Access Method, Access System, Computer Device and Medium of Internet of Things Terminal Devices
By generating and managing authorization codes on the authorization end, combined with the decryption and verification mechanism of the resource server, the problem of users privately manufacturing and operating IoT terminal devices is solved, and the effective management of access to resource server devices and protecting the rights and interests of software and hardware developers is achieved.
Patent Information
- Application Number
- CN202211161447.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-23
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2042-09-23
AI Technical Summary
In the prior art, users privately manufacture and operate IoT terminal devices, resulting in damage to the rights and interests of software and hardware developers. How to effectively manage resource servers and IoT terminal devices connected to them has become an urgent problem for technicians.
By using preset encryption tools on the authorization side to generate an authorization code, and store the signature code and authorization code in the authorization table, restricting the access of the IoT terminal device to the resource server. The resource server decrypts the received authorization code, verifies its legality, and determines whether the device has been registered based on the registry, so as to determine the legality and registration control of the IoT terminal device.
It effectively protects the rights and interests of software and hardware developers, prevents users from abuse of resource servers, and realizes restrictions and management of IoT terminal devices connected to resource servers, improving the security and stability of the system.
Smart Images

Figure CN115514567B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of the Internet of Things, and in particular to an access method, an access system, a computer device, and a medium for an Internet of Things terminal device. Background Art
[0002] In the related art, software and hardware developers deliver a predetermined number of Internet of Things terminal devices and resource servers to users according to user requirements. The users manage and operate the Internet of Things terminal devices through the resource servers, accept the registration of the Internet of Things terminal devices, and authorize the Internet of Things terminal devices, so that the Internet of Things terminal devices can obtain resource services by accessing the resource service manager.
[0003] However, there is a situation where users privately manufacture and operate Internet of Things terminal devices, which damages the rights and interests of software and hardware developers. How to manage the resource server and the Internet of Things terminal devices accessing the resource server has become a technical problem that needs to be solved urgently by those skilled in the art. Summary of the Invention
[0004] To solve at least one of the above problems, a first aspect of the present invention provides an access method for an Internet of Things terminal device, which is applied to an authorization end and includes:
[0005] Generating an authorization code using a preset encryption tool according to a feature code generated by the Internet of Things terminal device, and storing the feature code and the authorization code in an authorization table, where the feature code includes the identity identifier of the Internet of Things terminal device;
[0006] Sending the authorization code to the Internet of Things terminal device, so that the Internet of Things terminal device sends a registration request including the authorization code to the resource server;
[0007] Sending the feature code of the Internet of Things terminal device to the resource server, so that the resource server decrypts the authorization code using a decryption tool corresponding to the encryption tool in response to the registration request to obtain a decrypted feature code, determines whether the decrypted feature code has a matching feature code to determine whether the Internet of Things terminal device is legal. If it is not legal, a first invalid prompt message is returned. Otherwise, it is determined whether the decrypted feature code has been registered according to the registration table stored in the resource server. If it has been registered, a second invalid prompt message is returned. If it has not been registered, the Internet of Things terminal device is registered and the feature code is stored in the registration table.
[0008] Further, before generating an authorization code using a preset encryption tool according to a feature code generated by the Internet of Things terminal device and storing the feature code and the authorization code in an authorization table, the access method further includes: receiving the registration quantity of the Internet of Things terminal devices that can be registered by the resource server;
[0009] The step of generating an authorization code using a preset encryption tool based on the feature code generated by the IoT terminal device and storing the feature code and the authorization code in an authorization table further includes: determining whether the number of IoT terminal devices registered with the resource server in the authorization table has reached the registration quantity, and if it has reached the registration quantity, returning an expansion prompt message.
[0010] Further, the feature code further includes the sales identifier of the IoT terminal device. The step of generating an authorization code using a preset encryption tool based on the feature code generated by the IoT terminal device and storing the feature code and the authorization code in an authorization table further includes:
[0011] Determining whether the IoT terminal device is a normal sale according to the sales identifier. If the IoT terminal device is an abnormal sale, returning a third invalid prompt message; otherwise, generating an authorization code using a preset encryption tool according to the identity identifier of the IoT terminal device.
[0012] Further, the sales identifier further includes a sales type. The authorization end further includes an authorization information table, and the authorization information table includes at least one sales type and an authorization information item corresponding to the sales type;
[0013] The step of generating an authorization code using a preset encryption tool according to the identity identifier of the IoT terminal device further includes: obtaining a corresponding authorization information item according to the authorization information table and the sales identifier of the IoT terminal device, and generating an authorization code using a preset encryption tool according to the identity identifier of the IoT terminal device and the authorization information item;
[0014] The step of sending the feature code of the IoT terminal device to the resource server further includes: sending the identity identifier and the authorization information item of the IoT terminal device to the resource server, so that the resource server uses the decryption tool to decrypt the authorization code in response to the registration request to obtain a decrypted identity identifier and a decrypted authorization information item, determining whether the decrypted identity identifier has a matching identity identifier to determine whether the IoT terminal device is legal. If it is not legal, returning a first invalid prompt message; otherwise, determining whether the decrypted identity identifier has been registered according to the registration table stored in the resource server. If it has been registered, returning a second invalid information prompt; if it has not been registered, determining whether the decrypted authorization information item has a matching authorization information item to determine whether the IoT terminal device is valid. If it is invalid, returning a fourth invalid prompt message; otherwise, registering the IoT terminal device and storing the identity identifier in the registration table.
[0015] Further, the decryption tool and the encryption tool are a pair of asymmetric keys, where,
[0016] The encryption tool includes a private key, and the decryption tool includes a public key.
[0017] A second aspect of the present invention provides an access method for an IoT terminal device, which is applied to the IoT terminal device and includes:
[0018] Generating a feature code and sending an authorization request including the feature code to an authorization end, so that the authorization end uses a preset encryption tool to generate the authorization code according to the feature code, stores the feature code and the authorization code in an authorization table, sends the authorization code to the IoT terminal device, and sends the feature code to a resource server, where the feature code includes the identity identifier of the IoT terminal device;
[0019] Receiving and storing the authorization code, and sending a registration request including the authorization code to the resource server, so that the resource server uses a decryption tool corresponding to the encryption tool to decrypt the authorization code in response to the registration request to verify the authorization code according to the received feature code. If the verification is successful, the IoT terminal device is registered and the feature code is stored in the registration table.
