowchart of the network access authentication method for an image reading device according to an embodiment of this application;
[0046] Figure 3 is a flowchart of the network access authentication method for a terminal device according to an embodiment of this application;
[0047] Figure 4 is a flowchart of the network access authentication method according to a preferred embodiment of this application;
[0048] Figure 5 is a block diagram of the structure of an image reading device according to an embodiment of this application;
[0049] Figure 6 is a block diagram of the structure of a terminal device according to an embodiment of this application. Detailed Embodiments
[0050] To understand the purpose, technical solution and advantages of the present application more clearly, the present application will be described and explained below in conjunction with the drawings and embodiments.
[0051] Unless otherwise defined, the technical terms or scientific terms involved in the present application shall have the general meaning understood by those with ordinary skills in the technical field to which the present application belongs. In the present application, words such as "a", "an", "one kind", "the", "these", etc. do not indicate a limitation in quantity, and they can be singular or plural. The terms "including", "comprising", "having" and any variants thereof involved in the present application are intended to cover non-exclusive inclusion; for example, a process, method, system, product or device including a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent in these processes, methods, products or devices. The words "connected", "coupled", etc. involved in the present application do not limit to physical or mechanical connections, but may include electrical connections, whether directly or indirectly. The "plurality" involved in the present application means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, and B exists alone. Usually, the character " / " indicates that the associated objects before and after are in an "or" relationship. The terms "first", "second", "third", etc. involved in the present application are only used to distinguish similar objects and do not represent a specific order for the objects.
[0052] The method embodiment provided in this embodiment can be applied to an image reading device, specifically, it can be executed in the main control unit of the image reading device. The image reading device can be a device with an image reading function such as a network camera or an image scanner. The main control unit can be the processor unit of the image reading device. The main control unit can include one or more processors and a memory for storing data. Among them, the processor can include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA. The main control unit can also include a transmission device and an input / output device for communication functions, and can communicate with a remote server through a network, and perform data processing and storage through the remote server.
[0053] The memory can be used to store computer programs, such as software programs and modules of application software, such as the computer program corresponding to the network access authentication method in this embodiment. The processor executes various functional applications and data processing by running the computer program stored in the memory, that is, the above method is implemented. The memory can include high-speed random access memory, and can also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some embodiments, the memory can further include a memory remotely set relative to the processor, and these remote memories can be connected to the image reading device through a network. Examples of the above network include but are not limited to the Internet, intranet, local area network, mobile communication network, and combinations thereof.
[0054] The transmission device is used to receive or send data via a network. The above network includes the wireless network provided by the communication provider of the image reading device. In one example, the transmission device includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one example, the transmission device can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0055] Figure 1 It is a schematic diagram of the application environment of the network access authentication method in this embodiment. As Figure 1 shown, the network access authentication method in this embodiment can be applied to the image reading device 11. The access device 13 to which the image reading device 11 is to be connected is connected to the Internet. The access device 13 can be a network access device such as a switch or a router. The terminal device 12 is communicatively connected to the access device 13 through a wireless network. The terminal device 12 can be an interactive terminal such as a mobile phone, PDA, PC, laptop, PAD, etc. with control display and wireless communication functions. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic, and it does not limit various types of devices in the application environment of the above network access authentication method. The application environment may also include more or fewer components than those Figure 1 shown, or have a different configuration from that Figure 1 shown. For example, there can be multiple access devices 13, and the image reading device 11 can select one of the access devices 13 as the target access device. In the local area network of the same access device 13, there can also be multiple image reading devices 11 and multiple terminal devices 12, and each image reading device 11 can access the network through the corresponding terminal device 12.
[0056] In this embodiment, a network access authentication method is provided.Figure 2 is a flowchart of the network access authentication method for an image reading device according to this embodiment. As Figure 2 shown, this process includes the following steps:
[0057] Step S201: Generate corresponding authentication information based on the authentication image displayed on the terminal device. This authentication image is generated by the terminal device based on its corresponding account information.
