A System and Method for Secure Authentication of Internet of Things Devices and High-Availability Message Communication
By introducing systems such as authentication and authorization modules into IoT devices, combined with the main and backup mode of MQTT Broker message bus, the security and high availability problems of IoT device access authentication and message communication are solved, and fast and secure access to load balancing and device identity authentication are achieved, which improves the stability and security of the overall system.
Patent Information
- Application Number
- CN202210992216.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-18
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2042-08-18
AI Technical Summary
The prior art cannot effectively ensure the security of Internet of Things device access authentication and the high availability of message communication. Especially in edge computing environments, the traditional message communication bus architecture is prone to cause service downtime and increased message bus pressure.
The system consists of authentication and authorization module, edge plug-and-play module, ESDK device management module, security proxy module, edge proxy module and NGINX proxy module is used to realize load balancing and high availability through the main and standby mode of the MQTT Broker message bus, supports international mainstream encryption algorithms and national secret algorithms, and provides device unique identity identification and security authentication services.
It improves the security of IoT device access platform authentication and high availability of message communication, ensures the stability of the overall service and the legality of the equipment, supports fast identity authentication and load balancing, and prevents equipment from being tampered with or counterfeit.
Smart Images

Figure CN115459905B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of electric power Internet of Things, and in particular relates to a system and method for security authentication and high-availability message communication of Internet of Things devices. Background Art
[0002] With the popularization of edge computing and the support of 5G environment, more and more IoT devices are deployed at the edge of enterprises, and enterprise security protection work faces constant challenges. Due to the real-time, complexity, perception and data heterogeneity of edge computing service models, the privacy protection and data security mechanisms in the traditional cloud computing architecture cannot be fully applied. With the emergence of new scenarios such as smart medical care, smart transportation, smart factories, smart homes, and autonomous driving, data computing security, storage security, and sharing security have become more and more prominent. As a new form of technology, edge computing (edge computing originated in the field of media, which refers to an open platform that integrates network, computing, storage, and application core capabilities on the side close to the source of objects or data, providing the nearest service nearby. Its application is initiated on the edge side, resulting in faster network service response, meeting the basic needs of the industry in real-time business, application intelligence, security and privacy protection, etc.) has typical security problems existing in information systems, as well as new security issues under new technologies, new businesses, and new scenarios.
[0003] In the era of the Internet of Everything, whether it is Industry 4.0, smart grid, intelligent transmission or smart city, the number of Internet of Things (IoT) devices related to smart home, smart logistics, remote healthcare, etc. connected to the IoT will increase exponentially. It is expected that in 2022, tens of billions of IoT devices will be connected to the Internet. The access of a huge number of devices will inevitably bring a series of problems such as secure access authentication of data and stable and efficient communication of messages. Especially for grid devices, the requirement for real-time response of service messages is higher. In the traditional message communication bus architecture of the IoT cloud-edge-end, a single message communication bus mode is adopted. When a failure occurs in the application of edge-side devices or the access permission of the application needs to be restricted for security reasons, operations need to be performed on the message bus, and the access through the message bus cannot be sensed. When the message bus fails, the overall service will be down. As more and more devices interact between the cloud and the edge, the pressure on the message bus also increases. The patent with the publication number CN105450659A provides an IoT security authentication system and authentication method. The authentication system includes IoT devices connected to the home local area network, control terminal devices for controlling the IoT devices, and authentication devices connected to the home local area network for performing security authentication on the control terminal devices; when the control terminal device is first connected to the authentication device, it is connected to the authentication device through the home local area network, and when connected again, the control terminal device is connected to the authentication device through the wide area network or the home local area network; the authentication device is connected to the IoT devices through the home local area network; the authentication device includes a main control chip and a storage module connected to the main control chip for storing the unique identification information of the control terminal device and the unique identification information of the IoT devices. This patent only gives a technical solution for how to perform security authentication and does not involve how to ensure the high availability of messages.
[0004] Therefore, how to provide a system and method for secure authentication of IoT devices and high-availability message communication is an urgent problem to be solved by those skilled in the art. Summary of the Invention
[0005] Aiming at the deficiencies of the prior art, the purpose of the present invention is to provide a system for secure authentication of IoT devices and high-availability message communication to solve the problems in the prior art that the security of IoT device access authentication and the high availability of message communication cannot be guaranteed; in addition, the present invention also provides a method for secure authentication of IoT devices and high-availability message communication.
