Internet of Things General Terminal Security Authentication System, Method, Device and Internet of Things Communication Terminal

By designing a pan-terminal security certification system for the power Internet of Things, and using the collaborative work of cloud platform, Internet of Things communication terminal and security certification platform, the problem of security certification of power Internet of Things terminals has been solved, and the security guarantee of security certification of power Internet of Things systems and data transmission is achieved.

CN115459919BActive Publication Date: 2025-05-27GUANGDONG PLANNING & DESIGNING INST OF TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210937572.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-05
Publication Date
2025-05-27
Estimated Expiration
2042-08-05

AI Technical Summary

Technical Problem

The hardware performance of the power Internet of Things pan-terminal terminal is low, the operating system is complex, it is difficult to install high-performance certification software, and the firewall ports are limited, making it difficult to access massive terminals, and there is a risk of tampering with wireless connections.

Method used

Design a power Internet of Things pan-terminal security certification system, including cloud platform, Internet of Things communication terminal and security certification platform. The cloud platform receives the initial device feature information of the terminal, generates a unique identification code, and sends it to the Internet of Things communication terminal. When establishing a connection, the terminal collects the actual device feature information and requests the security authentication platform to perform security authentication based on the unique identification code and actual feature information.

Benefits of technology

Real-time and accurate security authentication of power IoT pan-terminals is realized, and the situations that cannot be detected due to tampering with the deployment in outdoor terminals is improved, the security of power IoT systems is ensured, and the secure transmission of communication data is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115459919B_ABST
    Figure CN115459919B_ABST
Patent Text Reader

Abstract

This application relates to an Internet of Things (IoT) general terminal authentication and transmission security authentication system, method, device, and IoT communication terminal. The system includes: a cloud platform for receiving initial device feature information of at least one IoT general terminal, extracting target data of a preset number of digits from the initial device feature information; generating a unique identification code corresponding to the IoT general terminal according to the target data; and sending the unique identification code corresponding to each IoT general terminal to the IoT communication terminal for storage by the IoT communication terminal. The IoT communication terminal is used for collecting actual device feature information of at least one target IoT general terminal when establishing a communication connection with the target IoT general terminal among each IoT general terminal; and requesting the security authentication platform to perform security authentication on the target IoT general terminal according to the unique identification code corresponding to the target IoT general terminal and the actual device feature information. Using this method can improve the security of the power IoT.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power technology, and in particular, to a power Internet of Things (IoT) general terminal security authentication system. Background Art

[0002] The power Internet of Things is the application of the Internet of Things in the smart grid, which is the result of the development of information and communication technology to a certain stage. It will effectively integrate communication infrastructure resources and power system infrastructure resources, improve the informatization level of the power system, improve the utilization efficiency of the existing infrastructure of the power system, and provide important technical support for power generation, transmission, transformation, distribution, and power consumption in the power grid.

[0003] Power IoT general terminals are usually deployed outdoors and need to face social users alone. Most IoT terminals can directly control devices. Therefore, it is necessary to continuously monitor and analyze the behaviors of IoT terminals and be able to block dangerous actions in a timely manner.

[0004] However, the hardware performance of power IoT general terminals is relatively low, and there are many operating systems, making it difficult to directly install access software with high performance requirements on the terminals. In addition, the number of power IoT general terminals is large. Using firewalls in traditional technologies, the firewall ports are limited, making it difficult to connect to a large number of power IoT general terminals. Finally, compared with traditional networks, power IoT general terminals use wireless connections as an important way for IoT terminals to access the network. In wireless access, the terminals are not physically restricted and are at risk of being replaced. Summary of the Invention

[0005] Based on this, in view of the above technical problems, it is necessary to provide a power IoT general terminal security authentication system that can improve the security of the power Internet of Things.

[0006] An IoT general terminal authentication system includes a cloud platform, an IoT communication terminal, and a security authentication platform;

[0007] The cloud platform is configured to receive initial device feature information of at least one IoT general terminal, extract target data of a preset number of digits from the initial device feature information; generate a unique identification code corresponding to the IoT general terminal according to the target data; and send the unique identification code corresponding to each IoT general terminal to the IoT communication terminal for storage by the IoT communication terminal;

[0008] The IoT communication terminal is configured to collect actual device feature information of at least one target IoT general terminal when establishing a communication connection with the at least one target IoT general terminal among the IoT general terminals; and request the security authentication platform to perform security authentication on the target IoT general terminal according to the unique identification code corresponding to the target IoT general terminal and the actual device feature information;

[0009] The security authentication platform is used to determine whether the target Internet of Things (IoT) general terminal passes security authentication based on the difference between the actual device feature information and the reference device feature information corresponding to the target IoT general terminal; the reference device feature information corresponding to the target IoT general terminal is determined according to the unique identification code corresponding to the target IoT general terminal.