[0058] Step S202: Receive the encrypted information sent by the terminal device. This encrypted information is generated by the terminal device by encrypting the configuration information of the target access device based on the authentication information.
[0059] Step S203: Decrypt the encrypted information based on the authentication information to obtain the configuration information.
[0060] Step S204: Perform network configuration based on the configuration information and perform identity authentication based on the authentication information.
[0061] Before accessing the network, the target access device to which the image reading device is to be connected has been determined, and the terminal device has already established a communication connection with the target access device. For a device with a wireless network access function, it can access the network by obtaining the configuration information of the target access device. This configuration information can be the SSID and password of the target access device. Among them, the SSID is the identity identifier of the access device, and the password is the credential for establishing a communication connection with the access device. After obtaining the configuration information and accessing the network, in order to further ensure the security of the network and data transmission, the identity of the image reading device can also be confirmed through the authentication information. The authentication information can be a token information generated based on the user account information corresponding to the image reading device. This token information is generated by the authentication server; the authentication information can also be other information that can prove the identity of the image reading device.
[0062] In this embodiment, the terminal device generates an authentication image based on the corresponding account information and displays it. The account information can be the identity information pre-stored on the terminal device, or the registered account information in the application installed on the terminal device, etc. The terminal device can send this account information to the authentication server and obtain the corresponding authentication information, and convert the authentication information into an authentication image based on the conversion rule. The image reading device obtains this authentication image and generates the corresponding authentication information.
[0063] The terminal device also encrypts the configuration information of the target access device based on the authentication information. For example, the authentication information is used as a key to encrypt the configuration information, and the encrypted information is obtained and sent to the image reading device. The configuration information can be pre-stored on the terminal device or pre-entered in the application installed on the terminal device. The encryption can be performed based on existing encryption algorithms, and this embodiment does not limit the encryption algorithm. The order of step S201 and step S202 can be swapped.
[0064] After receiving the encrypted information, the image reading device decrypts the encrypted information based on the authentication information to obtain the configuration information, and accesses the network according to the configuration information. After accessing, the authentication information is sent to the authentication server through the target access device for identity authentication.
[0065] The network access authentication method for the image reading device provided in this embodiment generates corresponding authentication information through the authentication image displayed by the terminal device, without the need for the terminal device to broadcast and send it, nor to establish a network connection with the terminal device through a hotspot to obtain the authentication information, which enhances the security and convenience of the transmission of the authentication information; by receiving the encrypted information sent by the terminal device, the encrypted configuration information of the target access device is obtained, and other devices cannot decrypt it due to the lack of authentication information after obtaining it, which improves the security of the transmission of the configuration information; by decrypting the encrypted information with the authentication information, the configuration information is obtained, and network configuration is performed based on the configuration information, and identity authentication is performed based on the authentication information, which reduces the operation links for the image reading device to access the network, enhances the convenience and efficiency of access, and improves the security of access and authentication.
[0066] In some of these embodiments, it also involves the specific process of generating corresponding authentication information based on the authentication image. This process includes the following steps:
[0067] Step S11, scanning to obtain the authentication image displayed by the terminal device;
[0068] Step S12, converting the authentication image into corresponding authentication information based on the conversion rule.
[0069] The image reading device scans the authentication image displayed by the terminal device through the lens. The authentication image can be the authentication information encoded and displayed in the form of a two-dimensional code or a bar code, etc. After obtaining the authentication image, the authentication image is converted into authentication information based on the conversion rule. The conversion rule can include the encoding rule and the reverse decoding rule between the two-dimensional code image and the string information. According to the conversion rule, the authentication image and the authentication information can be converted into each other. The authentication information is used to identify the identity of the image reading device and can be obtained by the terminal device from the authentication server based on the account information.
[0070] The network access authentication method for an image reading device provided in this embodiment scans to obtain the authentication image displayed on the terminal device, converts the authentication image into corresponding authentication information based on a conversion rule, and obtains the identity authentication credential of the image reading device by scanning the image, without the need for the terminal device to broadcast and send it, nor to establish a network connection with the terminal device through a hotspot to obtain the authentication information, enhancing the security and convenience of the transmission of authentication information.