[0020] Further, receiving a first invalid prompt message, where the first invalid prompt message is generated when the decryption feature code obtained by the resource server according to the decrypted authorization code does not match the feature code;
[0021] Or
[0022] Receiving a second invalid prompt message, where the second invalid prompt message is generated when the decryption feature code obtained by the resource server according to the decrypted authorization code already exists in the registration table stored by the resource server;
[0023] Or
[0024] Receiving an expansion prompt message, where the authorization end further includes the registration quantity of the IoT terminal devices that can be registered by the resource server, and the expansion prompt message is generated when the authorization end determines that the quantity of the IoT terminal devices already registered by the resource server in the authorization table has reached the registration quantity;
[0025] Or
[0026] Receiving a third invalid prompt message, where the feature code further includes the sales identifier of the IoT terminal device, and the third invalid prompt message is generated when the authorization end determines that the sales identifier of the IoT terminal device is an abnormal sale;
[0027] Or
[0028] Receive a fourth invalid prompt message. The feature code further includes a sales identifier of the IoT terminal device, and the sales identifier further includes a sales type. The authorization end obtains a corresponding authorization information item according to the sales type, and uses the encryption tool to generate the authorization code according to the identity identifier and the authorization information item. The fourth invalid prompt message is generated when the decryption authorization information obtained by the resource server using the decryption tool does not match the authorization information item.
[0029] Further, after receiving and storing the authorization code and sending a registration request including the authorization code to the resource server, the access method further includes:
[0030] Send a resource request including the authorization code and resource information to the resource server, so that the resource server decrypts the authorization code using the decryption tool in response to the resource request to verify the authorization code;
[0031] Receive resource content corresponding to the resource information, where the resource content is sent by the resource server after the authorization code is successfully verified.
[0032] A third aspect of the present invention provides an access method for an IoT terminal device, which is applied to a resource server and includes:
[0033] Receive a feature code sent by an authorization end, where the feature code includes an identity identifier of the IoT terminal device;
[0034] Receive a registration request sent by the IoT terminal device, where the registration request is generated by the authorization end according to the feature code using a preset encryption tool;
[0035] Use a decryption tool corresponding to the encryption tool to decrypt the authorization code to obtain a decrypted feature code, determine whether the decrypted feature code has a matching feature code to determine whether the IoT terminal device is legal. If it is not legal, return a first invalid prompt message. Otherwise, judge whether the decrypted feature code has been registered according to the registration table stored in the resource server. If it has been registered, return a second invalid prompt message. If it has not been registered, register the IoT terminal device and store the feature code in the registration table.
[0036] Further, after using the decryption tool corresponding to the encryption tool to decrypt the authorization code to obtain the decrypted feature code, the access method further includes:
[0037] Receive a resource request sent by the IoT terminal device, where the resource request is a resource request including the authorization code and resource information;
[0038] Use the decryption tool to decrypt the authorization code to obtain a decryption feature code, and verify the decryption feature code;
[0039] In response to successful verification of the decryption feature code, send the resource content corresponding to the resource information to the IoT terminal device.
[0040] The fourth aspect of the present invention provides an access system, including:
[0041] An authorization end, including an authorization table and an encryption tool;
[0042] A resource server, including a registration table, a decryption tool corresponding to the encryption tool, and a verification unit; and
[0043] At least one IoT terminal device, including an identity identifier and a feature code generation unit;
[0044] The authorization end is configured to:
[0045] According to the feature code generated by the feature code generation unit based on the identity identifier, use the encryption tool to generate an authorization code and store the feature code and the authorization code in the authorization table;
[0046] Send the authorization code to the IoT terminal device, so that the IoT terminal device sends a registration request including the authorization code to the resource server;
[0047] Send the feature code of the IoT terminal device to the resource server, so that the resource server, in response to the registration request, uses the decryption tool to decrypt the authorization code to obtain a decryption feature code, uses the verification unit to determine whether the decryption feature code has a matching feature code to determine whether the IoT terminal device is legal. If it is not legal, return a first invalid prompt message. Otherwise, according to the registration table, determine whether the decryption feature code has been registered. If it has been registered, return a second invalid prompt message. If it has not been registered, register the IoT terminal device and store the feature code in the registration table.
[0048] The fifth aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the method described in the first aspect;
[0049] Or
[0050] When the program is executed by a processor, it implements the method described in the second aspect;
[0051] Or
[0052] When the program is executed by a processor, it implements the method described in the third aspect.
[0053] The sixth embodiment of the present invention provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor.
[0054] When the processor executes the program, it implements the method described in the first aspect;
[0055] Or
[0056] When the processor executes the program, it implements the method described in the second aspect;
[0057] Or
[0058] When the processor executes the program, it implements the method described in the third aspect.
[0059] The beneficial effects of the present invention are as follows:
[0060] In view of the existing problems, the present invention formulates an access method, an access system, a computer device, and a medium for an IoT terminal device. By setting an authorization end in response to the operation control of software and hardware developers, the legitimacy of the IoT terminal device is judged, and the access of the IoT terminal device to the resource server is restricted by an authorization code. Then, the resource server verifies the authorization code to control the registration of the IoT terminal device on the resource server, so as to achieve the two-way limitation between the authorization end - IoT terminal device, the authorization end - resource server, and the IoT terminal device - resource server; that is, software and hardware developers supervise the resource server and the IoT terminal device through the authorization end, and restrict the IoT terminal devices accessing the resource server, effectively protecting the rights and interests of software and hardware developers, making up for the problems existing in the related technologies, and having a wide application prospect. BRIEF DESCRIPTION OF THE DRAWINGS
[0061] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0062] Figure 1 Show a flowchart of the access method described in an embodiment of the present invention;
[0063] Figure 2 Show a block diagram of the access system described in an embodiment of the present invention;
[0064] Figure 3 Show an access swimlane diagram of the access method described in an embodiment of the present invention;
[0065] Figure 4Flowchart showing the access method according to another embodiment of the present invention;
[0066] Figure 5 Flowchart showing the access method according to another embodiment of the present invention;
[0067] Figure 6 Schematic structural diagram of a computer device according to another embodiment of the present invention. Detailed implementation manners
[0068] To more clearly illustrate the present invention, the present invention will be further described below in conjunction with preferred embodiments and the accompanying drawings. Similar components in the drawings are denoted by the same reference numerals. Those skilled in the art should understand that the content specifically described below is illustrative rather than restrictive, and should not be used to limit the protection scope of the present invention.
[0069] In view of the above situation, the inventors pointed out after a large amount of research and experiments that in the related art, software and hardware developers deliver resource servers and IoT terminals. During the process of users operating IoT terminal devices through resource servers, the resource servers authorize the access of IoT terminal devices, resulting in the lack of operation monitoring by software and hardware developers and leading to the abuse of resource servers by users.
[0070] According to the above problems and the reasons causing these problems, as Figure 1 shown, an embodiment of the present invention provides an access method for IoT terminal devices applied to an authorization end, including:
[0071] Using a preset encryption tool to generate an authorization code according to the feature code generated by the IoT terminal device and storing the feature code and the authorization code in an authorization table, where the feature code includes the identity identifier of the IoT terminal device;
[0072] Sending the authorization code to the IoT terminal device, so that the IoT terminal device sends a registration request including the authorization code to the resource server;
[0073] Sending the feature code of the IoT terminal device to the resource server, so that the resource server decrypts the authorization code using a decryption tool corresponding to the encryption tool in response to the registration request to obtain a decrypted feature code, and determines whether the decrypted feature code has a matching feature code to determine whether the IoT terminal device is legal. If it is not legal, a first invalid prompt message is returned. Otherwise, according to the registration table stored in the resource server, it is determined whether the decrypted feature code has been registered. If it has been registered, a second invalid prompt message is returned. If it has not been registered, the IoT terminal device is registered and the feature code is stored in the registration table.