[0006] To solve the above technical problems, the present invention adopts the following technical solutions:
[0007] In a first aspect, the present invention provides a system for secure authentication and highly available message communication of Internet of Things (IoT) devices, including: an authentication and authorization module and an authentication server for authenticating the identities of IoT devices, receiving device authentication requests sent by IoT devices, and verifying whether the identities of IoT devices are legal; an edge plug-and-play module for checking whether an IoT device has been authenticated. If not, it obtains device information from the ESDK device management module and initiates an IoT device identity authentication request; an ESDK device management module for providing device information query interfaces, device control interfaces, and event notification subscriptions; a security proxy module for implementing secure authentication for IoT devices to access the platform, encrypting and decrypting original data at the software level, and providing an IoT device identity authentication service with low resource occupancy for multiple security levels. The security proxy module supports international mainstream encryption algorithms and national cryptography algorithms; an edge proxy module for receiving and using IoT device identity authentication information to connect to the platform and storing IoT device identity authentication information; an NGINX proxy module for interacting with the edge proxy module at the IoT device end and ensuring the high availability of messages through the primary and backup modes of the MQTT Broker message bus. The NGINX proxy module connects to the primary and backup MQTT Broker message buses using device certificates, account passwords. When an IoT device end sends a message request, the NGINX proxy module evenly distributes it to the MQTT Broker message bus with a low load. Through the NGINX proxy architecture, the access of IoT device applications to the MQTT Broker message bus can be recorded in access.log and sent to the monitoring platform; the authentication and authorization module, the ESDK device management module, the security proxy module, and the edge proxy module are respectively communicatively connected to the edge plug-and-play module, the NGINX proxy module is communicatively connected to the edge proxy module, and the authentication and authorization module and the security proxy module are also respectively communicatively connected to the authentication server.
[0008] Further, when the authentication and authorization module and the authentication server verify the identity of an IoT device, if it is legal, they distribute the device certificate, MQTT account password, and authorization code, and automatically register the device information in the database; if it is not legal, they perform a rollback operation, delete the device information and account password, and manage the list of valid device information.
[0009] Further, the edge proxy module is also responsible for data forwarding during communication and interaction with the platform end. The edge plug-and-play module, the ESDK device management module communicate with the platform through EdgeHub for forwarding.
[0010] Further, the device information obtained by the edge plug-and-play module includes the device unique ID and the MAC address.
[0011] Further, managing the list of valid device information includes querying, adding, deleting, and batch importing.
[0012] In a second aspect, the present invention also provides a method for secure authentication and highly available message communication of Internet of Things devices, including the following steps:
[0013] S10. When the Internet of Things device starts up, determine whether the device is registered. If not, start the registration process. The edge plug-and-play module calls the ESDK device management module interface to obtain the device unique ID and MAC address.
[0014] S20. The edge plug-and-play module sends the device information to the security proxy module for encryption.
[0015] S30. The edge plug-and-play module sends the encrypted device information to the authentication and authorization management module to obtain the authorization code and device certificate.
[0016] S40. The authentication and authorization management module sends the encrypted device information to the authentication server and returns the authentication result.
[0017] S50. Determine whether the authentication server checks that the ESN of the device is legal. The ESN is the encrypted device unique ID. If it is not legal, return an error message. If it is legal, return the encrypted device certificate, account password, and authorization code byte stream.
[0018] S60. The edge plug-and-play module sends the received device certificate, account password, and authorization code information to the security proxy module for decryption and sends the decrypted device certificate, account password, and authorization code information to the edge proxy module.
[0019] S70. The edge proxy module receives and saves the device certificate, account password, and authorization code information, returns the information of successful / failed processing, and uses the information related to the device certificate, account password, and authorization code information to connect to the NGINX proxy module.
[0020] S80. The NGINX proxy module uses the device certificate and account password to connect to the primary and standby MQTT Broker message buses and returns the information of successful / failed processing to the edge proxy module.