[0010] In one embodiment, the IoT communication terminal is used to send a security authentication request for the target IoT general terminal to the security authentication platform; the security authentication request carries the actual device feature information of the target IoT general terminal and the unique identification code corresponding to the target IoT general terminal.

[0011] The security authentication platform is used to, in response to the security authentication request, determine the reference device feature information corresponding to the target IoT general terminal according to the unique identification code corresponding to the target IoT general terminal; compare the difference between the reference device feature information and the actual device feature information to obtain a feature information comparison result; send a security authentication result generated based on the feature information comparison result to the IoT communication terminal; the security authentication result is used to represent whether the target IoT general terminal passes security authentication.

[0012] In one embodiment, the cloud platform is used to generate a random code with a specified number of digits according to a preset random code generation algorithm; generate the unique identification code corresponding to the IoT general terminal according to the random code and the target data.

[0013] In one embodiment, the cloud platform is used to obtain the data code corresponding to the target data; splice the random code to the end of the data code to obtain a target code; perform an encryption process on the target code according to a preset code encryption algorithm to obtain the unique identification code corresponding to the IoT general terminal.

[0014] In one embodiment, the cloud platform is used to encrypt the unique identification code corresponding to the IoT general terminal by using a preset key to generate an encryption certificate corresponding to the unique identification code; send the key and the encryption certificate to the IoT communication terminal.

[0015] In one embodiment, the IoT communication terminal is used to receive the key and the encryption certificate sent by the cloud platform; decrypt the encryption certificate by using the key to obtain the unique identification code corresponding to the IoT general terminal; save the unique identification code corresponding to the IoT general terminal to a preset storage area.

[0016] In one embodiment, the Internet of Things communication terminal is further configured to collect initial device feature information of at least one Internet of Things general terminal; encrypt the initial device feature information of each Internet of Things general terminal by using a preset feature information encryption algorithm to obtain encrypted device feature information corresponding to each Internet of Things general terminal; and send the encrypted device feature information corresponding to each Internet of Things general terminal to the cloud platform.

[0017] In one embodiment, the initial device feature information includes at least one of a device identification code, a media storage control address, a serial number, an operating system brand, an operating system serial number, and geographical location information.

[0018] In one embodiment, the Internet of Things general terminal is configured to collect Internet of Things sensing data; the Internet of Things general terminal is further configured to send the collected Internet of Things sensing data to a standardized data interface of the Internet of Things communication terminal according to a preset transmission protocol; and the standardized data interface is configured to transfer the Internet of Things sensing data to an operating system of the Internet of Things communication terminal for the operating system to perform data processing operations on the Internet of Things sensing data.

[0019] In one embodiment, the Internet of Things general terminal includes at least one of a temperature sensor, a humidity sensor, a light sensor, a pressure-sensitive sensor, and a displacement sensor.

[0020] An Internet of Things general terminal authentication method, the method includes:

[0021] When establishing a communication connection with at least one target Internet of Things general terminal, collect actual device feature information of the target Internet of Things general terminal;

[0022] Read a unique identification code corresponding to the target Internet of Things general terminal; the unique identification code is a code generated by pre-obtaining initial device feature information of the target Internet of Things general terminal and extracting target data with a preset number of digits from the initial device feature information;

[0023] According to the unique identification code and the actual device feature information, request a security authentication platform to perform security authentication on the target Internet of Things general terminal; the security authentication platform is configured to determine reference device feature information of the target Internet of Things general terminal according to the unique identification code, and determine whether the target Internet of Things general terminal passes the security authentication according to the difference between the actual device feature information and the reference device feature information.

[0024] An Internet of Things general terminal authentication device, the device includes:

[0025] A collection module, configured to collect actual device feature information of the target Internet of Things (IoT) general terminal when establishing a communication connection with at least one target IoT general terminal;

[0026] A reading module, configured to read a unique identification code corresponding to the target IoT general terminal; the unique identification code is a code generated by pre-acquiring initial device feature information of the target IoT general terminal and extracting target data with a preset number of digits from the initial device feature information;

[0027] An authentication module, configured to request a security authentication platform to perform security authentication on the target IoT general terminal according to the unique identification code and the actual device feature information; the security authentication platform is configured to determine reference device feature information of the target IoT general terminal according to the unique identification code, and determine whether the target IoT general terminal passes the security authentication according to the difference between the actual device feature information and the reference device feature information.