[0074] In this embodiment, an authorization end is set to respond to the operation control of software and hardware developers, judge the legality of the IoT terminal device, and limit the access of the IoT terminal device to the resource server through an authorization code. Then, the resource server verifies the authorization code to control the registration of the IoT terminal device on the resource server, so as to realize the two-way limitation between the authorization end - IoT terminal device, the authorization end - resource server, and the IoT terminal device - resource server; that is, software and hardware developers supervise the resource server and IoT terminal devices through the authorization end, and restrict the IoT terminal devices accessing the resource server, effectively protecting the rights and interests of software and hardware developers. Moreover, this embodiment sends a prompt message to the IoT terminal device to prompt the reason for non-access, effectively improving the user experience.
[0075] In a specific example, as Figure 2 shown, the access system of this embodiment includes an authorization end, a resource server, and at least one IoT terminal device. Among them, the authorization end is a terminal used by software and hardware developers, which can be a mobile terminal, such as intelligent mobile devices like smartphones and smart tablets; it can also be a web end, such as a web page; it can also be a pc end, such as a computer device; the resource server is a server that provides resource services, which can be a locally set server, or a remote server or a cloud server, and responds to the operation actions of the first user who operates the resource server; the IoT terminal device is a terminal IoT device, such as a sensing device that can access the network, a smart tablet, and a miniaturized dedicated computing device, etc., and responds to the operation actions of the second user who uses the IoT terminal device.
[0076] As Figure 3 shown, the following takes an IoT terminal device accessing the resource server as an example for illustration.
[0077] The first step is that the IoT terminal device generates a feature code, and the feature code includes the identity identifier of the IoT terminal device.
[0078] In this embodiment, the IoT terminal device generates a feature code according to the identity identifier that uniquely represents the device identity. The identity identifier is, for example, an identification such as a factory code, a MAC address, etc. The feature code is generated by a feature code generation unit set by the developer or distributor who manufactures or produces the IoT terminal device. This application does not make specific limitations on the identity identifier, as well as the generation method and process of the feature code, as long as the identity identifier uniquely represents the IoT terminal device and can generate a feature code, which will not be elaborated here.
[0079] The second step is that the IoT terminal device sends the feature code to the authorization end.
[0080] In this embodiment, the IoT terminal device sends the generated feature code to the authorization end, and the authorization end operated by the software and hardware developer issues an authorization code to the IoT terminal device to authorize the IoT terminal device to access the resource server, effectively monitoring the resource server operated by the user and the IoT terminal devices accessing it, so as to safeguard its own rights and interests. It should be noted that those skilled in the art should understand that the software and hardware developers described in this application can be the hardware and software developers who provide the resource server, IoT terminal device and operation software to the user, or can be the software developers who only provide at least the operation software, all within the protection scope of this application.
[0081] In this embodiment, the connection method between the IoT terminal device and the authorization end is not specifically limited. The IoT terminal device and the authorization end are connected through a wired or wireless network, or through a non-network method. For example, if the IoT terminal device is connected to the resource server through an internal local area network and the IoT terminal device does not access the external network and cannot establish a network connection with the authorization end, then other connection methods such as a mobile communication system are used for the interaction of the feature code and the authorization code. Those skilled in the art should select the connection method between the IoT terminal device and the authorization end according to actual application requirements, with the design criterion of realizing the interaction of the feature code and the authorization code between the two, all within the protection scope of this application, and will not be elaborated here.
[0082] In the third step, the authorization end uses a pre-set encryption tool to generate an authorization code based on the feature code generated by the IoT terminal device and stores the feature code and the authorization code in the authorization table.
[0083] In this embodiment, the authorization end issues an authorization code to the IoT terminal device so that the IoT terminal device can access the resource server, thereby realizing the monitoring of the operating status of the resource server and the IoT terminals accessing it. Specifically, the authorization end encrypts the feature code with a pre-set encryption tool to generate an authorization code, and the IoT terminal device accesses the resource server through this authorization code; that is, the monitoring of the resource server and the IoT terminal devices accessing it is realized through the authorization code generated by the authorization end.
[0084] At the same time, the authorization end receives the feature code and generates an authorization code, and establishes an authorization table at the authorization end. The authorization table includes the feature code and the authorization code corresponding to the feature code, so as to facilitate the further monitoring of the IoT terminal devices accessing the resource server by the authorization end. It should be noted that those skilled in the art should understand that if the authorization end faces multiple resource servers and IoT terminal devices respectively accessing the corresponding resource servers, the established authorization table is set corresponding to the resource server to which the IoT terminal device is to be connected to realize the monitoring of the operating status of each resource server.
[0085] Considering the limitation on the number of IoT terminal devices that the authorization end docks with the access resource server, in an alternative embodiment, before generating an authorization code using a preset encryption tool based on the feature code generated from the IoT terminal device and storing the feature code and the authorization code in the authorization table, the access method further includes: receiving the registration number of the IoT terminal devices that can be registered by the resource server;
[0086] Generating an authorization code using a preset encryption tool based on the feature code generated from the IoT terminal device and storing the feature code and the authorization code in the authorization table further includes: determining whether the number of IoT terminal devices registered by the resource server in the authorization table has reached the registration number, and if it has reached the registration number, returning an expansion prompt message.
[0087] In this embodiment, the authorization end limits the number of IoT terminal devices accessing the resource server according to the number of IoT terminal devices that can be registered by the resource server, effectively protecting the rights and interests of software and hardware developers and avoiding the abuse of the resource server by users. Specifically, in practical applications, software and hardware developers usually quote or charge according to the operation scale of the resource server, that is, quote or charge according to the number of IoT terminal devices accessing the resource server. In related technologies, the main reason for users to abuse the resource server is that users privately expand the operation scale of the resource server. Therefore, in this embodiment, by establishing an authorization table at the authorization end, the number of IoT terminal devices accessing the resource server can be obtained. Based on the pre-received registration number of IoT terminal devices that can be accessed by the resource server, it can be determined whether the user operates according to the predetermined operation scale. Specifically, when the authorization end receives the feature code of the IoT terminal device, it determines whether the number of IoT terminal devices accessing the resource server has reached the preset registration number according to the authorization table. If it has reached the registration number, no authorization code will be generated, and an expansion prompt message will be sent to the IoT terminal device, prompting the second user using the IoT terminal device to contact the first user operating the resource server to expand the operation scale of the resource server; thereby further improving the monitoring of the resource server and the IoT terminal devices accessing it by the authorization end and effectively protecting the rights and interests of software and hardware developers.
