Beacon-based third-party proxy authentication method and system

Through the third-party proxy authentication solution based on Beacon, the problem of the controlled equipment in the prior art that the distribution network needs to be connected to the cloud for authentication is solved, and the secure authentication and key issuance without the need for network access hardware and distribution network operations is realized, reducing costs and operational complexity and improving user experience.

CN115314894BActive Publication Date: 2025-05-23HANGZHOU TUYA INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210937503.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-05
Publication Date
2025-05-23
Estimated Expiration
2042-08-05

AI Technical Summary

Technical Problem

In the prior art, in order to ensure the security of the controlled equipment, it is necessary to authenticate the control equipment through the distribution network, resulting in increased equipment costs and complex user operations, which affects the user experience.

Method used

The third-party proxy authentication scheme based on Beacon is adopted, and the authentication request and result transmission is carried out through the Beacon broadcast packet. The third-party device (such as a mobile APP) is used as the proxy authentication device to complete the identity authentication and issuance of the control device, avoiding the control device's need to have network access hardware modules and network distribution operations.

Benefits of technology

It reduces the hardware cost of the controlled device, simplifies user operation steps, improves the user experience, and realizes safe and convenient data interaction between the controlled device and the controlled device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115314894B_ABST
    Figure CN115314894B_ABST
Patent Text Reader

Abstract

The present application relates to a method and system for third-party proxy authentication based on Beacon, which is applied to a controlled device, including: in response to a control instruction sent by a control device, sending a first Beacon broadcast packet to request authentication of the control device; receiving a second Beacon broadcast packet from a proxy authentication device, wherein the second Beacon broadcast packet includes an authentication result of the control device by a cloud server; and determining whether to accept control of the control device in response to the authentication result. According to the scheme of the present application, based on the characteristics of Beacon broadcast beacons, proxy authentication and authorization are performed by a third party, and there is no need to perform offline device configuration operations and access the cloud for the controlled device, which assists in the authorization and key distribution between the control device and the controlled device. Therefore, on the one hand, the controlled device does not need to have a hardware device for connecting to the cloud, reducing costs; on the other hand, there is no need to complete the configuration and cloud connection for the controlled device, simplifying the operation steps.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of intelligent device control, and in particular to a method and system for third-party proxy authentication based on Beacon. Background Art

[0002] At present, for the pairing control between two offline single-point devices, such as a control device and a controlled device, in order to ensure the security of the control process of the controlled device and avoid the risk of control by illegal terminals, the controlled device needs to connect to the cloud to authenticate the control device, verify the legitimacy of the control device identity, and obtain the key used to encrypt the transmitted data in the interaction process if the identity is legitimate to ensure the security of data transmission during the communication process.

[0003] The prerequisite for the controlled device to connect to the cloud for verification is that the controlled device has completed the network configuration link. For example, if you use a remote control to control a light bulb, you need to successfully configure the light bulb, connect to the cloud to complete the remote control identity verification and obtain the key, so that legal and secure data interaction can be achieved between the remote control and the light bulb.

[0004] However, since the authentication control device method in the prior art requires the controlled device to access the cloud through a distribution network, the controlled device must carry a hardware module with network access and must complete a series of steps to complete the network access and connect to the cloud. The entire process requires hardware facilities that can support network access, which will increase the equipment cost accordingly. The steps to complete the network configuration execution require high manual operation from the user, which is inconvenient for the user and brings a bad user experience. Summary of the invention

[0005] In order to achieve authentication of the control device while not requiring the hardware configuration of the controlled device to have a hardware module for network access, and not requiring network configuration operations to be performed on the controlled device, the present application provides a Beacon-based third-party proxy authentication solution.

[0006] According to a first aspect of the present application, a Beacon-based third-party proxy authentication method is provided, which is applied to a controlled device and includes:

[0007] In response to a control instruction sent by a control device, sending a first Beacon broadcast packet to request authentication of the control device;

[0008] receiving a second Beacon broadcast packet from the proxy authentication device, wherein the second Beacon broadcast packet includes an authentication result of the control device by the cloud server; and

[0009] In response to the authentication result, it is determined whether to accept control of the control device.