[0028] An IoT communication terminal, comprising a memory and a processor, where the memory stores a computer program, and the processor implements the steps of the above method when executing the computer program.

[0029] A computer-readable storage medium, on which a computer program is stored, and the computer program implements the steps of the above method when being executed by a processor.

[0030] The above-mentioned Internet of Things (IoT) general-purpose terminal authentication system, method, device, and IoT communication terminal. In the IoT general-purpose terminal authentication system, the cloud platform receives the initial device feature information of at least one IoT general-purpose terminal, extracts the target data with a preset number of digits from the initial device feature information, generates a unique identification code that matches the IoT general-purpose terminal according to the target data, and then distributes the unique identification codes corresponding to each IoT general-purpose terminal to the IoT communication terminal for storage by the IoT communication terminal. Then, when the IoT communication terminal establishes a communication connection with at least one target IoT general-purpose terminal among the IoT general-purpose terminals, the IoT communication terminal collects the actual device feature information of the target IoT general-purpose terminal, and based on the unique identification code corresponding to the target IoT general-purpose terminal and the actual device feature information, requests the security authentication platform to determine whether the target IoT general-purpose terminal passes the security authentication according to the difference between the actual device feature information and the reference device feature information corresponding to the target IoT general-purpose terminal. Among them, the reference device feature information corresponding to the target IoT general-purpose terminal is determined according to the unique identification code corresponding to the target IoT general-purpose terminal. In this way, it is possible to verify in real time and accurately whether the IoT general-purpose terminals connected to the live network have changed, thereby avoiding the situation where the IoT general-purpose terminals deployed outdoors are tampered with and cannot be detected, improving the security level of the power IoT, and then realizing the secure transmission of communication data, and achieving a power IoT security technology that is self-controlled, secure and efficient, and has obvious cost advantages. This solution can be applied to the domestic power IoT security key technology in the power application scenario, conforms to the security characteristics of the power IoT, supports multiple communication systems, has a high communication rate, a large processing bandwidth, and a strong anti-interference ability, effectively fills the gap in the lack of power IoT security application terminals, and improves the overall competitiveness of the IoT security industry. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 It is a framework diagram of an IoT general-purpose terminal authentication system in an embodiment.

[0032] Figure 2 It is a timing diagram of an IoT terminal authentication process in an embodiment.

[0033] Figure 3 It is a schematic flowchart of an IoT general-purpose terminal authentication method in an embodiment.

[0034] Figure 4 It is a structural block diagram of an IoT general-purpose terminal authentication device in an embodiment.

[0035] Figure 5 It is an internal structure diagram of an IoT communication terminal in an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] In order to make the objectives, technical solutions, and advantages of the present application clearer and more understandable, the present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0037] An Internet of Things (IoT) general terminal authentication system provided by an embodiment of the present application can be applied to an application environment as Figure 1 shown. Among them, the IoT general terminal authentication system includes a cloud platform 110, an IoT communication terminal 120, and a security authentication platform 130. Among them, the IoT communication terminal 120 can communicate with the cloud platform 110 and the security authentication platform 130 through a network. The IoT communication terminal 120 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, IoT devices, and portable wearable devices. The IoT devices can be smart speakers, smart TVs, smart air conditioners, smart vehicle-mounted devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The cloud platform 110 and the security authentication platform 130 can be implemented by independent servers or a server cluster composed of multiple servers.

[0038] The cloud platform is used to receive the initial device feature information of at least one IoT general terminal, extract the target data with a preset number of digits in the initial device feature information; generate a unique identification code corresponding to the IoT general terminal according to the target data; and send the unique identification code corresponding to each IoT general terminal to the IoT communication terminal for storage by the IoT communication terminal.

[0039] Among them, the initial device feature information includes at least one of a device identification code, a media storage control address, a serial number, an operating system brand, an operating system serial number, and geographical location information.

[0040] In practical applications, the initial device feature information of the IoT general terminal can also be named as the power IoT general terminal information.

[0041] Among them, the IoT general terminal can refer to at least one of a temperature sensor, a humidity sensor, a light sensor, a pressure-sensitive sensor, and a displacement sensor with IoT connection function.