[0021] After successful connection, the edge proxy module interacts with the platform through the NGINX proxy module. When the edge side sends a message request, the NGINX proxy module will evenly distribute it to the MQTT Broker message bus with a low load. Through the NGINX proxy architecture, the access of the Internet of Things device application to the MQTT Broker message bus can be recorded in the access.log and sent to the monitoring platform, thereby ensuring the high availability of messages.
[0022] Further, in the step S50, the basis for the authentication server to check whether the ESN of the device is legal is whether the ESN is in the database and has not been used.
[0023] Further, in the step S50, the authorization code and the account password are randomly generated according to certain rules to ensure the uniqueness of the account.
[0024] Compared with the prior art, the system and method for secure authentication and highly available message communication of Internet of Things devices provided by the present invention have at least the following beneficial effects:
[0025] Based on a full proxy and adopting a primary and standby message bus mode, the present invention schedules and manages message requests, evenly distributes them to message bus servers with low load, realizes load balancing, improves the high availability and fault tolerance of message communication, ensures the stability of messages through the primary and standby mode of the message bus, and thus guarantees the normal operation of the overall service. For device network access authorization, after passing security authentication, the device can be automatically registered in the management platform. To prevent the device from being tampered with or counterfeited, the platform only allows access to legally authorized devices, provides a unique identity for each Internet of Things device for device authentication, supports international mainstream encryption algorithms and national cryptographic algorithms, quickly docks with the Internet of Things device identity authentication service, and comprehensively improves the security of access authentication and data communication of various Internet of Things devices to the platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the solution of the present invention, the drawings required for description in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0027] Figure 1 It is a system structure block diagram of a secure authentication and highly available message communication system for Internet of Things devices provided by an embodiment of the present invention;
[0028] Figure 2 It is a schematic diagram of device access authentication of a secure authentication and highly available message communication system for Internet of Things devices provided by an embodiment of the present invention;
[0029] Figure 3 It is a start-up flowchart of an edge plug-and-play module of a secure authentication and highly available message communication system for Internet of Things devices provided by an embodiment of the present invention;
[0030] Figure 4 It is an encryption schematic diagram of a security proxy module of a secure authentication and highly available message communication system for Internet of Things devices provided by an embodiment of the present invention;
[0031] Figure 5 Schematic diagram for decrypting the security proxy module of a system for secure authentication and highly available message communication of Internet of Things devices provided by an embodiment of the present invention. Detailed implementation manners
[0032] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this invention belongs; the terms used in the description of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. For example, the terms such as "length", "width", "upper", "lower", "left", "right", "front", "rear", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. indicate the orientation or position based on the orientation or position shown in the drawings, and are only for convenience of description and cannot be construed as a limitation to the technical solution of the present invention.
[0033] The terms "comprising" and "having" and any variations thereof in the description and claims of the present invention and the above drawings are intended to cover non-exclusive inclusion; the terms "first", "second", etc. in the description and claims of the present invention or the above drawings are used to distinguish different objects and are not used to describe a specific order. In the description and claims of the present invention and the above drawings, when an element is referred to as being "fixed to" or "mounted on" or "disposed on" or "connected to" another element, it can be directly or indirectly located on the other element. For example, when an element is referred to as being "connected to" another element, it can be directly or indirectly connected to the other element.
[0034] In addition, the mention of "embodiment" in this article means that a specific feature, structure or characteristic described in connection with the embodiment can be included in at least one embodiment of the present invention. The phrase appears at various positions in the description and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0035] The present invention provides a system for secure authentication and highly available message communication of Internet of Things (IoT) devices, which is used in the identity authentication and message communication of IoT devices. The system for secure authentication and highly available message communication of IoT devices includes: an authentication and authorization module and an authentication server, which are used for the identity authentication of IoT devices, receiving device authentication requests sent by IoT devices, and verifying whether the identities of IoT devices are legal; an edge plug-and-play module, which is used to check whether the IoT device has been authenticated. If not, it obtains device information from the ESDK device management module and initiates an IoT device identity authentication request; the ESDK device management module, which is used to provide device information query interfaces, device control interfaces, and event notification subscriptions; a security proxy module, which is used to implement the secure authentication of IoT devices accessing the platform, encrypting and decrypting the original data at the software level, and providing IoT device identity authentication services with low resource occupancy for multiple security levels. The security proxy module supports international mainstream encryption algorithms and national cryptographic algorithms; an edge proxy module, which is used to receive and use the IoT device identity authentication information to connect to the platform and save the IoT device identity authentication information; an NGINX proxy module, which is used to interact with the edge proxy module at the IoT device side and ensure the high availability of messages through the primary and standby modes of the MQTT Broker message bus. The NGINX proxy module connects to the primary and standby MQTT Broker message buses using device certificates, account passwords. When the IoT device side sends a message request, the NGINX proxy module will evenly distribute it to the MQTT Broker message bus with a low load. Through the NGINX proxy architecture, the access of the application of the IoT device to the MQTT Broker message bus can be recorded in the access.log and sent to the monitoring platform; the authentication and authorization module, the ESDK device management module, the security proxy module, and the edge proxy module are respectively communicatively connected to the edge plug-and-play module, the NGINX proxy module is communicatively connected to the edge proxy module, and the authentication and authorization module and the security proxy module are also respectively communicatively connected to the authentication server.