[0088] Considering the possibility that the feature code of the IoT terminal device may be cracked or forged, in an alternative embodiment, the feature code further includes the sales identifier of the IoT terminal device. Generating an authorization code using a preset encryption tool based on the feature code generated from the IoT terminal device and storing the feature code and the authorization code in the authorization table further includes:
[0089] Judging whether the IoT terminal device is sold normally according to the sales identifier. If the IoT terminal device is not sold normally, a third invalid prompt message will be returned. Otherwise, an authorization code will be generated using a preset encryption tool based on the identity identifier of the IoT terminal device.
[0090] In this embodiment, the legitimacy of the IoT terminal device is further determined by the sales identifier characterizing the legitimate identity, which can avoid the problem that the legitimate IoT terminal device cannot obtain the authorization code due to the cracking and counterfeiting of the feature code of the IoT terminal device, resulting in the leakage of the feature code. By returning a prompt message to the IoT terminal device to prompt the user for the reason why the authorization code cannot be obtained, the user experience of the second user using the IoT terminal device and the first user using the resource server is effectively improved.
[0091] Based on the sales identifier used in the foregoing embodiment, in an alternative embodiment, the sales identifier further includes a sales type, and the authorization end further includes an authorization information table, where the authorization information table includes at least one sales type and an authorization information item corresponding to the sales type;
[0092] The step of generating an authorization code by using a preset encryption tool according to the identity identifier of the IoT terminal device further includes: obtaining the corresponding authorization information item according to the authorization information table and the sales identifier of the IoT terminal device, and generating an authorization code by using the preset encryption tool according to the identity identifier of the IoT terminal device and the authorization information item.
[0093] In this embodiment, the access permission of the IoT terminal device is further limited by the authorization code through the sales type in the sales identifier. For example, the authorization time, authorization range, etc. of the authorization code obtained by the IoT terminal device are limited according to different sales types.
[0094] Specifically, for example, the sales type includes three sales levels with different fee levels. The first is the time-limited user, for example, the usage period is one year; the second is the service-limited user, for example, only a certain service provided by the resource server is limited; the third is the unlimited user, for example, the usage period and the usage service are not limited. By issuing authorization codes with different authorization information items to IoT terminal devices of different sales levels, the supervision ability of the authorization end is effectively improved, and the operation mode of the resource server is enriched. When the authorization time of the IoT terminal device expires or the authorization range is expanded, a new sales identifier is obtained by repurchasing, and a new authorization code is obtained through the new sales identifier, effectively improving the supervision efficiency of the authorization end and the operation efficiency of the resource server.
[0095] It should be noted that the specific form of the authorization information table in this application is not limited, and it can be an independent report or an extension of the authorization table. Those skilled in the art should select an appropriate method according to the actual application requirements, with the design criterion of limiting the authorization information item by the sales level of the sales type, which will not be elaborated here.
[0096] In this embodiment, by establishing an authorization information table at the authorization end, the monitoring of the resource server and the IoT terminal devices accessing it by the authorization end is further improved, which not only effectively protects the rights and interests of software and hardware developers, but also provides a more complete operation mode for the resource server.
[0097] Step 4: The authorization end sends the authorization code to the IoT terminal device.
[0098] Step 5: The authorization end sends the feature code of the IoT terminal device to the resource server.
[0099] In this embodiment, the authorization end sends the generated authorization code to the IoT terminal device, and at the same time sends the feature code of the IoT terminal device to be accessed to the resource server, so that the resource server can identify the IoT terminal device accessing and registering it. That is, the authorization end sends the feature code to the resource server to facilitate the resource server to confirm the legitimacy of the identity of the subsequent registration request of the IoT terminal.
[0100] Step 6: The IoT terminal device sends a registration request including the authorization code to the resource server.
[0101] Step 7: The resource server uses the decryption tool corresponding to the encryption tool to decrypt the authorization code according to the registration request to obtain the decrypted feature code. The resource server determines whether the decrypted feature code has a matching feature code to determine whether the IoT terminal device is legal. If it is not legal, it returns the first invalid prompt message. Otherwise, it determines whether the decrypted feature code has been registered according to the registration table stored in the resource server. If it has been registered, it returns the second invalid prompt message. If it has not been registered, it registers the IoT terminal device and stores the feature code in the registration table.
[0102] In this embodiment, after obtaining the authorization code, the IoT terminal device uses the authorization code to send a registration request to the resource server. The resource server uses the decryption tool to decrypt the authorization code to obtain the decrypted feature code, and compares it with the feature code sent by the authorization end to verify whether the IoT terminal device can access the resource server, that is, whether it can register with the resource server to obtain the resources of the resource server. In this embodiment, through the IoT terminal device - authorization end, the authorization end issues an encrypted authorization code to the IoT terminal device to be accessed. Through the authorization end - resource server, the authorization end sends the feature code of the IoT terminal device to be accessed to the resource server. Through the IoT terminal device - resource server, the resource server verifies the authorization code and determines whether the IoT terminal device can register with the resource server.
[0103] Based on the authorization information items provided in the foregoing embodiments, in an alternative embodiment, the step of sending the feature code of the IoT terminal device to the resource server further includes: sending the identity identifier and the authorization information item of the IoT terminal device to the resource server, so that the resource server decrypts the authorization code using the decryption tool in response to the registration request to obtain the decrypted identity identifier and the decrypted authorization information item, determines whether the decrypted identity identifier has a matching identity identifier to determine whether the IoT terminal device is legal, if it is not legal, returns a first invalid prompt message, otherwise determines whether the decrypted identity identifier has been registered according to the registry stored in the resource server, if it has been registered, returns a second invalid information prompt, if it has not been registered, determines whether the decrypted authorization information item has a matching authorization information item to determine whether the IoT terminal device is valid, if it is invalid, returns a fourth invalid prompt message, otherwise registers the IoT terminal device and stores the identity identifier in the registry.
[0104] In this embodiment, the authorization code generated by encrypting the feature code and the authorization information item by the authorization end is decrypted at the resource server end to obtain the decrypted feature code and the decrypted authorization information item. On the one hand, the reliability of encryption and decryption is improved by increasing the encrypted content. On the other hand, the operation ability of the resource server and the legality verification of the IoT terminal device are effectively improved, further improving the stability and security of the access system on the basis of protecting the rights and interests of software and hardware developers.
[0105] Considering the security of the encryption of the feature code by the authorization end and the decryption of the encrypted information by the resource server, in an alternative embodiment, the decryption tool and the encryption tool are a pair of asymmetric keys, wherein the encryption tool includes a private key and the decryption tool includes a public key.
[0106] In this embodiment, considering the security risks of the symmetric encryption and decryption algorithm using the same key at the encryption end and the decryption end, this embodiment realizes the encryption and decryption of the authorization code by setting the private key of the asymmetric encryption algorithm at the authorization end and the public key different from the private key of the asymmetric encryption algorithm at the resource server, thereby further improving the security of the authorization code. Specifically, encryption is performed by the private key at the authorization end. As long as the private key is secure, the authorization code can be prevented from being cracked, thereby further protecting the rights and interests of software and hardware developers. The asymmetric encryption algorithm used in this embodiment can be the RSA algorithm or other asymmetric encryption algorithms, and the present application does not make specific limitations thereon.