[0071] In some of these embodiments, it involves the specific process of receiving the encrypted information sent by the terminal device. This process includes the following steps:
[0072] Step S21, scan the wireless communication channel and receive the broadcast packet sent by the terminal device;
[0073] Step S22, extract the encrypted information from the broadcast packet.
[0074] Before accessing the network, the image reading device can obtain the broadcast / multicast packet sent by the terminal device by receiving broadcast or multicast information. If there are multiple terminal devices in a local area network, multiple broadcast / multicast packets can be received. After the terminal device enables the broadcast function, it can send the encrypted configuration information through the UDP broadcast / multicast packet. The image reading device receives the broadcast packet by scanning the wireless communication channel, and the scanned channel can be the channel list pre-saved in the image reading device. After receiving it, the encrypted information in the broadcast packet is extracted according to the data format of the UDP protocol. When the image reading device receives multiple broadcast packets, the broadcast packets are decrypted using the authentication information. If the decryption is correct, the corresponding configuration information is obtained. If the decryption is incorrect, it means that the broadcast packet is not sent by the corresponding terminal device and the data is invalid.
[0075] The network access authentication method for an image reading device provided in this embodiment scans the channel to receive the broadcast packet and extracts the encrypted information in the broadcast packet. Even if other devices receive the broadcast packet and obtain the encrypted information, they cannot decrypt and obtain the configuration information due to the lack of authentication information, improving the security of the transmission of the configuration information. The broadcast method is simple and fast, improving the transmission efficiency of the configuration information.
[0076] In some of these embodiments, it involves the specific process of performing identity authentication based on the authentication information. This process includes the following steps:
[0077] Step S31, send the authentication information to the cloud server based on the network;
[0078] Step S32, when the account information obtained based on the authentication information is consistent with the account information in the cloud server, receive the authentication passed instruction sent by the cloud server to complete the identity authentication.
[0079] After the image reading device accesses the network through the configuration information, it establishes a wireless connection with the target access device. The authentication information is sent to the cloud server through the target access device. The cloud server can be an authentication server for network access or a cloud server corresponding to a specific application of the terminal device. The authentication information can be token information (Token) generated based on the account information corresponding to the terminal device.
[0080] Before obtaining the authentication information, the terminal device can send the account information to the cloud server. In this process, the cloud server stores the account information, and sends the token information generated based on the account information to the terminal device, binding the account information with the token information. The terminal device converts the token information into an authentication image according to the conversion rule, and the image reading device converts the authentication image back into token information again. Therefore, when the image reading device sends the token information to the cloud server, the cloud server compares the account information corresponding to the token information with the stored account information. If the account information is consistent, it determines that the authentication is passed and sends an authentication passed instruction to the image reading device.
[0081] The network access authentication method for the image reading device provided in this embodiment sends authentication information to the cloud server by accessing the network, binds the account information corresponding to the image reading device with the authentication information through the cloud server, compares the account information associated with the authentication information with the account information sent by the terminal device, and determines that the authentication is passed when they are consistent. It can achieve identity authentication without additional information transmission, improving the authentication efficiency. The authentication information is generated by the cloud server based on the account information and can only be recognized by the cloud server, improving the security of identity authentication.
[0082] This embodiment also provides a network access authentication method for the terminal device, which can be specifically executed in the processor unit of the terminal device. The processor unit can include one or more processors and a memory for storing data. Among them, the processor can include, but is not limited to, processing devices such as a microprocessor MCU or a field programmable gate array FPGA. The processor unit can also include a transmission device and an input / output device for communication functions, and can communicate with a remote server through the network, and perform data processing and storage through the remote server.
[0083] The memory can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the network access authentication method in this embodiment. The processor executes various functional applications and data processing by running the computer program stored in the memory, that is, the above method is implemented. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some embodiments, the memory may further include a memory remotely provided with respect to the processor, and these remote memories can be connected to the image reading device through a network. Examples of the above network include but are not limited to the Internet, intranet, local area network, mobile communication network, and combinations thereof.