[0036] The present invention can effectively improve the security of the access authentication of various IoT devices to the platform and the high availability of message communication.
[0037] In order to enable the personnel in the technical field to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings.
[0038] The present invention provides a system for secure authentication and highly available message communication of Internet of Things (IoT) devices, which is used in the identity authentication and message communication of IoT devices, such as Figure 1As shown in the figure, in this embodiment, the system for secure authentication and highly available message communication of Internet of Things (IoT) devices includes: an authentication and authorization module and an authentication server, which are used for the identity authentication of IoT devices, receiving device authentication requests sent by IoT devices, and verifying whether the identities of IoT devices are legal; an edge plug-and-play module, which is used to check whether the IoT device has been authenticated. If not, it obtains device information from the ESDK device management module and initiates an IoT device identity authentication request; the ESDK device management module, which is used to provide device information query interfaces, device control interfaces, and event notification subscriptions; a security proxy module, which is used to implement the secure authentication of IoT devices accessing the platform, encrypting and decrypting the original data at the software level, and providing an IoT device identity authentication service with low resource occupancy for multiple security levels. The security proxy module supports international mainstream encryption algorithms and national cryptographic algorithms; an edge proxy module, which is used to receive and use the IoT device identity authentication information to connect to the platform and save the device information; an NGINX proxy module, which is used to interact with the edge proxy module at the IoT device end and ensure the high availability of messages through the primary and standby modes of the MQTT Broker message bus. The NGINX proxy module connects to the primary and standby MQTT Broker message buses using device certificates, account passwords. When the IoT device end sends a message request, the NGINX proxy module will evenly distribute it to the MQTT Broker message bus with a low load. Through the NGINX proxy architecture, the access of the IoT device application through the MQTT Broker message bus can be recorded in the access.log and sent to the monitoring platform; the authentication and authorization module, the ESDK device management module, the security proxy module, and the edge proxy module are respectively communicatively connected to the edge plug-and-play module, and the NGINX proxy module is communicatively connected to the edge proxy module. The authentication and authorization module and the security proxy module are also respectively communicatively connected to the authentication server.
[0039] Further, in this embodiment, when the authentication and authorization module and the authentication server verify the identity of the IoT device, if it is legal, they distribute the device certificate, MQTT account password, and authorization code, and automatically register the device information in the database; if it is not legal, they perform a rollback operation, delete the device information and account password, and manage the list of valid device information. The management content includes querying, adding, deleting, and batch importing.
[0040] Specifically, as Figure 2 shown, the process of the authentication and authorization module and the authentication server verifying the identity of the IoT device is as follows:
[0041] The IoT device calls the ESDK device management module through the security code module to obtain the authentication data stream;
[0042] The edge plug-and-play module transmits the authentication data stream to the authentication and authorization module at the platform segment;
[0043] The platform-side authentication and authorization module sends the authentication request to the TID authentication server by calling the server-side SDK;
[0044] The authentication server returns the authentication result. If the authentication is successful, the server-side SDK will return the server-side authentication data stream, authorization code, and session Token. At the same time, it will distribute the certificate, MQTT account password, and authorization code, and automatically register the device information in the database. When the authentication fails, it will perform a rollback operation to delete the device information and account password, and manage the list of valid device information, including querying, adding, deleting, and batch importing;
[0045] When the TID authentication server returns successfully, the platform-side authentication and authorization module needs to transmit the authentication data stream information completely to the edge plug-and-play module, and record the authorization code and session Token for subsequent business data encryption / decryption.