[0010] According to a second aspect of the present application, a Beacon-based third-party proxy authentication method is provided, which is applied to a proxy authentication device, including:

[0011] receiving a first Beacon broadcast packet sent by a controlled device, wherein the first Beacon broadcast packet includes a proxy authentication request for requesting authentication of the control device;

[0012] Sending the proxy authentication request to the cloud server;

[0013] receiving an authentication result from the cloud server; and

[0014] The authentication result is sent to the controlled device through a second Beacon broadcast packet.

[0015] According to a third aspect of the present application, a Beacon-based third-party proxy authentication system is provided, the system comprising a cloud server, a control device, a controlled device, and a proxy authentication device.

[0016] The control device sends a pairing instruction and a control instruction to the controlled device;

[0017] The cloud server receives the proxy authentication request from the proxy authentication device, authenticates the identity of the control device, and returns an authentication result;

[0018] The controlled device executes the method according to the first aspect; and

[0019] The proxy authentication device executes the method as described in the second aspect.

[0020] According to a fourth aspect of the present application, there is provided an electronic device, including:

[0021] A processor and a memory. The memory stores computer instructions, and when the computer instructions are executed by the processor, the processor executes the method according to the first aspect and the second aspect.

[0022] According to a fifth aspect of the present application, a non-transitory computer storage medium is provided, storing a computer program, which, when executed by multiple processors, enables the processors to execute the methods described in the first and second aspects.

[0023] According to the Beacon-based third-party proxy authentication solution of this application, based on the characteristics of Beacon broadcast beacons, proxy authentication and authorization are performed by a third party, and there is no need to perform offline device configuration operations and access the cloud for the controlled device, and assist in the authorization and key distribution between the control device and the controlled device. Therefore, on the one hand, the controlled device does not need to have cloud-connected hardware devices, such as wifi, cat1 and other modules, reducing costs; on the other hand, there is no need to complete the network configuration and cloud connection link for the controlled device, simplifying the operation steps, making the user use process simpler and more convenient, and improving the user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without exceeding the scope of protection required by the present application.

[0025] Figure 1 It is a schematic diagram of a Beacon-based third-party proxy authentication system according to an embodiment of the present application.

[0026] Figure 2 It is a flowchart of a Beacon-based third-party proxy authentication method implemented by a controlled device according to an embodiment of the present application.

[0027] Figure 3 It is a flowchart of a Beacon-based third-party proxy authentication method implemented by a proxy authentication device according to an embodiment of the present application.

[0028] Figure 4 It is a structural diagram of an electronic device provided by this application. DETAILED DESCRIPTION

[0029] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present application.

[0030] Bluetooth Beacon is a Bluetooth beacon or Bluetooth base station. It is a broadcast protocol based on the low-power Bluetooth protocol. It also refers to a low-power Bluetooth slave device that has this protocol, but Beacon does not establish a connection with any Bluetooth device. Scanners around search for the RSSI (Received Signal Strength Indicator) and broadcast packets of the Beacon to determine which MAC address of the slave device the Beacon comes from.

[0031] This application mainly uses Beacon technology to achieve identity authentication of the control device with the help of a third party (such as a mobile phone APP as an agent).

[0032] The general process of the present application scheme is as follows: when the control device initiates a control instruction to the controlled device, the controlled device sends out a proxy authentication request data packet through a Beacon broadcast packet. When a surrounding third party, such as a mobile phone APP, scans the proxy authentication request data packet, it calls the cloud interface to complete the authentication, and obtains the key for data interaction through the authentication. The third party then sends the result of the proxy authentication and the key obtained after the authentication is successful through a Beacon broadcast packet. After the controlled device monitors the result of the proxy authentication, it completes the identification and authentication of the control device's identity, and obtains the key, and can then conduct normal offline data interaction with the control device.