[0084] The transmission device is used to receive or send data via a network. The above network includes the wireless network provided by the communication provider of the image reading device. In one example, the transmission device includes a network adapter (abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one example, the transmission device can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0085] In this embodiment, a network access authentication method for a terminal device is provided. Figure 3 It is the flowchart of the network access authentication method for the terminal device in this embodiment, as Figure 3 shown, and the process includes the following steps:
[0086] Step S301, obtain the authentication information corresponding to the account information, and generate and display an authentication image based on the authentication information;
[0087] Step S302, obtain the configuration information of the target access device, and encrypt the configuration information based on the authentication information to generate encrypted information;
[0088] Step S303, send the encrypted information to the image reading device that generates authentication information based on the authentication image and decrypts the encrypted information based on the authentication information.
[0089] Before accessing the network, the target access device to which the image reading device is to be accessed has been determined, and the terminal device has established a communication connection with the target access device. The terminal device can obtain the account information through the installed application program, and obtain the authentication information based on the account information. The obtaining method can be to send the account information to the cloud server and receive the authentication information sent by the cloud server. Convert the authentication information into an authentication image based on the conversion rule. The authentication image can be a two-dimensional code or a barcode, etc. The conversion rule can be the encoding rule of the two-dimensional code.
[0090] The terminal device can also obtain the configuration information of the target access device through the installed application, including the SSID and password of the target access device. This configuration information can be pre-entered into the application and can be modified. Based on the authentication information, the configuration information is encrypted to generate encrypted information and sent to the image reading device. The encryption algorithm is not limited in this embodiment.
[0091] The network access authentication method for the terminal device provided in this embodiment obtains the authentication information corresponding to the account information, generates and displays an authentication image based on the authentication information, does not require the broadcast method, nor does it need to establish a network connection with the image reading device through a hotspot to send the authentication information, enhancing the security and convenience of the authentication information transmission; encrypts the configuration information with the authentication information to generate encrypted information and sends it to the image reading device. Other devices cannot decrypt it due to the lack of authentication information after obtaining it, improving the security of the configuration information transmission, reducing the operation steps for the image reading device to access the network, enhancing the convenience and efficiency of access, and improving the security of access and authentication.
[0092] In some of these embodiments, it involves the specific process of generating and displaying an authentication image based on the authentication information. This process includes the following steps:
[0093] Step S41, convert the authentication information into a corresponding authentication image based on the conversion rule;
[0094] Step S42, display the authentication image.
[0095] The conversion rule is pre-set and can include the encoding rule and the reverse decoding rule between the QR code image and the string information. The authentication image and the authentication information can be converted into each other according to the conversion rule. The authentication image is displayed on the display screen of the terminal device.
[0096] The network access authentication method for the terminal device provided in this embodiment converts the authentication information into a corresponding authentication image and displays it based on the pre-set conversion rule, without the need to send it through the broadcast method or establish a network connection with the image reading device through a hotspot to send the authentication information, enhancing the security and convenience of the authentication information transmission.
[0097] In some of these embodiments, it involves the specific process of sending the encrypted information to the image reading device. This process includes the following steps:
[0098] Step S51, generate a broadcast packet based on the encrypted information;
[0099] Step S52, broadcast the broadcast packet in the wireless communication channel.
[0100] The terminal device can encapsulate the encrypted information in a broadcast packet based on the data format of the UDP protocol and send it externally, enabling the image reading device to receive the broadcast packet. Moreover, even if other devices receive the broadcast packet and obtain the encrypted information, they cannot decrypt and obtain the configuration information due to the lack of authentication information, which improves the security of the transmission of the configuration information. The broadcast method is simple and fast, which improves the transmission efficiency of the configuration information.
[0101] In some of these embodiments, a specific process for obtaining the authentication information corresponding to the account information is involved. This process includes the following steps:
[0102] Step S61, sending the account information to the cloud server based on the network;
[0103] Step S62, receiving the authentication information sent by the cloud server, where the authentication information is generated by the cloud server based on the account information.