[0042] In a specific implementation, the IoT communication terminal can collect the initial device feature information of at least one IoT general terminal. Then, the IoT communication terminal sends the initial device feature information, such as a device identification code, a media storage control address, a serial number, an operating system brand, an operating system serial number, geographical location information, etc., to the cloud platform. Specifically, the IoT communication terminal can encrypt the above data using a national secret algorithm according to the requirements of the power industry, and then send the encrypted data packet to the cloud platform, thereby realizing the sending of the initial device feature information of the IoT general terminal to the cloud platform.

[0043] Among them, after receiving the initial device feature information of the Internet of Things general terminal, the cloud platform extracts the target data with a preset number of digits in the initial device feature information; then, the cloud platform generates a unique identification code that matches each Internet of Things general terminal according to the target data. The cloud platform sends the unique identification codes that match each Internet of Things general terminal to the Internet of Things communication terminal for storage by the Internet of Things communication terminal.

[0044] In specific implementation, after receiving the encrypted data packet sent by the Internet of Things communication terminal, the cloud platform decrypts the encrypted data packet to obtain the initial device feature information of the Internet of Things general terminal. Then, the cloud platform can generate a random code with a specified number of digits according to a preset random code generation algorithm; the cloud platform obtains the data code corresponding to the target data; the cloud platform splices the random code to the end of the data code to obtain the target code; the cloud platform encrypts the target code according to a preset code encryption algorithm to obtain the unique identification code corresponding to the Internet of Things general terminal, and sends the unique identification code corresponding to the Internet of Things general terminal to the Internet of Things communication terminal.

[0045] In the process of sending the unique identification codes corresponding to each Internet of Things general terminal to the Internet of Things communication terminal, the cloud platform can use a preset key to encrypt the unique identification codes corresponding to the Internet of Things general terminal to generate an encryption certificate corresponding to the unique identification code; the cloud platform sends the key and the encryption certificate to the Internet of Things communication terminal.

[0046] In specific implementation, after receiving the key and the encryption certificate sent by the cloud platform, the Internet of Things communication terminal can use the key to decrypt the encryption certificate to obtain the unique identification code corresponding to the Internet of Things general terminal; save the unique identification code corresponding to the Internet of Things general terminal to a preset storage area.

[0047] In practical applications, the Internet of Things communication terminal can support the conversion of multiple interfaces such as RS232, RS485, E1, and RJ45 into an Ethernet interface for output. The switching capacity is 100 Mbps. At the same time, the Internet of Things communication terminal supports the conversion of multiple protocols and interface types, protocol conversion functions, and data exchange functions. The switching capacity can reach 100 Mbps in the multi-protocol concurrent conversion mode.

[0048] The Internet of Things communication terminal is powered by alternating current, the external power supply voltage can be 100 - 240V, and the rated power can be 60W.

[0049] The Internet of Things communication terminal is used to collect the actual device feature information of at least one target Internet of Things general terminal among various Internet of Things general terminals when establishing a communication connection with the target Internet of Things general terminal; and request the security authentication platform to perform security authentication on the target Internet of Things general terminal according to the unique identification code corresponding to the target Internet of Things general terminal and the actual device feature information.

[0050] In specific implementation, when the Internet of Things communication terminal establishes a communication connection with the target Internet of Things general terminal, the Internet of Things communication terminal can collect the actual device feature information of the target Internet of Things general terminal; then, the Internet of Things communication terminal requests the security authentication platform to perform security authentication on the target Internet of Things general terminal through the unique identification code corresponding to the target Internet of Things general terminal and the actual device feature information pre-distributed by the cloud platform through the security authentication SDK installed locally.

[0051] The security authentication platform is used to judge whether the target Internet of Things general terminal passes the security authentication according to the difference between the actual device feature information and the initial device feature information corresponding to the target Internet of Things general terminal; the initial device feature information corresponding to the target Internet of Things general terminal is determined according to the unique identification code corresponding to the target Internet of Things general terminal.

[0052] In specific implementation, the Internet of Things communication terminal can send a security authentication request for the target Internet of Things general terminal to the security authentication platform based on the unique identification code corresponding to the target Internet of Things general terminal and the actual device feature information through the API interface of the security authentication SDK. After receiving the security authentication request, the security authentication platform can determine the initial device feature information corresponding to the target Internet of Things general terminal according to the unique identification code corresponding to the target Internet of Things general terminal; then, the cloud platform uses the initial device feature information corresponding to the target Internet of Things general terminal to perform real-time comparison with the actual device feature information, so as to verify in real time whether the general terminal connected to the live network has changed, and further judge whether the target Internet of Things general terminal passes the security authentication.