[0107] So far, the access of the IoT terminal device to the resource server is completed. In this embodiment, by setting an authorization end in response to the operation control of software and hardware developers, the legitimacy of the IoT terminal device is judged, and the access of the IoT terminal device to the resource server is restricted by an authorization code. Then, the resource server verifies the authorization code to control the registration of the IoT terminal device in the resource server, so as to realize the pairwise limitation among the three parties of the authorization end - IoT terminal device, the authorization end - resource server, and the IoT terminal device - resource server; that is, software and hardware developers supervise the resource server and the IoT terminal device through the authorization end, and restrict the IoT terminal devices accessing the resource server, effectively protecting the rights and interests of software and hardware developers and solving the problems existing in the related technologies. At the same time, through the communication between the authorization end and the resource server, the legitimacy of the IoT terminal device is further ensured, and the problem that external illegal users access the resource server by cracking and forging IoT terminal devices is avoided, further improving the security and stability of the access system.
[0108] Considering that the second user using the IoT terminal device and the first user using the resource server are the same user. For example, when applied to internal departments such as libraries and meeting rooms in campuses, enterprises or other types of units, the IoT terminal device and the resource server are connected through an internal local area network. To further simplify the access process, in an optional embodiment, the IoT terminal device generates a feature code and sends an authorization request including the feature code to the authorization end. The authorization end generates an encrypted authorization code using an encryption tool based on the feature code and feeds back the authorization code to the IoT terminal device. The IoT terminal device sends a registration request to the resource server according to the feature code and the authorization code. The resource server decrypts the authorization code using a decryption tool to obtain the decrypted feature code, and compares the decrypted feature code with the received feature code. If they are different, a first invalid prompt message is returned. Otherwise, it is determined that the IoT terminal device is a legal device, and it is judged whether the decrypted feature code has been registered through the registry stored in the resource server. If it has been registered, a second invalid prompt message is returned. If it has not been registered, the IoT terminal device is registered and the feature code is stored in the registry.
[0109] In this embodiment, since both the IoT terminal device and the resource server are set in the same department, on the premise of ensuring that there is no external illegal user cracking and forging the IoT terminal device, by simplifying the access process, the access efficiency of the access system is further improved on the basis of effectively protecting the rights and interests of software and hardware developers, thereby improving the user experience.
[0110] It should be noted that the embodiments of the present application adopt a progressive manner. Those skilled in the art should understand that the implementation manners such as the sales identifier and the sales type in the sales identifier in the foregoing embodiments can all be applied to this embodiment and are all within the protection scope of the present application, and will not be elaborated herein.
[0111] Considering that after the IoT terminal device accesses the resource server and requests service resources from the resource server, in an optional embodiment, after the IoT terminal device receives and stores the authorization code and sends a registration request including the authorization code to the resource server, the access method further includes: sending a resource request including the authorization code and resource information to the resource server, so that the resource server decrypts the authorization code using the decryption tool in response to the resource request to verify the authorization code; receiving the resource content corresponding to the resource information, where the resource content is sent by the resource server after the authorization code is verified successfully.
[0112] In this embodiment, first, the IoT terminal device sends a resource request including the authorization code and resource information to the resource server; second, the resource server decrypts the authorization code using the decryption tool in response to the resource request to verify the authorization code; finally, the IoT terminal device receives the resource content corresponding to the resource information. Through the encrypted authorization code issued by the authorization end to the IoT terminal device, the decryption and verification of the encrypted authorization code by the resource server, this embodiment can realize the function that the IoT terminal device further requests service resources from the resource server on the basis of accessing the resource server, that is, realize the operation of the resource server on the IoT terminal device.
[0113] Based on the above access method, as Figure 4 shown, an embodiment of the present application further provides an access method applied to an IoT terminal device, generating a feature code and sending an authorization request including the feature code to the authorization end, so that the authorization end generates the authorization code using a preset encryption tool according to the feature code and stores the feature code and the authorization code in the authorization table, sends the authorization code to the IoT terminal device, sends the feature code to the resource server, where the feature code includes the identity identifier of the IoT terminal device; receiving and storing the authorization code, and sending a registration request including the authorization code to the resource server, so that the resource server decrypts the authorization code using a decryption tool corresponding to the encryption tool in response to the registration request to verify the authorization code according to the received feature code, and if the verification is successful, registers the IoT terminal device and stores the feature code in the registration table.
[0114] In this embodiment, by setting an authorization end that responds to the operation control of software and hardware developers, the legitimacy of the IoT terminal device is judged, and the access of the IoT terminal device to the resource server is restricted through an authorization code. Then, the resource server verifies the authorization code to control the registration of the IoT terminal device on the resource server, thereby realizing the supervision of the resource server and the IoT terminal device through the authorization end, restricting the IoT terminal device accessing the resource server, effectively protecting the rights and interests of software and hardware developers, and solving the problems existing in the related technologies. For the specific implementation manners, refer to the foregoing embodiments and will not be elaborated herein.
[0115] In an optional embodiment, the IoT terminal device receives a first invalid prompt message, which is generated when the decryption feature code obtained by the resource server according to the decrypted authorization code does not match the feature code.
[0116] In this embodiment, when the IoT terminal device sends a registration request including an authorization code to the resource server, if the decryption feature code obtained by the resource server by decrypting the authorization code does not match the feature code sent by the authorization end to the resource server, it indicates that the IoT terminal device is an illegal IoT terminal device. The resource server sends a prompt message to the IoT terminal device to prompt the user using the IoT terminal device for the reason of non-access, thereby improving the user experience.
[0117] In an optional embodiment, the IoT terminal device receives a second invalid prompt message, which is generated when the decryption feature code obtained by the resource server according to the decrypted authorization code already exists in the registration table stored in the resource server.
[0118] In this embodiment, when the IoT terminal device sends a registration request including an authorization code to the resource server, if the decryption feature code obtained by the resource server by decrypting the authorization code is verified and it is judged according to the stored registration table that the decryption feature code has been registered, it indicates that the IoT terminal device is an illegal IoT terminal device. For example, when forging the feature code and authorization code of a legal IoT terminal device to access the resource server, the resource server sends a prompt message to the IoT terminal device to prompt the user using the IoT terminal device for the reason of non-access, thereby improving the user experience.
[0119] In an optional embodiment, the IoT terminal device receives an expansion prompt message. The authorization end further includes the registration quantity of the IoT terminal devices that can be registered by the resource server. The expansion prompt message is generated when the authorization end judges that the quantity of the IoT terminal devices already registered by the resource server in the authorization table has reached the registration quantity.
[0120] In this embodiment, when the IoT terminal device sends an authorization request including a feature code to the authorization end, if the authorization end determines in the stored authorization table that the number of IoT terminal devices accessing the resource server has reached the registered number, it sends a prompt message to the IoT terminal device to prompt the user using the IoT terminal device for the reason of not obtaining the authorization code, thereby protecting the rights and interests of software and hardware developers and improving the user experience.