[0104] The terminal device can obtain the authentication information through the cloud server. After sending the account information to the cloud server, the cloud server stores the account information and sends the authentication information generated based on the account information to the terminal device, binding the account information with the authentication information. Therefore, when the image reading device sends the token information to the cloud server, the cloud server compares the account information corresponding to the token information with the stored account information. If the account information is consistent, it determines that the authentication is passed and sends an authentication passed instruction to the image reading device.
[0105] The network access authentication method for the terminal device provided in this embodiment generates the authentication information corresponding to the account information through the cloud server and binds the account information and the authentication information in the cloud server. Identity authentication can be achieved without additional information transmission, which improves the authentication efficiency. The authentication information is generated by the cloud server based on the account information and can only be recognized by the cloud server, which improves the security of identity authentication.
[0106] The following describes and illustrates this embodiment through preferred embodiments.
[0107] The network access authentication method of this preferred embodiment is applied to the image reading device and the terminal device. Among them, the image reading device is a network camera, and the terminal device is a mobile phone. The network access authentication method applied to the terminal device in this preferred embodiment is executed through the application APP on the mobile phone. Figure 4 It is the flowchart of the network access authentication method of this preferred embodiment. As Figure 4 shown, this process includes the following steps:
[0108] S401, the mobile phone APP sends the account information to the cloud server through the network;
[0109] S402, the mobile phone APP receives the token information sent by the cloud server;
[0110] S403, the mobile phone APP designates the target access device and obtains the corresponding SSID and password;
[0111] Steps S401 - S402 and S403 can be swapped in order.
[0112] S404, the mobile phone APP uses the token information as the key to encrypt the SSID and password;
[0113] S405, the mobile phone APP encodes the token information into a QR code and displays it on the screen;
[0114] S406, the mobile phone APP sends the encrypted SSID and password information through the network broadcast packet / multicast packet;
[0115] Steps S405 and S406 can be swapped in order.
[0116] S407, the network camera obtains the token information by scanning the mobile phone screen through the lens;
[0117] S408, the network camera receives the encrypted SSID and password in the network broadcast packet / multicast packet;
[0118] Steps S407 and S408 can be swapped in order.
[0119] S409, the network camera uses the token information to decrypt the encrypted SSID and password;
[0120] S410, the network camera uses the SSID and password to complete network access and completes identity authentication through the token information.
[0121] Through the above steps S401 to S410, the mobile phone APP generates the corresponding token information based on the account information through the cloud server, and uses the token information as the key to encrypt the SSID and password, improving the security of the configuration information transmission; the mobile phone APP encodes the token information into a QR code for display, the network camera scans the QR code through the lens to obtain it, and generates the corresponding authentication information, without the need to obtain the authentication information by broadcast or establishing a hotspot network, enhancing the security and convenience of the authentication information transmission; the network camera obtains the encrypted configuration information through the network broadcast packet / multicast packet, and other devices cannot decrypt it due to the lack of authentication information after obtaining it, improving the security of the configuration information transmission; the network camera decrypts the encrypted information through the authentication information, obtains the configuration information, and performs network configuration based on the configuration information and identity authentication based on the authentication information, reducing the operation links for the camera to access the network, enhancing the convenience and efficiency of access, and improving the security of access and authentication.
[0122] It should be noted that the steps shown in the above process or the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0123] In some embodiments, the present application also provides an image reading device, which is used to implement the corresponding embodiments and preferred implementation manners of the network access authentication method for the image reading device. Those that have been described will not be repeated here. The following terms such as "module", "unit", "sub-unit", etc. can be a combination of software and / or hardware that can achieve a predetermined function.
[0124] In some embodiments, Figure 5 is the structural block diagram of the image reading device in this embodiment, as Figure 5 shown, the image reading device includes:
[0125] A generation module 51, configured to generate corresponding authentication information based on the authentication image displayed by the terminal device, where the authentication image is generated by the terminal device based on its corresponding account information; and
[0126] A receiving module 52, configured to receive the encrypted information sent by the terminal device, where the encrypted information is generated by the terminal device encrypting the configuration information of the target access device based on the authentication information;
[0127] A decryption module 53, configured to decrypt the encrypted information based on the authentication information to obtain the configuration information;
[0128] An authentication module 54, configured to perform network configuration based on the configuration information and perform identity authentication based on the authentication information.