[0053] In practical applications, the cloud platform also includes a platform security module and an application system security module; parameters can be set, the working status can be monitored, fault diagnosis and data statistics can be performed on the platform security module and the application system security module respectively, which fully reflects the convenient operation performance of the system. Both the platform security module and the application system security module include functions such as permission management, resource management, remote control, device monitoring and data statistics, adopt the B / S architecture, have a friendly human-computer interface and convenient operation.

[0054] In the technical solution of this embodiment, the cloud platform receives the initial device feature information of at least one IoT general-purpose terminal, and extracts the target data with a preset number of digits in the initial device feature information; according to the target data, generates a unique identification code that matches the IoT general-purpose terminal; then sends the unique identification codes corresponding to each IoT general-purpose terminal to the IoT communication terminal for storage by the IoT communication terminal; then, when the IoT communication terminal establishes a communication connection with at least one target IoT general-purpose terminal among each IoT general-purpose terminal, the IoT communication terminal collects the actual device feature information of the target IoT general-purpose terminal; and according to the unique identification code corresponding to the target IoT general-purpose terminal and the actual device feature information, requests the security authentication platform to determine whether the target IoT general-purpose terminal passes the security authentication according to the difference between the actual device feature information and the reference device feature information corresponding to the target IoT general-purpose terminal; wherein, the reference device feature information corresponding to the target IoT general-purpose terminal is determined according to the unique identification code corresponding to the target IoT general-purpose terminal; in this way, it can be realized to verify in real time and accurately whether the IoT general-purpose terminals connected to the live network have changed, thereby avoiding the situation that the IoT general-purpose terminals deployed outdoors are tampered with and cannot be detected in time, improving the security level of the power IoT, and then realizing the secure transmission of communication data, and realizing the power IoT security technology with independent control, safety and efficiency, and obvious cost advantages. This solution can be applied to the domestic power IoT security key technology in the power application scenario, conforms to the security characteristics of the power IoT, supports multiple communication systems, has a high communication rate, a large processing bandwidth, and a strong anti-interference ability, effectively fills the gap of the lack of power IoT security application terminals, and improves the overall competitiveness of the IoT security industry.

[0055] In another embodiment, the IoT communication terminal is used to send a security authentication request for a target IoT general-purpose terminal to the security authentication platform; the security authentication request carries the actual device feature information of the target IoT general-purpose terminal and the unique identification code corresponding to the target IoT general-purpose terminal. The security authentication platform is used to respond to the security authentication request, determine the initial device feature information corresponding to the target IoT general-purpose terminal according to the unique identification code corresponding to the target IoT general-purpose terminal; compare the difference between the initial device feature information and the actual device feature information to obtain a feature information comparison result; send the security authentication result generated based on the feature information comparison result to the IoT communication terminal; the security authentication result is used to represent whether the target IoT general-purpose terminal passes the security authentication.

[0056] For the convenience of understanding by those skilled in the art, Figure 2Also provided is a timing diagram of the authentication process for Internet of Things terminals; in practical applications, the target Internet of Things communication terminal can input a security authentication instruction to the security authentication SDK by calling the authentication API (application programming interface) provided by the security authentication SDK (software development kit). In response to the security authentication instruction, the security authentication SDK reads the credential (i.e., the unique identification code corresponding to the target Internet of Things general terminal), and encapsulates it together with the actual device feature information of the target Internet of Things general terminal into a verification package and sends it to the security authentication platform.

[0057] The security authentication platform then performs security identification on the received verification package; among them, the security authentication platform parses the received verification package to obtain the credential of the target Internet of Things general terminal and the actual device feature information of the target Internet of Things general terminal; then, the security authentication platform determines the initial device feature information corresponding to the target Internet of Things general terminal according to the unique identification code corresponding to the target Internet of Things general terminal. Then, the security authentication platform compares the difference between the initial device feature information and the actual device feature information to obtain the feature information comparison result, that is, the authentication result; and sends the security authentication result generated based on the feature information comparison result to the Internet of Things communication terminal; the security authentication result is used to represent whether the target Internet of Things general terminal passes the security authentication.