[0121] In an alternative embodiment, the IoT terminal device receives a third invalid prompt message, and the feature code further includes the sales identifier of the IoT terminal device, and the third invalid prompt message is generated when the authorization end determines that the sales identifier of the IoT terminal device is an abnormal sale.
[0122] In this embodiment, when the IoT terminal device sends an authorization request including a feature code to the authorization end, if the authorization end determines that the IoT terminal device is an abnormal sale based on the sales identifier, it sends a prompt message to the IoT terminal device to prompt the user using the IoT terminal device for the reason of not obtaining the authorization code, thereby protecting the rights and interests of software and hardware developers and improving the user experience.
[0123] In an alternative embodiment, the IoT terminal device receives a fourth invalid prompt message, the feature code further includes the sales identifier of the IoT terminal device, the sales identifier further includes a sales type, the authorization end obtains a corresponding authorization information item according to the sales type, and uses the encryption tool to generate the authorization code according to the identity identifier and the authorization information item, and the fourth invalid prompt message is generated when the decrypted authorization information obtained by the resource server using the decryption tool does not match the authorization information item.
[0124] In this embodiment, when the IoT terminal device sends a registration request including an authorization code to the resource server, if there is a problem that the decrypted feature code obtained by decrypting the authorization code by the resource server does not match the authorization information item during verification, it indicates that the IoT terminal device is an invalid IoT terminal device, and the resource server sends a prompt message to the IoT terminal device to prompt the user using the IoT terminal device for the reason of not being connected, thereby improving the user experience.
[0125] Based on the above access method, as Figure 5 shown, an embodiment of the present application further provides an access method applied to an IoT terminal device, including:
[0126] Receiving a feature code sent by an authorization end, the feature code including an identity identifier of the IoT terminal device;
[0127] Receiving a registration request sent by the IoT terminal device, the registration request being generated by the authorization end according to the feature code using a preset encryption tool;
[0128] Use a decryption tool set corresponding to the encryption tool to decrypt the authorization code to obtain a decrypted feature code, determine whether the decrypted feature code has a matching feature code to determine whether the IoT terminal device is legal. If it is not legal, return a first invalid prompt message. Otherwise, judge whether the decrypted feature code has been registered according to the registry stored in the resource server. If it has been registered, return a second invalid prompt message. If it has not been registered, register the IoT terminal device and store the feature code in the registry.
[0129] In this embodiment, by setting an authorization end responsive to the operation control of software and hardware developers, the legitimacy of the IoT terminal device is judged and the access of the IoT terminal device to the resource server is restricted through the authorization code. Then, the resource server verifies the authorization code to control the registration of the IoT terminal device in the resource server, so as to realize the supervision of the resource server and the IoT terminal device through the authorization end, restrict the IoT terminal device accessing the resource server, effectively protect the rights and interests of software and hardware developers, and solve the problems existing in the related technologies. For the specific implementation manner, refer to the foregoing embodiments and will not be elaborated herein.
[0130] Corresponding to the access method provided in the above embodiment, an embodiment of the present application further provides an access system applying the above access method. Since the access system provided in the embodiment of the present application corresponds to the access methods provided in the above several embodiments, the foregoing implementation manners are also applicable to the access system provided in this embodiment and will not be described in detail in this embodiment.
[0131] Such as Figure 2As shown in the figure, an embodiment of the present application further provides an access system applying the above access method, including: an authorization end, including an authorization table and an encryption tool; a resource server, including a registration table, a decryption tool corresponding to the encryption tool, and a verification unit; and at least one Internet of Things terminal device, including an identity identifier and a feature code generation unit; the authorization end is configured to: according to the feature code generated by the feature code generation unit based on the identity identifier, use the encryption tool to generate an authorization code and store the feature code and the authorization code in the authorization table; send the authorization code to the Internet of Things terminal device, so that the Internet of Things terminal device sends a registration request including the authorization code to the resource server; send the feature code of the Internet of Things terminal device to the resource server, so that the resource server decrypts the authorization code using the decryption tool in response to the registration request to obtain a decrypted feature code, and uses the verification unit to determine whether the decrypted feature code has a matching feature code to determine whether the Internet of Things terminal device is legal. If it is not legal, a first invalid prompt message is returned. Otherwise, it is determined according to the registration table whether the decrypted feature code has been registered. If it has been registered, a second invalid prompt message is returned. If it has not been registered, the Internet of Things terminal device is registered and the feature code is stored in the registration table.
[0132] In this embodiment, by setting an authorization end that responds to the operation control of software and hardware developers, the legitimacy of the Internet of Things terminal device is judged, and the access of the Internet of Things terminal device to the resource server is restricted through the authorization code. Then, the resource server verifies the authorization code to control the registration of the Internet of Things terminal device in the resource server, so as to realize the supervision of the resource server and the Internet of Things terminal device by the authorization end, restrict the Internet of Things terminal device accessing the resource server, effectively protect the rights and interests of software and hardware developers, and solve the problems existing in the related technologies. For the specific implementation manners, refer to the foregoing embodiments and will not be elaborated herein.
[0133] Another embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the above access method is implemented.
[0134] In practical applications, the computer-readable storage medium may adopt any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device.
[0135] The computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device.
[0136] The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination of the above.
[0137] The computer program code for performing the operations of the present invention can be written in one or more programming languages or a combination thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0138] As Figure 6As shown, a schematic structural diagram of a computer device provided by another embodiment of the present invention. Figure 6 The computer device 12 shown is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present invention.
[0139] As Figure 6 shown, the computer device 12 is presented in the form of a general-purpose computing device. The components of the computer device 12 may include, but are not limited to: one or more processors or processing units 16, a system memory 28, and a bus 18 connecting different system components (including the system memory 28 and the processing unit 16).
[0140] The bus 18 represents one or more of several types of bus structures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any bus structure in a variety of bus structures. By way of example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.
[0141] The computer device 12 typically includes a variety of computer system-readable media. These media can be any available media accessible by the computer device 12, including volatile and non-volatile media, removable and non-removable media.
[0142] The system memory 28 may include computer system-readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. The computer device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 34 can be used to read and write non-removable, non-volatile magnetic media ( Figure 6 not shown, commonly referred to as a "hard disk drive"). Although Figure 6 not shown in the figure, a disk drive for reading and writing removable non-volatile disks (such as "floppy disks") and an optical disk drive for reading and writing removable non-volatile optical disks (such as CD-ROM, DVD-ROM, or other optical media) can be provided. In these cases, each drive can be connected to the bus 18 through one or more data media interfaces. The memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of the present invention.
[0143] A program / utilities 40 having a set (at least one) of program modules 42 can be stored, for example, in a memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. The program modules 42 generally execute the functions and / or methods in the embodiments described in the present invention.