[0033] Figure 1 Schematic diagram of a Beacon-based third-party proxy authentication system according to an embodiment of the present application. Figure 1 As shown, the system includes a cloud server, a control device, a controlled device and an agent authentication device, wherein the control device can be any device with a control function, such as a controller, a remote control, etc., and can be a device with only a control function or a device with an integrated control function. The controlled device can be any device controlled by the controlled device to perform a corresponding function, such as a smart home device. The agent authentication device is any device that can send and receive broadcast packets through Beacon, such as a smart phone, a tablet, a smart watch and other terminals, and the agent authentication device has an application APP that supports the Beacon protocol.

[0034] like Figure 1 As shown, in the system, the cloud server, the control device, the controlled device and the proxy authentication device cooperate with each other to complete the authentication process of the control device, including:

[0035] 1. The control device sends a pairing command to perform local pairing with the controlled device.

[0036] In one embodiment, the controlling device indicates through a pairing instruction that it is trying to establish a network connection with the controlled device.

[0037] 2. The controlling device sends a control instruction to the controlled device in an attempt to control it.

[0038] According to one embodiment, the control instruction includes control device identification information, and the identification information may include one or more of a MAC address, a device ID, and a UUID (Universally Unique Identifier) ​​of the control device, for indicating the identity of the control device.

[0039] According to one embodiment, the controlling device sends a control instruction to the controlled device, indicating an attempt to control the controlled device. After receiving the control instruction, the controlled device needs to authenticate the legitimacy of the controlling device identity through the cloud server before determining whether to accept the control of the controlling device.

[0040] 3. The proxy authentication device arbitrarily controls the controlled device and sends information to the controlled device indicating that the proxy authentication device can receive Beacon broadcast packets.

[0041] In this application, the controlled device is not directly connected to the cloud server, and the legitimacy of the controlled device is not directly authenticated by the cloud server, but the authentication request is sent to the cloud server through the proxy authentication device. The controlled device sends the authentication request to the outside through the Beacon broadcast packet. Before sending the Beacon broadcast packet, it is necessary to ensure that the proxy authentication device can scan the Beacon broadcast packet.

[0042] The proxy authentication device sends information indicating that the proxy authentication device can receive Beacon broadcast packets to the controlled device, triggering the authentication condition of the controlled device. The controlled device can then send Beacon broadcast packets to request proxy authentication.

[0043] In one embodiment, the information indicating that the proxy authentication device can receive the Beacon broadcast packet may be information dedicated to indicating that the proxy authentication device can receive the Beacon broadcast packet, or may not be information dedicated to indicating that the proxy authentication device can receive the Beacon broadcast packet, and the controlled device can learn that the current proxy authentication device can receive the Beacon broadcast packet through the information. In one embodiment, the information indicating that the proxy authentication device can receive the Beacon broadcast packet is a Beacon broadcast packet having a predetermined protocol format and belonging to Bluetooth broadcast.

[0044] 4. The controlled device sends the first Beacon broadcast packet to request proxy authentication of the controlling device.

[0045] In one embodiment, the first Beacon broadcast packet includes a proxy authentication request, and the proxy authentication request contains identification information of the control device.

[0046] 5. The proxy authentication device scans the first Beacon broadcast packet of the controlled device and sends a proxy authentication request to the cloud server.

[0047] In one embodiment, the proxy authentication device has established a network connection with the cloud service, supports the Beacon protocol, and uses Bluetooth scanning to listen to Beacon broadcast packets. After receiving the first Beacon broadcast packet from the controlled device, the cloud interface is called to transmit a proxy authentication request to the cloud server.

[0048] 6. After the cloud server completes the authentication verification, the authentication result will be sent to the proxy authentication device.

[0049] In one embodiment, the cloud server authenticates the control device according to the proxy authentication request, and sends the authentication result to the proxy authentication device after the authentication verification is completed. The authentication result is either a result that the identity of the control device is legal or a result that the identity of the control device is illegal.