[0058] The technical solution of this embodiment can realize real-time and accurate verification of whether the Internet of Things general terminals connected to the live network have changed, thereby avoiding the situation that the Internet of Things general terminals deployed outdoors are tampered with and cannot be detected in time, improving the security level of the power Internet of Things, and then realizing the secure transmission of communication data, and realizing a power Internet of Things security technology with independent control, security and efficiency, and obvious cost advantages.

[0059] In another embodiment, the Internet of Things communication terminal is further configured to collect the initial device feature information of at least one Internet of Things general terminal; use a preset feature information encryption algorithm to encrypt the initial device feature information of each Internet of Things general terminal to obtain the encrypted device feature information corresponding to each Internet of Things general terminal; and send the encrypted device feature information corresponding to each Internet of Things general terminal to the cloud platform.

[0060] Among them, the feature information encryption algorithm may refer to an algorithm for encrypting device feature information.

[0061] In specific implementation, the Internet of Things communication terminal is installed with this security encryption program; the security encryption program is used to perform security encryption operations on the data sent by the Internet of Things terminal. The security encryption operation complies with the X.509 standard, uses BASE-64 encoding, adopts a five-category security certificate mechanism, encrypts IP layer communication, complies with IPsec, the ciphertext uses an encapsulated security payload, the number of encrypted terminals supported in the same network is not less than 255, the maximum number of concurrent encrypted tunnels > 200, and the working secret key survival period is 1 - 24 hours.

[0062] After the Internet of Things communication terminal collects the initial device feature information of at least one Internet of Things general terminal, the Internet of Things communication terminal can use the data encryption algorithm in the security encryption program to encrypt the initial device feature information of each Internet of Things general terminal, and obtain the encrypted device feature information corresponding to each Internet of Things general terminal. Then, the Internet of Things communication terminal sends the encrypted device feature information corresponding to each Internet of Things general terminal to the cloud platform.

[0063] In the technical solution of this embodiment, by encrypting the initial device feature information of the Internet of Things general terminal and then sending it to the cloud platform, the Internet of Things communication terminal can improve the security of data transmission between the Internet of Things communication terminal and the cloud platform.

[0064] In another embodiment, the Internet of Things general terminal is used to collect Internet of Things sensing data; the Internet of Things general terminal is also used to send the collected Internet of Things sensing data to the standardized data interface of the Internet of Things communication terminal according to a preset transmission protocol.

[0065] Among them, the standardized data interface is used to transfer the Internet of Things sensing data to the operating system of the Internet of Things communication terminal for the operating system to perform data processing operations on the Internet of Things sensing data.

[0066] In specific implementation, the Internet of Things general terminal can collect Internet of Things sensing data; for example, Internet of Things sensors such as temperature sensors, humidity sensors, light sensors, pressure-sensitive sensors, and displacement sensors with Internet of Things connection functions send the real-time collected data as Internet of Things sensing data to the standardized data interface of the Internet of Things communication terminal according to a preset transmission protocol.

[0067] After the standardized data interface of the Internet of Things communication terminal receives the Internet of Things sensing data, the standardized data interface can transfer the collected Internet of Things sensing data to the operating system running on the Internet of Things communication terminal, so that the operating system can use the Internet of Things sensing data to perform a series of data processing operations.

[0068] In the technical solution of this embodiment, by using the standardized data interface, the Internet of Things communication terminal can receive the Internet of Things sensing data collected by different Internet of Things general terminals, which can improve the usage range and versatility of the Internet of Things communication terminal.

[0069] In one embodiment, as Figure 3 shown, a method for authenticating an Internet of Things general terminal is provided. Taking the method applied to the Internet of Things communication terminal in Figure 1 as an example, the method includes the following steps:

[0070] Step S310, when establishing a communication connection with at least one target Internet of Things general terminal, collect the actual device feature information of the target Internet of Things general terminal.

[0071] Step S320: Read the unique identification code corresponding to the target IoT general terminal; the unique identification code is generated by pre-acquiring the initial device feature information of the target IoT general terminal and extracting target data with a preset number of digits from the initial device feature information.

[0072] Step S330: Request the security authentication platform to perform security authentication on the target IoT general terminal according to the unique identification code and the actual device feature information; the security authentication platform is used to determine the reference device feature information of the target IoT general terminal according to the unique identification code, and judge whether the target IoT general terminal passes the security authentication according to the difference between the actual device feature information and the reference device feature information.

[0073] It should be noted that the specific limitations of the above steps can be referred to the specific limitations of the IoT communication terminal above, and will not be elaborated here.

[0074] It should be understood that although the steps in the flowcharts involved in the above embodiments are displayed in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps or stages in other steps.