[0129] In the image reading device of this embodiment, the generation module 51 generates corresponding authentication information based on the authentication image displayed by the terminal device, without the need for the terminal device to broadcast and send it, nor to establish a network connection with the terminal device through a hotspot to obtain the authentication information, enhancing the security and convenience of the transmission of the authentication information; the receiving module 52 receives the encrypted information sent by the terminal device to obtain the encrypted configuration information of the target access device, and other devices cannot decrypt it due to the lack of authentication information after obtaining it, improving the security of the transmission of the configuration information; the decryption module 53 decrypts the encrypted information based on the authentication information to obtain the configuration information, and the authentication module 54 performs network configuration based on the configuration information and performs identity authentication based on the authentication information, reducing the operation links for the image reading device to access the network, enhancing the convenience and efficiency of access, and improving the security of access and authentication.
[0130] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation manners, and will not be elaborated herein.
[0131] In some embodiments, the present application also provides a terminal device, which is used to implement the corresponding embodiments and preferred implementation manners of the network access authentication method for the terminal device. Those that have been described will not be elaborated again. The following terms such as "module", "unit", "sub-unit", etc. can be a combination of software and / or hardware that can achieve a predetermined function.
[0132] In some embodiments, Figure 6 is the structural block diagram of the terminal device in this embodiment, as Figure 6 shown, the terminal device includes:
[0133] A display module 61, configured to obtain authentication information corresponding to account information, and generate and display an authentication image based on the authentication information;
[0134] An encryption module 62, configured to obtain configuration information of a target access device, and encrypt the configuration information based on the authentication information to generate encrypted information;
[0135] A sending module 63, configured to send the encrypted information to an image reading device that generates authentication information based on the authentication image and decrypts the encrypted information based on the authentication information.
[0136] The terminal device in this embodiment obtains authentication information corresponding to account information through the display module 61, generates and displays an authentication image based on the authentication information, does not need to establish a network connection with the image reading device through a broadcast method or a hotspot to send the authentication information, enhancing the security and convenience of the transmission of the authentication information; the encryption module 62 encrypts the configuration information based on the authentication information to generate encrypted information and sends it to the image reading device through the sending module 63. Other devices cannot decrypt it due to the lack of authentication information, improving the security of the transmission of the configuration information, reducing the operation steps for the image reading device to access the network, enhancing the convenience and efficiency of access, and improving the security of access and authentication.
[0137] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation manners, and will not be elaborated herein.
[0138] It should be understood that the specific embodiments described herein are only used to explain this application, rather than to limit it. According to the embodiments provided by the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0139] Obviously, the accompanying drawings are only some examples or embodiments of the present application. For those of ordinary skill in the art, the present application can also be applied to other similar situations based on these drawings without creative labor. Additionally, it can be understood that although the work done during this development process may be complex and time-consuming, for those of ordinary skill in the art, certain design, manufacturing, or production changes based on the technical content disclosed in the present application are only conventional technical means and should not be regarded as insufficient disclosure of the present application.
[0140] The term "embodiment" in this application means that the specific features, structures, or characteristics described in connection with the embodiments may be included in at least one embodiment of the present application. The phrase appears in various positions in the specification and does not necessarily mean the same embodiment, nor does it mean being independent or alternative to other embodiments and mutually exclusive. Those of ordinary skill in the art can clearly or implicitly understand that the embodiments described in this application can be combined with other embodiments without conflict.