[0050] When the identity of the control device is confirmed to be legitimate, the authentication result may also include a key, which is used for the controlled device to exchange data with the control device. In one embodiment, the key may be a public-private key pair or a symmetric key, which is not limited in this application.

[0051] 7. The proxy authentication device sends the authentication result to the controlled device via the second Beacon broadcast packet.

[0052] In one embodiment, after receiving the authentication result, the proxy authentication device sends the authentication result to the controlled device in the form of a second Beacon broadcast packet.

[0053] After receiving the authentication result, the controlled device decides whether to accept the control of the controlling device.

[0054] In one embodiment, when the authentication result proves that the identity of the controlling device is legitimate, the controlled device accepts the control of the controlling device, and further, the controlled device and the controlling device exchange data through a key. In another embodiment, when the authentication result proves that the identity of the controlling device is not legitimate, the controlled device ignores the control instruction, that is, does not respond to the control instruction of the controlling device, or returns an indication information to the controlling device, indicating that the identity of the controlling device is not legitimate.

[0055] according to Figure 1In the embodiment shown, based on the characteristics of Beacon broadcast beacons, proxy authentication and authorization are performed through a third party, and there is no need to perform offline device configuration and cloud access on the controlled device, which assists in the authorization and key distribution between the control device and the controlled device. Therefore, on the one hand, the controlled device does not need to have cloud-connected hardware devices, such as wifi, cat1 and other modules, reducing costs; on the other hand, there is no need to complete the network configuration and cloud connection link for the controlled device, simplifying the operation steps and improving the user experience.

[0056] exist Figure 1 Based on the Beacon-based third-party proxy authentication system shown, according to one aspect of the present application, a Beacon-based third-party proxy authentication method implemented by a controlled device is provided. Figure 2 FIG. 1 is a flowchart of a Beacon-based third-party proxy authentication method implemented by a controlled device according to an embodiment of the present application. Figure 2 As shown, the method includes the following steps.

[0057] Step S201: In response to a control instruction sent by a control device, a first Beacon broadcast packet is sent to request authentication of the control device.

[0058] According to one embodiment, the controlling device sends a control instruction to the controlled device, indicating an attempt to control the controlled device. After receiving the control instruction, the controlled device needs to authenticate the legitimacy of the controlling device identity through the cloud server before determining whether to accept the control of the controlling device.

[0059] In this application, the controlled device is not directly connected to the cloud server, and the legitimacy of the controlled device is not directly authenticated by the cloud server, but the authentication request is sent to the cloud server through the proxy authentication device. The controlled device sends the authentication request to the outside through the Beacon broadcast packet.

[0060] In one embodiment, the first Beacon broadcast packet includes a proxy authentication request, and the proxy authentication request contains identification information of the control device.

[0061] In one embodiment, before the controlled device sends an authentication request via a Beacon broadcast packet, it needs to ensure that the proxy authentication device can scan the Beacon broadcast packet. The proxy authentication device sends information to the controlled device indicating that the proxy authentication device can receive the Beacon broadcast packet, triggering the authentication condition of the controlled device, and the controlled device can send a Beacon broadcast packet to request proxy authentication.

[0062] Thus, step S201 includes: upon receiving information sent by the proxy authentication device indicating that the proxy authentication device can receive Beacon broadcast packets, sending a first Beacon broadcast packet to request authentication of the control device.

[0063] The first Beacon broadcast packet is sent only when it is determined that the proxy authentication device can receive the Beacon broadcast packet based on the information sent by the proxy authentication device indicating that the proxy authentication device can receive the Beacon broadcast packet. This can prevent the problem of being unable to implement proxy authentication of the control device due to the first Beacon broadcast packet being not received.

[0064] Step S202: receiving a second Beacon broadcast packet from the proxy authentication device, wherein the Beacon broadcast packet includes an authentication result of the cloud server on the control device.