[0046] Specifically, the data structure of the authentication message is shown in Tables 1 and 2 below:
[0047]
[0048] Table 1
[0049]
[0050] Table 2
[0051] Specifically, the data table structure is shown in Table 3:
[0052] Table Name Column Name Data Type Description edgenode id int(11) ID edgenode name varchar(100) Node Name edgenode node_code varchar(80) Node Number edgenode system_type varchar(100) System Type edgenode products varchar(100) Product edgenode ip varchar(45) IP edgenode mqtt_address varchar(100) MQTT Address edgenode mqtt_username varchar(100) MQTT Username edgenode mqtt_password varchar(64) MQTT Password edgenode authcode varchar(256) Authentication Code edgenode created_at datetime Creation Time edgenode updated_at datetime Update Time edgenode del int(11) ID
[0053] Table 3
[0054] Furthermore, in this embodiment, the edge plug-and-play module checks whether the IoT device has been authenticated. If not, it obtains the device information (such as the device unique ID and MAC address) from the ESDK device management module, and initiates an IoT device identity authentication request. The entire authentication process is completed within two seconds, and the authentication result is forwarded to the edge proxy module.
[0055] Specifically, as Figure 3 shown, the process of the edge plug-and-play module is as follows:
[0056] Check whether the edge device has been authenticated;
[0057] Obtain the device information from the ESDK device management module;
[0058] Initiate an IoT device identity authentication request;
[0059] Forward the authentication result to the EdgeHub forwarding module.
[0060] Specifically, the data structure for obtaining device identity information is shown in Table 4:
[0061]
[0062] Table 4
[0063] Specifically, the data structure for requesting device identity authentication is shown in Table 5:
[0064]
[0065]
[0066] Specifically, the data structure for sending device identity authentication information to Edgehub is shown in Table 6:
[0067]
[0068] Specifically, the data structure for sending the identity authentication processing structure to the cloud service is shown in Table 7:
[0069]
[0070]
[0071] Table 7
[0072] Furthermore, in this embodiment, the ESDK device management module provides a device information query structure, a device control interface, and event notification subscriptions. It interacts with the operating system to unify the interfaces for applications to access Internet of Things devices.
[0073] Specifically, the data structure for querying device identity information is shown in Table 8:
[0074]
[0075] Table 8
[0076] Furthermore, in this embodiment, the security proxy module implements the security authentication for Internet of Things devices to access the platform, encrypts and decrypts the original data at the software level, provides an Internet of Things device identity authentication service with multiple security levels and less resource occupation, supports international mainstream encryption algorithms and national cryptography algorithms, and meets different security qualification requirements.
[0077] Specifically, it supports international mainstream encryption algorithms and national cryptography algorithms, such as Figure 4 shown. Taking SM4 as an example, the specific encryption process is as follows:
[0078] The SM4 algorithm is a block cipher algorithm. The block length of the algorithm is 128 bits, and the key length is 128 bits. Both the encryption algorithm and the key expansion algorithm adopt a 32-round non-linear iterative structure. The decryption algorithm has the same structure as the encryption algorithm, except that the order of using the round keys is reversed. The decryption round keys are the reverse order of the encryption round keys. The algorithm adopts a non-linear iterative structure, and each iteration is given by a round function. The round function is composed of a non-linear transformation and a linear transformation. The non-linear transformation is given by the S-box, where rki is the round key, and the composite permutation T forms the round function. The generation of the round keys takes the encryption key as the input. The linear transformation in the round function is different, and there are also some differences in parameters.
[0079] Basic cryptographic components: The SM4 cryptographic algorithm uses basic cryptographic components such as S-boxes, non-linear transformation τ, linear transformation component L, and composite transformation T.
[0080] Round function: The SM4 cryptographic algorithm adopts a structure that iterates on the basic round function. Using the above basic cryptographic components, the round function can be constructed. The round function of the SM4 cryptographic algorithm is a cryptographic function that takes words as the processing unit.
[0081] Encryption algorithm: The SM4 cryptographic algorithm is a block cipher algorithm. The data block length is 128 bits, and the key length is 128 bits. The encryption algorithm adopts a 32-round iterative structure, and each round uses a round key.