[0144] The computer device 12 can also communicate with one or more external devices 14 (such as a keyboard, a pointing device, a display 24, etc.), and can also communicate with one or more devices that enable a user to interact with the computer device 12, and / or communicate with any device that enables the computer device 12 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through an input / output (I / O) interface 22. Moreover, the computer device 12 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 20. As Figure 6 shown, the network adapter 20 communicates with other modules of the computer device 12 through a bus 18. It should be understood that although Figure 6 not shown in the figure, other hardware and / or software modules can be used in conjunction with the computer device 12, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0145] The processor unit 16 executes various functional applications and data processing by running programs stored in the system memory 28, such as implementing an access method provided by the embodiments of the present invention.
[0146] In view of the existing problems at present, the present invention formulates an access method, an access system, a computer device, and a medium for an Internet of Things terminal device. By setting an authorization end in response to the operation control of software and hardware developers, the legitimacy of the Internet of Things terminal device is judged, and the access to the resource server by the Internet of Things terminal device is restricted through an authorization code. Then, the resource server verifies the authorization code to control the registration of the Internet of Things terminal device in the resource server, thereby realizing the pairwise limitation among the three parties of the authorization end - Internet of Things terminal device, the authorization end - resource server, and the Internet of Things terminal device - resource server; that is, software and hardware developers supervise the resource server and the Internet of Things terminal device through the authorization end, and restrict the Internet of Things terminal devices accessing the resource server, effectively protecting the rights and interests of software and hardware developers, making up for the problems existing in the related technologies, and having a wide application prospect.
[0147] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention, rather than limitations on the implementation manners of the present invention. For those of ordinary skill in the art, other different forms of changes or variations can be made based on the above description. It is impossible to enumerate all the implementation manners here. Any obvious changes or variations derived from the technical solutions of the present invention still fall within the protection scope of the present invention.
Claims
1. An access method for an Internet of Things terminal device, characterized in that, applied to the authorization end, including: receiving the registration quantity of Internet of Things terminal devices that can be registered by the resource server; generating an authorization code using a preset encryption tool based on the feature code generated by the Internet of Things terminal device, and storing the feature code and the authorization code in an authorization table, where the feature code includes the identity identifier of the Internet of Things terminal device, and further including: judging whether the quantity of the Internet of Things terminal devices already registered by the resource server in the authorization table reaches the registration quantity, and if it has reached the registration quantity, returning an expansion prompt message; sending the authorization code to the Internet of Things terminal device, so that the Internet of Things terminal device sends a registration request including the authorization code to the resource server; sending the feature code of the Internet of Things terminal device to the resource server, so that the resource server decrypts the authorization code using a decryption tool corresponding to the encryption tool in response to the registration request to obtain a decrypted feature code, judging whether the decrypted feature code has a matching feature code to determine whether the Internet of Things terminal device is legal, if it is not legal, returning a first invalid prompt message, otherwise judging whether the decrypted feature code has been registered according to the registration table stored in the resource server, if it has been registered, returning a second invalid prompt message, if it has not been registered, registering the Internet of Things terminal device and storing the feature code in the registration table; the feature code further includes the sales identifier of the Internet of Things terminal device, and the step of generating an authorization code using a preset encryption tool based on the feature code generated by the Internet of Things terminal device and storing the feature code and the authorization code in an authorization table further includes: judging whether the Internet of Things terminal device is for normal sales according to the sales identifier, if the Internet of Things terminal device is for abnormal sales, returning a third invalid prompt message, otherwise generating an authorization code using a preset encryption tool according to the identity identifier of the Internet of Things terminal device; the sales identifier further includes a sales type, and the authorization end further includes an authorization information table, where the authorization information table includes at least one sales type and an authorization information item corresponding to the sales type; the step of generating an authorization code using a preset encryption tool according to the identity identifier of the Internet of Things terminal device further includes: obtaining a corresponding authorization information item according to the authorization information table and the sales identifier of the Internet of Things terminal device, and generating an authorization code using a preset encryption tool according to the identity identifier of the Internet of Things terminal device and the authorization information item; Sending the feature code of the IoT terminal device to the resource server further includes: sending the identity identifier and authorization information item of the IoT terminal device to the resource server, so that the resource server uses the decryption tool to decrypt the authorization code in response to the registration request to obtain the decrypted identity identifier and decrypted authorization information item, determining whether the decrypted identity identifier has a matching identity identifier to determine whether the IoT terminal device is legal, if it is not legal, returning a first invalid prompt message, otherwise, determining whether the decrypted identity identifier has been registered according to the registration table stored in the resource server, if it has been registered, returning a second invalid information prompt, if it has not been registered, determining whether the decrypted authorization information item has a matching authorization information item to determine whether the IoT terminal device is valid, if it is invalid, returning a fourth invalid prompt message, otherwise, registering the IoT terminal device and storing the identity identifier in the registration table.
2. The access method according to claim 1, wherein, the decryption tool and the encryption tool are a pair of asymmetric keys, wherein, the encryption tool includes a private key, and the decryption tool includes a public key.
3. An access method for an IoT terminal device, wherein, applied to the IoT terminal device, includes: generating a feature code and sending an authorization request including the feature code to an authorization end, so that the authorization end generates an authorization code according to the feature code using a preset encryption tool, stores the feature code and the authorization code in an authorization table, sends the authorization code to the IoT terminal device, and sends the feature code to the resource server, the feature code including the identity identifier of the IoT terminal device; receiving and storing the authorization code, and sending a registration request including the authorization code to the resource server, so that the resource server decrypts the authorization code using a decryption tool corresponding to the encryption tool in response to the registration request to verify the authorization code according to the received feature code, and if the verification is successful, registering the IoT terminal device and storing the feature code in a registration table; receiving a first invalid prompt message, the first invalid prompt message being generated when the decrypted feature code obtained by the resource server according to the decrypted authorization code does not match the feature code; receiving a second invalid prompt message, the second invalid prompt message being generated when the decrypted feature code obtained by the resource server according to the decrypted authorization code already exists in the registration table stored by the resource server; receiving an expansion prompt message, the authorization end further including the registration quantity of the IoT terminal devices that can be registered by the resource server, the expansion prompt message being generated when the authorization end determines that the quantity of the IoT terminal devices already registered by the resource server in the authorization table has reached the registration quantity; receiving a third invalid prompt message, the feature code further including the sales identifier of the IoT terminal device, the third invalid prompt message being generated when the authorization end determines that the sales identifier of the IoT terminal device is an abnormal sale; Receive the fourth invalid prompt message. The feature code further includes the sales identifier of the IoT terminal device, and the sales identifier further includes a sales type. The authorization end obtains the corresponding authorization information item according to the sales type, and uses the encryption tool to generate the authorization code according to the identity identifier and the authorization information item. The fourth invalid prompt message is generated when the decrypted authorization information obtained by the resource server using the decryption tool does not match the authorization information item.
4. The access method according to claim 3, wherein, after receiving and storing the authorization code and sending a registration request including the authorization code to the resource server, the access method further includes: sending a resource request including the authorization code and resource information to the resource server, so that the resource server uses the decryption tool to decrypt the authorization code in response to the resource request to verify the authorization code; receiving the resource content corresponding to the resource information, where the resource content is sent by the resource server after the authorization code is verified successfully.