[0065] The proxy authentication device sends the proxy authentication request to the cloud server. After receiving the authentication result, the authentication result is sent out in the form of a Beacon broadcast packet. The controlled device receives the Beacon broadcast packet from the proxy authentication device, and the Beacon broadcast packet includes the authentication result of the cloud server on the control device.

[0066] Step S203: In response to the authentication result, determine whether to accept the control of the control device.

[0067] The authentication result confirms that the identity of the control device is legal or illegal. In one embodiment, when the authentication result confirms that the identity of the control device is legal, the controlled device accepts the control of the control device, and further, the controlled device and the control device exchange data through a key. In another embodiment, when the authentication result confirms that the identity of the control device is illegal, the controlled device ignores the control instruction, that is, does not respond to the control instruction of the control device, or returns an indication information to the control device, indicating that the identity of the control device is illegal.

[0068] Thus, step S203 includes sub-step S2031 and sub-step S2032:

[0069] Sub-step S2031, accepting control of the control device when the authentication result proves that the identity of the control device is legitimate;

[0070] Sub-step S2031: when the authentication result proves that the identity of the control device is illegal, the control instruction is ignored.

[0071] according to Figure 2The above steps shown are based on the characteristics of Beacon broadcast beacons. Through proxy authentication and authorization by a third party, the controlled device is not required to have a cloud-connected hardware device, nor does it require offline device configuration and cloud-connected operations for the controlled device. This can assist in the authorization and key distribution between the control device and the controlled device. In this way, since the controlled device does not need to have a cloud-connected hardware device, the device cost can be reduced; and since there is no need to configure the controlled device, the operation steps are simplified and the user experience is improved.

[0072] In one embodiment, the identification information of the control device comes from the control instruction sent by the control device. The identification information may include one or more of the MAC address, device ID and UUID of the control device, which is used to indicate the identity of the control device.

[0073] so, Figure 2 The method shown also includes: step S204, acquiring identification information of the control device in response to the control instruction sent by the control device.

[0074] In one embodiment, when the identity of the control device is confirmed to be legitimate, the authentication result may further include a key, and the key is used for data exchange between the controlled device and the control device.

[0075] so, Figure 2 The method shown also includes: step S205, when the authentication result proves that the identity of the control device is legitimate, exchanging data with the control device through the key included in the authentication result.

[0076] When the identity of the control device is verified to be legitimate, the authentication result includes a key, and the controlled device and the control device perform subsequent data exchange through the key, which can ensure the security of the data exchange process.

[0077] exist Figure 1 On the basis of the Beacon-based third-party proxy authentication system shown, according to another aspect of the present application, a Beacon-based third-party proxy authentication method implemented by a proxy authentication device is provided. Figure 3 FIG. 1 is a flowchart of a Beacon-based third-party proxy authentication method implemented by a proxy authentication device according to an embodiment of the present application. Figure 3 As shown, the method includes the following steps.

[0078] Step S301: receiving a first Beacon broadcast packet sent by a controlled device, where the first Beacon broadcast packet includes a proxy authentication request for requesting authentication of the control device.

[0079] In this application, the controlled device is not directly connected to the cloud server, and the legitimacy of the control device is not directly authenticated through the cloud server. Instead, the authentication request is sent to the cloud server through the proxy authentication device. The controlled device sends out the authentication request in the form of a Beacon broadcast packet. In one embodiment, the first Beacon broadcast packet includes a proxy authentication request, and the proxy authentication request contains the identification information of the control device. The proxy authentication device supports the Beacon protocol, and Bluetooth scans and listens for Beacon broadcast packets, including the first Beacon broadcast packet.

[0080] Step S302: Send a proxy authentication request to the cloud server.

[0081] In one embodiment, the proxy authentication device has established a network connection with the cloud service. After receiving the first Beacon broadcast packet from the controlled device, it calls the cloud interface to transmit the proxy authentication request to the cloud server.

[0082] Step S303: Receive the authentication result from the cloud server.