[0141] The above-described embodiments merely represent several implementation manners of the present application. Their descriptions are relatively specific and detailed, but should not be construed as limiting the scope of patent protection. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several variations and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A network access authentication method for an image reading device, characterized in that, The method includes: Generating corresponding authentication information based on an authentication image displayed by a terminal device, where the authentication image is generated by the terminal device based on its corresponding account information; wherein, the authentication information is token information generated by a cloud server based on the account information, the terminal device converts the token information into the authentication image according to a conversion rule, and an image reading device converts the authentication image back into token information again; the account information is registration account information in an application installed on the terminal device; and Receiving encrypted information sent by the terminal device, where the encrypted information is generated by the terminal device encrypting configuration information of a target access device based on the authentication information; Decrypting the encrypted information based on the authentication information to obtain the configuration information; Performing network configuration based on the configuration information and performing identity authentication based on the authentication information.
2. The method according to claim 1, wherein The generating corresponding authentication information based on an authentication image displayed by a terminal device includes: Scanning and acquiring the authentication image displayed by the terminal device; Converting the authentication image into corresponding authentication information based on a conversion rule.
3. The method according to claim 1, wherein The receiving encrypted information sent by the terminal device includes: Scanning a wireless communication channel and receiving a broadcast packet sent by the terminal device; Extracting the encrypted information in the broadcast packet.
4. The method according to claim 1, wherein The performing identity authentication based on the authentication information includes: Sending the authentication information to the cloud server based on the network; Receiving an authentication passed instruction sent by the cloud server when the account information obtained based on the authentication information is consistent with the account information in the cloud server, and completing identity authentication.
5. A network access authentication method for a terminal device, characterized in that, The method includes: Obtaining authentication information corresponding to account information, and generating and displaying an authentication image based on the authentication information; wherein, the authentication information is token information generated by a cloud server based on the account information, the terminal device converts the token information into the authentication image according to a conversion rule, and an image reading device converts the authentication image back into token information again; the account information is registration account information in an application installed on the terminal device; Obtaining configuration information of a target access device, and encrypting the configuration information based on the authentication information to generate encrypted information; Sending the encrypted information to an image reading device that generates authentication information based on the authentication image and decrypts the encrypted information based on the authentication information.
6. The method according to claim 5, wherein The generating and displaying an authentication image based on the authentication information includes: Converting the authentication information into a corresponding authentication image based on a conversion rule; Displaying the authentication image.
7. The method according to claim 5, characterized in that The sending the encrypted information to an image reading device that generates authentication information based on the authentication image and decrypts the encrypted information based on the authentication information includes: Generating a broadcast packet based on the encrypted information; Broadcasting the broadcast packet in a wireless communication channel.
8. The method according to claim 5, characterized in that, The obtaining authentication information corresponding to account information includes: Sending the account information to the cloud server based on the network; Receiving the authentication information sent by the cloud server, where the authentication information is generated by the cloud server based on the account information.
9. An image reading device, characterized in that, Includes: A generation module, configured to generate corresponding authentication information based on an authentication image displayed by a terminal device, where the authentication image is generated by the terminal device based on its corresponding account information; wherein, the authentication information is token information generated by a cloud server based on the account information, the terminal device converts the token information into the authentication image according to a conversion rule, and an image reading device converts the authentication image back into token information again; the account information is registration account information in an application installed on the terminal device; and A receiving module, configured to receive encrypted information sent by the terminal device, where the encrypted information is generated by the terminal device encrypting configuration information of a target access device based on the authentication information; A decryption module, configured to decrypt the encrypted information based on the authentication information to obtain the configuration information; An authentication module, configured to perform network configuration based on the configuration information and perform identity authentication based on the authentication information.
10. A terminal device, characterized in that, including; A display module, configured to obtain authentication information corresponding to account information, generate an authentication image based on the authentication information and display it; wherein, the authentication information is token information generated by a cloud server based on the account information, the terminal device converts the token information into the authentication image according to a conversion rule, and an image reading device converts the authentication image back into token information again; the account information is registration account information in an application installed on the terminal device; An encryption module, configured to obtain configuration information of a target access device and encrypt the configuration information based on the authentication information to generate encrypted information; A sending module, configured to send the encrypted information to an image reading device that generates authentication information based on the authentication image and decrypts the encrypted information based on the authentication information.
Citation Information
Patent Citations
Method for fast configuring remote video monitoring system
CN103414881A
Network security control method
CN111726801A