[0082] Key expansion algorithm: The SM4 cryptographic algorithm uses a 128-bit encryption key and adopts a 32-round iterative encryption structure. Each round of encryption uses a 32-bit round key, and a total of 32 round keys are used. Therefore, a key expansion algorithm is needed to generate 32 round keys from the encryption key.
[0083] Specifically, as Figure 5 shown, the specific decryption process is as follows:
[0084] Decryption algorithm: The SM4 cryptographic algorithm is an involution operation. Therefore, the decryption algorithm has the same structure as the encryption algorithm, except that the order of using the round keys is reversed. The decryption round keys are the reverse order of the encryption round keys.
[0085] Specifically, the data structure of data encryption is shown in Table 9:
[0086]
[0087]
[0088] Table 9
[0089] The data structure of data decryption is shown in Table 10:
[0090]
[0091] Table 10
[0092] Furthermore, in this embodiment, the edge proxy module receives and uses the identity authentication information of the IoT device to connect to the platform, saves the device information, and is responsible for data forwarding during communication and interaction with the platform end. It is connected to the NGINX proxy module on the platform end. Other microservices on the edge communicate with the platform through the edge proxy module for forwarding, which facilitates permission control.
[0093] Specifically, the data structure of the device identity authentication information saving interface is shown in Table 11:
[0094]
[0095]
[0096] Table 11
[0097] Furthermore, in this embodiment, as Figure 1 shown, the NGINX proxy module is used to interact with the edge proxy module on the IoT device side, and uses the device certificate, account password to connect to the primary and standby 2 MQTT Broker message buses. When the IoT device side sends a message request, the NGINX proxy module will evenly distribute it to the MQTT Broker message bus with a low load. Through the NGINX proxy architecture, the access of the edge device application to the MQTT Broker message bus can be recorded in access.log and sent to the monitoring platform, ensuring the reliability of the message. The primary and standby mode of the message bus ensures the stability of the message, and thus ensures the normal operation of the overall business.
[0098] Specifically, the functions of the NGINX proxy module to achieve load balancing include:
[0099] a. Forwarding function
[0100] According to certain algorithms such as the weight algorithm and the round-robin algorithm, forward the client requests to different message bus servers, relieve the pressure on a single message bus, and improve the system concurrency.
[0101] b. Fault removal
[0102] Through the heartbeat detection method, judge whether the message bus can work normally currently. If the message bus fails, automatically send the request to the message bus.
[0103] c. Recovery and addition
[0104] If it is detected that the faulty message bus resumes work, automatically add it to the queue for processing user requests.
[0105] Specifically, the process of the NGINX proxy module implementing message bus load balancing is as follows:
[0106] a. Set the port numbers of the primary and standby message buses MQTT Brokers, which are 8081 and 8082 respectively;
[0107] b. First, define the path of the sub-configuration file for load balancing in the main NGINX configuration file. The directive for the path of the sub-configuration file for load balancing should be at the same level as the http statement block. Generally, it can be written at the end of the main configuration file. Since stream is a first-level statement block and there can be only one in the entire NGINX, all load balancing configurations are written in the same file.
[0108] c. The load balancing configuration mainly focuses on the configuration of upstream. Assume that the IP addresses and port numbers of two MQTT Brokers are 192.168.0.28:8081 and 192.168.0.28:8082 respectively. The specific details are as follows:
[0109]
[0110] Among them, down means that the current server does not participate in the load temporarily. The default value of weight is 1. The larger the weight, the greater the load weight. The default value of max_fails, which allows the number of request failures, is 1. When the maximum number is exceeded, an error defined by the proxy_next_upstream module is returned.
[0111] Specifically, the load balancing strategy is as follows:
[0112] a. Process requests in turn
[0113] Each request is sequentially assigned to different message bus servers in chronological order. If a message bus server goes down, it is automatically removed, and the remaining ones continue to be polled.
[0114] b. Weight
[0115] By configuring the weight, the polling probability is specified. The weight is proportional to the access ratio and is used in the case where the performance of application servers is uneven.
[0116] c. ip_hash algorithm
[0117] Each request is assigned according to the hash result of the access IP. In this way, each visitor is fixed to access an application server, which can solve the problem of session sharing.