[0083] In one embodiment, the cloud server authenticates the control device according to the proxy authentication request and sends the authentication result to the proxy authentication device after the authentication verification is completed. Among them, the authentication result is either the result that the identity of the control device is legal or the result that the identity of the control device is illegal.

[0084] When it is confirmed that the identity of the control device is legal, the authentication result may further include a key, which is used for data exchange between the controlled device and the control device.

[0085] Step S304: Send the authentication result to the controlled device through a second Beacon broadcast packet.

[0086] In one embodiment, after the proxy authentication device receives the authentication result, it gives the authentication result to the controlled device in the form of a second Beacon broadcast packet.

[0087] According to Figure 3 The above steps shown, based on the characteristics of the Beacon broadcast beacon, through the proxy authentication device, proxy authentication and authorization are carried out by receiving and sending Beacon broadcasts. It does not require the controlled device to have a hardware device for connecting to the cloud, nor does it require the operation of offline device network configuration and the process of accessing the cloud for the controlled device, and it can assist in the authorization between the control device and the controlled device and the key distribution. In this way, since it does not require the controlled device to have a hardware device for connecting to the cloud, the device cost can be reduced; moreover, since there is no need to configure the network for the controlled device, the operation steps are simplified and the user experience is improved.

[0088] In one embodiment, before the controlled device sends an authentication request via a Beacon broadcast packet, it needs to ensure that the proxy authentication device can scan the Beacon broadcast packet. The proxy authentication device sends information to the controlled device indicating that the proxy authentication device can receive the Beacon broadcast packet, triggering the authentication condition of the controlled device, and the controlled device can send a Beacon broadcast packet to request proxy authentication.

[0089] so, Figure 3 The method shown also includes: step S305, before receiving the first Beacon broadcast packet sent by the controlled device, sending information indicating that the proxy authentication device can receive the Beacon broadcast packet to the controlled device.

[0090] In this way, the proxy authentication device sends information indicating that the proxy authentication device can receive Beacon broadcast packets. The controlled device will send the first Beacon broadcast packet only when it determines that the proxy authentication device can receive Beacon broadcast packets. This can prevent the problem of being unable to implement proxy authentication of the controlling device due to the first Beacon broadcast packet sent by the controlled device not being received.

[0091] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0092] See also Figure 4 , Figure 4 An electronic device is provided, comprising a processor and a memory. The memory stores computer instructions, and when the computer instructions are executed by the processor, the processor executes the computer instructions to achieve the following Figure 2 and Figure 3 The method and refinement scheme shown.

[0093] It should be understood that the above device embodiments are only illustrative, and the device disclosed in the present invention can also be implemented in other ways. For example, the division of units / modules described in the above embodiments is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units, modules or components can be combined, or can be integrated into another system, or some features can be ignored or not executed.

[0094] In addition, unless otherwise specified, each functional unit / module in each embodiment of the present invention may be integrated into one unit / module, each unit / module may exist physically separately, or two or more units / modules may be integrated together. The above-mentioned integrated unit / module may be implemented in the form of hardware or in the form of a software program module.

[0095] If the integrated unit / module is implemented in the form of hardware, the hardware may be a digital circuit, an analog circuit, etc. The physical implementation of the hardware structure includes but is not limited to transistors, memristors, etc. If not otherwise specified, the processor or chip may be any appropriate hardware processor, such as a CPU, a GPU, an FPGA, a DSP, an ASIC, etc. If not otherwise specified, the on-chip cache, the off-chip memory, and the memory may be any appropriate magnetic storage medium or magneto-optical storage medium, such as a resistive random access memory RRAM (Resistive Random Access Memory), a dynamic random access memory DRAM (Dynamic Random Access Memory), a static random access memory SRAM (Static Random-Access Memory), an enhanced dynamic random access memory EDRAM (Enhanced Dynamic Random Access Memory), a high-bandwidth memory HBM (High-Bandwidth Memory), a hybrid memory cube HMC (Hybrid Memory Cube), etc.