[0075] Based on the same inventive concept, an embodiment of the present application also provides an IoT general terminal authentication device for implementing the above-mentioned IoT general terminal authentication method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the following IoT general terminal authentication devices can be referred to the limitations of the IoT general terminal authentication method above, and will not be elaborated here.

[0076] In one embodiment, as Figure 4 shown, an IoT general terminal authentication device is provided, including:

[0077] A collection module 410, configured to collect the actual device feature information of the target IoT general terminal when establishing a communication connection with at least one target IoT general terminal.

[0078] A reading module 420 is configured to read a unique identification code corresponding to the target Internet of Things (IoT) general terminal; the unique identification code is generated by pre-acquiring initial device feature information of the target IoT general terminal and extracting target data with a preset number of digits from the initial device feature information.

[0079] An authentication module 430 is configured to request a security authentication platform to perform security authentication on the target IoT general terminal according to the unique identification code and the actual device feature information; the security authentication platform is configured to determine benchmark device feature information of the target IoT general terminal according to the unique identification code, and determine whether the target IoT general terminal passes the security authentication according to the difference between the actual device feature information and the benchmark device feature information.

[0080] Each module in the above IoT general terminal authentication device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in a processor in a computer device in hardware form or be independent of the processor, or can be stored in a memory in the computer device in software form, so that the processor can call and execute operations corresponding to each of the above modules.

[0081] In one embodiment, a computer device is provided. The computer device can be an IoT communication terminal, and its internal structure diagram can be as shown in Figure 5 The computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements an IoT general terminal authentication method. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the outer shell of the computer device, or an external keyboard, a touchpad, or a mouse, etc.

[0082] Those skilled in the art can understand that Figure 5 the structure shown in is only a block diagram of a part of the structure related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.

[0083] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the processor is caused to execute the steps of the above-mentioned method for authenticating general IoT terminals. The steps of the method for authenticating general IoT terminals herein may be the steps of the method for authenticating general IoT terminals in each of the above embodiments.

[0084] In one embodiment, a computer-readable storage medium is provided, storing a computer program. When the computer program is executed by the processor, the processor is caused to execute the steps of the above-mentioned method for authenticating general IoT terminals. The steps of the method for authenticating general IoT terminals herein may be the steps of the method for authenticating general IoT terminals in each of the above embodiments.

[0085] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the processor is caused to execute the steps of the above-mentioned method for authenticating general IoT terminals. The steps of the method for authenticating general IoT terminals herein may be the steps of the method for authenticating general IoT terminals in each of the above embodiments.

[0086] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties.

[0087] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0088] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0089] The above-described embodiments only represent several implementation manners of this application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of this application. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application should be subject to the appended claims.

Claims

1. An Internet of Things (IoT) general - terminal authentication system, characterized in that, it includes a cloud platform, an IoT communication terminal, and a security authentication platform; The cloud platform is used to receive the initial device feature information of at least one IoT general - terminal, and extract the target data with a preset number of digits from the initial device feature information; According to the target data, generate a unique identification code corresponding to the IoT general - terminal; Send the unique identification code corresponding to each IoT general - terminal to the IoT communication terminal for storage by the IoT communication terminal; The IoT communication terminal is used to collect the actual device feature information of at least one target IoT general - terminal when establishing a communication connection with the at least one target IoT general - terminal among the IoT general - terminals; By invoking the authentication application programming interface provided by the security authentication SDK, input a security authentication instruction to the security authentication SDK; the security authentication SDK is used to respond to the security authentication instruction, read the unique identification code corresponding to the target IoT general - terminal, and encapsulate it together with the actual device feature information of the target IoT general - terminal into a verification package and send it to the security authentication platform; The security authentication platform is used to receive the verification package, obtain the unique identification code of the target IoT general - terminal and the actual device feature information of the target IoT general - terminal; according to the unique identification code corresponding to the target IoT general - terminal, determine the reference device feature information corresponding to the target IoT general - terminal; The cloud platform is further used to perform real - time comparison between the reference device feature information corresponding to the target IoT general - terminal and the actual device feature information to verify in real time whether the target IoT general - terminal has changed and determine whether the target IoT general - terminal passes the security authentication.