[0118] The embodiment of the present invention also provides a method for Internet of Things device security authentication and highly available message communication applied to the above system, including the following steps:
[0119] S10. When the IoT device starts up, determine whether the device has been registered. If not, start the registration process. The Edge Plug and Play module calls the ESDK device management module interface to obtain device information such as the device unique ID and MAC address;
[0120] S20. The Edge Plug and Play module sends the device information to the security proxy module for encryption;
[0121] S30. The Edge Plug and Play module sends the encrypted device information to the authentication and authorization management module to obtain the authorization code and device certificate;
[0122] S40. The authentication and authorization management module sends the encrypted device information to the authentication server and returns the authentication result;
[0123] S50. Determine whether the authentication server checks whether the ESN of the device is legal. The ESN is the encrypted device unique ID (whether the ESN is in the database and not in use). If it is not legal, return an error message. If it is legal, return the encrypted device certificate, account password, and authorization code byte stream (the authorization code and account password are randomly generated according to certain rules to ensure the uniqueness of the account);
[0124] S60. The Edge Plug and Play module sends the received device certificate, account password, and authorization code information to the security proxy module for decryption and sends the decrypted device certificate, account password, and authorization code information to the edge proxy module;
[0125] S70. The edge proxy module receives and saves the device certificate, account password, and authorization code information, returns the information of successful / failed processing, and uses the relevant information to connect to the NGINX proxy module;
[0126] S80. The NGINX proxy module uses the device certificate and account password to connect to the primary and standby MQTT Broker message buses and returns the information of successful / failed processing to the edge proxy module;
[0127] S90. After the connection is successful, the edge proxy module interacts with the platform through the NGINX proxy module. When the edge side sends a message request, the NGINX proxy module will evenly distribute it to the MQTT Broker message bus with a low load. Through the NGINX proxy architecture, the access of the IoT device application to the MQTT Broker message bus can be recorded in the access.log and sent to the monitoring platform, thereby ensuring the high availability of the message.
[0128] A system and method for security authentication and highly available message communication of Internet of Things devices described in the above embodiments, based on a full proxy, adopts a primary and standby message bus mode to schedule and manage message requests and evenly distribute them to message bus servers with low load, achieving load balancing, improving the high availability and fault tolerance of message communication, ensuring the stability of messages through the primary and standby mode of the message bus, and thus guaranteeing the normal operation of the overall business and device network access authorization. After passing security authentication, the device can be automatically registered in the management platform. To prevent the device from being tampered with or counterfeited, the platform only allows access to legally authorized devices, provides a unique identity identifier for each Internet of Things device for device authentication, supports international mainstream encryption algorithms and national cryptography algorithms, quickly docks with the Internet of Things device identity authentication service, and comprehensively improves the security of access platform authentication and data communication for various Internet of Things devices.
[0129] Obviously, the embodiments described above are only the preferred embodiments of the present invention, rather than all embodiments. The preferred embodiments of the present invention are given in the accompanying drawings, but do not limit the patent scope of the present invention. The present invention can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosed content of the present invention more thorough and comprehensive. Although the present invention has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions recorded in the foregoing specific embodiments, or perform equivalent replacements for some of the technical features. Any equivalent structure directly or indirectly using the content of the specification and drawings of the present invention in other related technical fields shall be equally within the scope of the patent protection of the present invention.