[0096] If the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a memory and includes several instructions for a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present disclosure. The aforementioned memory includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk and other media that can store program codes.

[0097] The present application also provides a non-transitory computer storage medium storing a computer program. When the computer program is executed by a plurality of processors, the processors execute the following Figure 2 and Figure 3 The method and refinement scheme shown.

[0098] According to the Beacon-based third-party proxy authentication solution of this application, based on the characteristics of Beacon broadcast beacons, proxy authentication and authorization are performed by a third party, and there is no need to perform offline device configuration operations and access the cloud for the controlled device, and assist in the authorization and key distribution between the control device and the controlled device. Therefore, on the one hand, the controlled device does not need to have cloud-connected hardware devices, such as wifi, cat1 and other modules, reducing costs; on the other hand, there is no need to complete the network configuration and cloud connection link for the controlled device, simplifying the operation steps, making the user use process simpler and more convenient, and improving the user experience.

[0099] The embodiments of the present application are described in detail above. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method and its core idea of ​​the present application. At the same time, changes or deformations made by those skilled in the art based on the ideas of the present application, the specific implementation methods and the scope of application of the present application, all belong to the scope of protection of the present application. In summary, the content of this specification should not be construed as a limitation on the present application.

Claims

1. A Beacon-based third-party proxy authentication method, applied to controlled devices, It is characterized in that include: In response to a control instruction sent by the control device, upon receiving information sent by the proxy authentication device indicating that the proxy authentication device can receive Beacon broadcast packets, sending a first Beacon broadcast packet to request authentication of the control device; receiving a second Beacon broadcast packet from the proxy authentication device, wherein the second Beacon broadcast packet includes an authentication result of the control device by the cloud server; as well as In response to the authentication result, it is determined whether to accept control of the control device.

2. The method according to claim 1, It is characterized in that Also includes: In response to the control instruction sent by the control device, the identification information of the control device is obtained, the identification information includes one or more of the MAC address, device ID and UUID of the control device, and the first Beacon broadcast packet includes the identification information of the control device.

3. The method according to claim 1 or 2, It is characterized in that The determining, in response to the authentication result, whether to accept the control of the control device comprises: If the authentication result proves that the identity of the control device is legitimate, accepting control of the control device; When the authentication result confirms that the identity of the control device is illegal, the control instruction is ignored.

4. The method according to claim 3, It is characterized in that Also includes: When the authentication result confirms that the identity of the control device is legitimate, data is exchanged with the control device through the key included in the authentication result.

5. A Beacon-based third-party proxy authentication method, applied to proxy authentication devices, It is characterized in that include: Sending information to the controlled device indicating that the proxy authentication device can receive Beacon broadcast packets; receiving a first Beacon broadcast packet sent by the controlled device, wherein the first Beacon broadcast packet includes a proxy authentication request for requesting authentication of the control device; Sending the proxy authentication request to the cloud server; Receiving an authentication result from the cloud server; as well as The authentication result is sent to the controlled device through a second Beacon broadcast packet.

6. The method according to claim 5, It is characterized in that In the case where the authentication result confirms that the identity of the control device is legitimate, the authentication result includes a key, and the key is used for data exchange between the controlled device and the control device.

7. A Beacon-based third-party proxy authentication system, the system comprising a cloud server, a control device, a controlled device and a proxy authentication device, Features: The control device sends a pairing instruction and a control instruction to the controlled device; The cloud server receives the proxy authentication request from the proxy authentication device, authenticates the identity of the control device, and returns an authentication result; The controlled device executes the method according to any one of claims 1 to 4; and The proxy authentication device executes the method according to claim 5 or 6.

8. A non-transitory computer storage medium storing a computer program, which, when executed by a plurality of processors, causes the processors to execute the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Method and system of device for accessing network based Wifi Beacon frame and control terminal

    CN107750058A

  • Authentication and authorization method and apparatus, authentication server, and machine-readable storage medium

    CN108462710A