5. An access method for an IoT terminal device, wherein, applied to a resource server, includes: sending the registration quantity of the IoT terminal device that can be registered to the authorization end; receiving the feature code sent by the authorization end, where the feature code includes the identity identifier of the IoT terminal device; receiving the registration request sent by the IoT terminal device, where the registration request includes the authorization code generated by the authorization end using a preset encryption tool according to the feature code. The authorization code is obtained by the IoT terminal device after sending an authorization request to the authorization end based on the feature code, and further includes: making the authorization end judge whether the number of the IoT terminal devices already registered in the resource server in the stored authorization table reaches the registration quantity. If the registration quantity has been reached, the authorization end returns an expansion prompt message; using the decryption tool corresponding to the encryption tool to decrypt the authorization code to obtain a decrypted feature code, judging whether the decrypted feature code has a matching feature code to determine whether the IoT terminal device is legal. If it is not legal, return the first invalid prompt message. Otherwise, judge whether the decrypted feature code has been registered according to the registration table stored in the resource server. If it has been registered, return the second invalid prompt message. If it has not been registered, register the IoT terminal device and store the feature code in the registration table; wherein, the feature code further includes the sales identifier of the IoT terminal device. The authorization end generating the authorization code using the preset encryption tool according to the feature code includes: the authorization end judging whether the IoT terminal device is sold normally according to the sales identifier. If the IoT terminal device is not sold normally, the authorization end returns the third invalid prompt message. Otherwise, generate the authorization code using the preset encryption tool according to the identity identifier of the IoT terminal device; the sales identifier further includes a sales type, and the authorization end further includes an authorization information table, where the authorization information table includes at least one sales type and the authorization information item corresponding to the sales type. The authorization terminal generating an authorization code using a preset encryption tool based on the feature code further includes: the authorization terminal obtaining a corresponding authorization information item according to the authorization information table and the sales identifier of the IoT terminal device, and generating an authorization code using the preset encryption tool according to the identity identifier of the IoT terminal device and the authorization information item; The resource server receiving the feature code sent by the authorization terminal further includes: receiving the identity identifier and the authorization information item of the IoT terminal device sent by the authorization terminal; The resource server receiving the registration request sent by the IoT terminal device further includes: The resource server decrypting the authorization code using the decryption tool according to the registration request to obtain a decrypted authorization information item, and determining whether the IoT terminal device is valid by determining whether the decrypted authorization information item has a matching authorization information item when the IoT terminal device is legal and unregistered. If it is invalid, the resource server returns a fourth invalid prompt message. Otherwise, the IoT terminal device is registered and the identity identifier is stored in the registry.
6. The access method according to claim 5, wherein, After decrypting the authorization code using the decryption tool corresponding to the encryption tool to obtain a decrypted feature code, the access method further includes: Receiving a resource request sent by the IoT terminal device, the resource request including the authorization code and a resource request for resource information; Decrypting the authorization code using the decryption tool to obtain a decrypted feature code, and verifying the decrypted feature code; Responding to the successful verification of the decrypted feature code by sending resource content corresponding to the resource information to the IoT terminal device.
7. An access system, wherein, including: An authorization terminal, including an authorization table and an encryption tool; A resource server, including a registry, a decryption tool corresponding to the encryption tool, and a verification unit; and At least one IoT terminal device, including an identity identifier and a feature code generation unit; The authorization terminal is configured to: Receive the registration quantity of the IoT terminal devices that can be registered by the resource server; According to the feature code generated by the feature code generation unit according to the identity identifier, generating an authorization code using the encryption tool and storing the feature code and the authorization code in the authorization table. The feature code includes the identity identifier of the IoT terminal device, and further includes: determining whether the quantity of the IoT terminal devices already registered by the resource server in the authorization table reaches the registration quantity. If it has reached the registration quantity, return an expansion prompt message; Sending the authorization code to the IoT terminal device, so that the IoT terminal device sends a registration request including the authorization code to the resource server; Send the feature code of the IoT terminal device to the resource server, so that the resource server decrypts the authorization code using the decryption tool in response to the registration request to obtain the decrypted feature code, and uses the verification unit to determine whether the decrypted feature code has a matching feature code to determine whether the IoT terminal device is legal. If it is not legal, return the first invalid prompt message; otherwise, determine whether the decrypted feature code has been registered according to the registration table. If it has been registered, return the second invalid prompt message; if it has not been registered, register the IoT terminal device and store the feature code in the registration table; The feature code further includes the sales identifier of the IoT terminal device. The step of generating an authorization code using the encryption tool and storing the feature code and the authorization code in the authorization table according to the feature code generated by the feature code generation unit based on the identity identifier further includes: determining whether the IoT terminal device is sold normally according to the sales identifier. If the IoT terminal device is sold abnormally, return the third invalid prompt message; otherwise, generate an authorization code using the preset encryption tool according to the identity identifier of the IoT terminal device; The sales identifier further includes the sales type. The authorization end further includes an authorization information table, and the authorization information table includes at least one sales type and the authorization information item corresponding to the sales type. The step of generating an authorization code using the encryption tool and storing the feature code and the authorization code in the authorization table further includes: obtaining the corresponding authorization information item according to the authorization information table and the sales identifier of the IoT terminal device, and generating an authorization code using the preset encryption tool according to the identity identifier of the IoT terminal device and the authorization information item. The step of sending the feature code of the IoT terminal device to the resource server further includes: sending the identity identifier and the authorization information item of the IoT terminal device to the resource server, so that the resource server decrypts the authorization code using the decryption tool in response to the registration request to obtain the decrypted identity identifier and the decrypted authorization information item, and determines whether the decrypted identity identifier has a matching identity identifier to determine whether the IoT terminal device is legal. If it is not legal, return the first invalid prompt message; otherwise, determine whether the decrypted identity identifier has been registered according to the registration table stored in the resource server. If it has been registered, return the second invalid information prompt; if it has not been registered, determine whether the decrypted authorization information item has a matching authorization information item to determine whether the IoT terminal device is valid. If it is not valid, return the fourth invalid prompt message; otherwise, register the IoT terminal device and store the identity identifier in the registration table.
8. A computer-readable storage medium, on which a computer program is stored, characterized in that, when the program is executed by a processor, it implements the method according to any one of claims 1-2; or when the program is executed by a processor, it implements the method according to any one of claims 3-4; or when the program is executed by a processor, it implements the method according to any one of claims 5-6.
9. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein, when the processor executes the program, the method described in any one of claims 1-2 is implemented; or when the processor executes the program, the method described in any one of claims 3-4 is implemented; or when the processor executes the program, the method described in any one of claims 5-6 is implemented.
Citation Information
Patent Citations
Resource operation method and device
CN107659406A
Registration authentication method, server, terminal equipment and readable storage medium
CN111343156A