2. The IoT general - terminal authentication system according to claim 1, characterized in that, The IoT communication terminal is used to send a security authentication request for the target IoT general - terminal to the security authentication platform; the security authentication request carries the actual device feature information of the target IoT general - terminal and the unique identification code corresponding to the target IoT general - terminal; The security authentication platform is used to respond to the security authentication request, determine the reference device feature information corresponding to the target IoT general - terminal according to the unique identification code corresponding to the target IoT general - terminal; compare the difference between the reference device feature information and the actual device feature information to obtain a feature information comparison result; send a security authentication result generated based on the feature information comparison result to the IoT communication terminal; the security authentication result is used to indicate whether the target IoT general - terminal passes the security authentication.

3. The IoT general - terminal authentication system according to claim 1, characterized in that, The cloud platform is used to generate a random code with a specified number of digits according to a preset random code generation algorithm; obtain the data code corresponding to the target data; splice the random code to the end of the data code to obtain a target code; and encrypt the target code according to a preset code encryption algorithm to obtain the unique identification code corresponding to the Internet of Things general terminal.

4. The Internet of Things general terminal authentication system according to claim 1, wherein, the cloud platform is used to encrypt the unique identification code corresponding to the Internet of Things general terminal by using a preset key to generate an encryption certificate corresponding to the unique identification code; and send the key and the encryption certificate to the Internet of Things communication terminal.

5. The Internet of Things general terminal authentication system according to claim 4, wherein, the Internet of Things communication terminal is used to receive the key and the encryption certificate sent by the cloud platform; decrypt the encryption certificate by using the key to obtain the unique identification code corresponding to the Internet of Things general terminal; save the unique identification code corresponding to the Internet of Things general terminal to a preset storage area.

6. The Internet of Things general terminal authentication system according to claim 1, wherein, the Internet of Things communication terminal is further used to collect the initial device feature information of at least one Internet of Things general terminal; encrypt the initial device feature information of each Internet of Things general terminal by using a preset feature information encryption algorithm to obtain the encrypted device feature information corresponding to each Internet of Things general terminal; and send the encrypted device feature information corresponding to each Internet of Things general terminal to the cloud platform.

7. An Internet of Things general terminal authentication method, wherein, the method includes: when establishing a communication connection with at least one target Internet of Things general terminal, collecting the actual device feature information of the target Internet of Things general terminal; inputting a security authentication instruction to the security authentication SDK by calling the authentication application programming interface provided by the security authentication SDK; responding to the security authentication instruction by the security authentication SDK, reading the unique identification code corresponding to the target Internet of Things general terminal, and encapsulating it together with the actual device feature information of the target Internet of Things general terminal into a verification packet and sending it to the security authentication platform; the unique identification code is a code generated by previously obtaining the initial device feature information of the target Internet of Things general terminal and extracting target data with a preset number of digits from the initial device feature information; the security authentication platform is used to determine the reference device feature information of the target Internet of Things general terminal according to the unique identification code, and judge whether the target Internet of Things general terminal passes the security authentication according to the difference between the actual device feature information and the reference device feature information.

8. An Internet of Things general terminal authentication device, wherein, the device includes: a collection module, configured to collect the actual device feature information of the target Internet of Things general terminal when establishing a communication connection with at least one target Internet of Things general terminal; A reading module, configured to input a security authentication instruction to the security authentication SDK by calling an authentication application programming interface provided by the security authentication SDK; and read a unique identification code corresponding to the target Internet of Things (IoT) general terminal through the security authentication SDK's response to the security authentication instruction; the unique identification code is a code generated by pre-acquiring initial device feature information of the target IoT general terminal and extracting target data with a preset number of digits from the initial device feature information. An authentication module, configured to encapsulate the unique identification code together with the actual device feature information of the target IoT general terminal into a verification packet and send it to the security authentication platform; request the security authentication platform to perform security authentication on the target IoT general terminal according to the unique identification code and the actual device feature information; the security authentication platform is configured to determine reference device feature information of the target IoT general terminal according to the unique identification code, and judge whether the target IoT general terminal passes the security authentication according to the difference between the actual device feature information and the reference device feature information.

9. An IoT communication terminal, comprising a memory and a processor, where the memory stores a computer program, characterized in that when the processor executes the computer program, the steps of the method according to claim 7 are implemented.

10. A computer-readable storage medium, on which a computer program is stored, characterized in that when the computer program is executed by a processor, the steps of the method according to claim 7 are implemented.

Citation Information

Patent Citations

  • Safe access method, device and equipment for Internet of Things equipment and medium

    CN114268508A

  • Cloud access authentication method, device and system for lightweight ubiquitous power Internet of Things terminal

    CN114500003A