Claims
1. A system for secure authentication of Internet of Things devices and highly available message communication, characterized in that, Including: The authentication and authorization module and the authentication server are used for the identity authentication of Internet of Things devices, receiving the device authentication requests sent by the Internet of Things devices, and verifying whether the identities of the Internet of Things devices are legal; The edge plug-and-play module is used to check whether the Internet of Things device has been authenticated. If not, it obtains the device information from the ESDK device management module and initiates an Internet of Things device identity authentication request; The ESDK device management module is used to provide device information query interfaces, device control interfaces, and event notification subscriptions; The security proxy module is used to implement the security authentication for the Internet of Things devices to access the platform, encrypt and decrypt the original data at the software level, and provide an Internet of Things device identity authentication service with low resource occupancy for multiple security levels. The security proxy module supports international mainstream encryption algorithms and national encryption algorithms; The edge proxy module is used to receive and use the Internet of Things device identity authentication information to connect to the platform and save the Internet of Things device identity authentication information; The NGINX proxy module is used to interact with the edge proxy module at the Internet of Things device side, and ensure the high availability of messages through the primary and standby modes of the MQTT Broker message bus. The NGINX proxy module uses device certificates, account passwords to connect to the two MQTT Broker message buses of the primary and standby. When the Internet of Things device side sends a message request, the NGINX proxy module will evenly distribute it to the MQTT Broker message bus with a low load. Through the NGINX proxy architecture, the access of the applications of the Internet of Things devices to the MQTT Broker message bus can be recorded in the access.log and sent to the monitoring platform; The authentication and authorization module, the ESDK device management module, the security proxy module, and the edge proxy module are respectively communicatively connected to the edge plug-and-play module. The NGINX proxy module is communicatively connected to the edge proxy module. The authentication and authorization module and the security proxy module are also respectively communicatively connected to the authentication server.
2. The system for secure authentication and highly available message communication of an Internet of Things device according to claim 1, characterized in that, When the authentication and authorization module and the authentication server verify the identity of the Internet of Things device, if it is legal, they distribute the device certificate, MQTT account password, and authorization code, and automatically register the device information in the database; If it is not legal, a rollback operation is performed to delete the device information and the account password, and manage the list of valid device information.
3. The system for secure authentication and highly available message communication of an Internet of Things device according to claim 1, characterized in that, The edge proxy module is also responsible for data forwarding during communication and interaction with the platform side. The edge plug-and-play module, the ESDK device management module communicate with the platform through EdgeHub for forwarding.
4. The system for secure authentication and highly available message communication of an Internet of Things device according to claim 1, wherein, The device information obtained by the edge plug-and-play module includes the device unique ID and the MAC address.
5. The system for secure authentication and highly available message communication of an Internet of Things device according to claim 2, wherein Managing the list of valid device information includes querying, adding, deleting, and batch importing.
6. A method applied to the system of Internet of Things device security authentication and highly available message communication according to any one of claims 1 to 5, characterized in that, Including the following steps: S10. When the Internet of Things device starts up, it judges whether the device has been registered. If not, it starts the registration process. The edge plug-and-play module calls the ESDK device management module interface to obtain the device unique ID and the MAC address; S20. The edge plug-and-play module sends the device information to the security proxy module for encryption; S30. The edge plug-and-play module sends the encrypted device information to the authentication and authorization management module to obtain an authorization code and a device certificate; S40. The authentication and authorization management module sends the encrypted device information to the authentication server and returns an authentication result; S50. Determine whether the authentication server checks whether the ESN of the device is legal. The ESN is the encrypted unique ID of the device. If it is not legal, an error message is returned. If it is legal, the encrypted device certificate, account password, and authorization code byte stream are returned; S60. The edge plug-and-play module sends the received device certificate, account password, and authorization code information to the security proxy module for decryption and sends the decrypted device certificate, account password, and authorization code information to the edge proxy module; S70. The edge proxy module receives and saves the device certificate, account password, and authorization code information, returns information indicating success / failure of processing, and uses the device certificate, account password, and authorization code information to connect to the NGINX proxy module; S80. The NGINX proxy module uses the device certificate and account password to connect to the primary and standby MQTT Broker message buses and returns information indicating success / failure of processing to the edge proxy module; S90. After successful connection, the edge proxy module interacts with the platform through the NGINX proxy module. When a message request is sent from the edge side, the NGINX proxy module evenly distributes it to the MQTT Broker message bus with a low load. Through the NGINX proxy architecture, the access of the Internet of Things device application through the MQTT Broker message bus can be recorded in access.log and sent to the monitoring platform, thereby ensuring the high availability of messages.
7. A method according to claim 6, characterized in that In step S50, the basis for determining whether the authentication server checks whether the ESN of the device is legal is whether the ESN is in the database and has not been used.
8. A method according to claim 7, wherein In step S50, the authorization code and account password are randomly generated according to certain rules to ensure the uniqueness of the account.
Citation Information
Patent Citations
Security authentication system and authentication method for the Internet of things
CN105450659A
Authentication method for power grid terminal layer equipment access
CN112468490A
Internet of Things equipment registration and security authentication connection and instruction interaction method
CN114362931A