A Mobile Terminal and Intelligent Device Security Authentication Method and System
By determining the valid life cycle of issuing a certificate between the mobile terminal and the smart device and generating a digital certificate of a shared key, the problem of lack of strict identity authentication and low security in the prior art is solved, and higher security and loss recovery rate is achieved.
Patent Information
- Application Number
- CN202211283534.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-20
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-10-20
AI Technical Summary
In the prior art, mobile terminals and smart devices lack a strict identity authentication system, resulting in low security factor for information transmission and difficulty in retrieving it after the mobile terminal is lost.
By determining the target smart device and the target mobile terminal, determining the certificate valid life cycle for issuing the certificate based on it, generating and issuing the first and second digital certificates of the shared key, the identity authentication and communication connection between the devices are realized, and the certificate is regenerated when the certificate validity cycle arrives.
It improves the security of information transmission between mobile terminals and smart devices, enhances the strictness of identity authentication, improves the probability of recovery after mobile terminals are lost, and protects users' privacy and property security.
Smart Images

Figure CN115665746B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of identity authentication, and particularly to a method and system for secure authentication between a mobile terminal and an intelligent device. Background Art
[0002] With the continuous development of Internet of Things technology, more and more Internet of Things mobile terminal devices are involved in improving the living standards of the people. Intelligent detection devices such as mobile bracelets monitor, record and analyze user data to help users accurately understand their own health conditions.
[0003] The mobile terminal connects to the corresponding intelligent device through identity authentication to transmit monitoring information and analysis results. Currently, the common mobile terminal identity authentication method is to set a fixed certificate for single matching, and then directly connect according to the matching records of the intelligent device. The existing connection method between the mobile terminal and the intelligent device has a low level of strictness in identity authentication, there is a risk of user data leakage, and it is difficult to retrieve the mobile terminal after it is lost, resulting in low property security of the user's mobile terminal.
[0004] In the prior art, there are technical problems that the pairing between the mobile terminal and the intelligent device lacks a strict identity authentication system, the security coefficient of information transmission during the pairing connection process is low, and it is difficult to retrieve the mobile terminal after it is lost. Summary of the Invention
[0005] The present application provides a method and system for secure authentication between a mobile terminal and an intelligent device, which are used to solve the technical problems in the prior art that the pairing between the mobile terminal and the intelligent device lacks a strict identity authentication system, the security coefficient of information transmission during the pairing connection process is low, and it is difficult to retrieve the mobile terminal after it is lost.
[0006] In view of the above problems, the present application provides a method and system for secure authentication between a mobile terminal and an intelligent device.
[0007] In the first aspect of the present application, a security authentication method for a mobile terminal and an intelligent device is provided. The method includes: determining a target intelligent device and a target mobile terminal; determining a valid life cycle of a certificate for signing the certificate according to the target intelligent device and the target mobile terminal; generating and signing a first digital certificate for the target intelligent device; generating and signing a second digital certificate for the target mobile terminal, where the first digital certificate and the second digital certificate share a key; the target intelligent device initiating a connection pairing request to the target mobile terminal based on the first digital certificate; the target mobile terminal performing identity authentication with the target intelligent device based on the second digital certificate to obtain an identity authentication result; when the identity authentication result is authentication passed, establishing a communication connection between the target intelligent device and the target mobile terminal; determining whether the first digital certificate and the second digital certificate reach the valid life cycle of the certificate, and regenerating the first digital certificate and the second digital certificate when the valid life cycle of the certificate is reached.
[0008] In the second aspect of the present application, a security authentication system for a mobile terminal and an intelligent device is provided. The system includes: a connection object determination module for determining a target intelligent device and a target mobile terminal; a certificate term calculation module for determining a valid life cycle of a certificate for signing the certificate according to the target intelligent device and the target mobile terminal; a device certificate issuance module for generating and signing a first digital certificate for the target intelligent device; a terminal certificate issuance module for generating and signing a second digital certificate for the target mobile terminal, where the first digital certificate and the second digital certificate share a key; a connection pairing start module for the target intelligent device initiating a connection pairing request to the target mobile terminal based on the first digital certificate; an identity verification execution module for the target mobile terminal performing identity authentication with the target intelligent device based on the second digital certificate to obtain an identity authentication result; a communication connection execution module for establishing a communication connection between the target intelligent device and the target mobile terminal when the identity authentication result is authentication passed; a certificate verification and update module for determining whether the first digital certificate and the second digital certificate reach the valid life cycle of the certificate, and regenerating the first digital certificate and the second digital certificate when the valid life cycle of the certificate is reached.
[0009] One or more technical solutions provided in the present application have at least the following technical effects or advantages:
[0010] The method provided by the embodiment of the present application determines a target intelligent device and a target mobile terminal; determines the valid life cycle of the issued certificate according to the target intelligent device and the target mobile terminal, improving the security of information transmission between devices compared with a one-time identity card, generates and issues a first digital certificate to the target intelligent device; generates and issues a second digital certificate to the target mobile terminal, where the first digital certificate and the second digital share a key; the target intelligent device initiates a connection pairing request to the target terminal based on the first digital certificate; the target mobile terminal performs identity authentication with the target intelligent device based on the second digital certificate to obtain an identity authentication result; when the identity authentication result is authentication passed, a communication connection is established between the target intelligent device and the target mobile terminal; determines whether the first digital certificate and the second digital certificate reach the valid life cycle of the certificate, and regenerates the first digital certificate and the second digital certificate when reaching the valid life cycle of the certificate. It achieves the technical effects of matching and connecting management between the mobile terminal and the intelligent device based on a strict identity authentication system, increasing the cost of crime, increasing the probability of recovering a lost mobile terminal, avoiding the leakage of user privacy, and protecting the property security of the user's mobile terminal. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Figure 1 It is a schematic flowchart of a method for secure authentication between a mobile terminal and an intelligent device provided by the present application;
[0012] Figure 2 It is a schematic flowchart of determining the valid life cycle of the issued certificate in a method for secure authentication between a mobile terminal and an intelligent device provided by the present application;
[0013] Figure 3 It is a schematic flowchart of evaluating the importance degree of transmitted information in a method for secure authentication between a mobile terminal and an intelligent device provided by the present application;
[0014] Figure 4 It is a schematic structural diagram of a system for secure authentication between a mobile terminal and an intelligent device provided by the present application.
[0015] Description of the reference numerals: connection object determination module 11, certificate term calculation module 12, device certificate issuance module 13, terminal certificate issuance module 14, connection pairing start module 15, identity verification execution module 16, communication connection execution module 17, certificate verification and update module 18. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] The present application provides a security authentication method and system for a mobile terminal and an intelligent device, which are used to solve the technical problems existing in the prior art, such as the lack of a strict identity authentication system for pairing the mobile terminal and the intelligent device, the low security factor of information transmission during the pairing connection process, and the difficulty in retrieving the mobile terminal after it is lost.
[0017] In view of the above technical problems, the general idea of the technical solution provided by the present application is as follows:
[0018] According to the mobile terminal and the intelligent device, analyze and determine the valid period of the pairing authentication certificate, and based on the valid period, perform periodic automatic reconnection and pairing of the mobile terminal with the intelligent device. After the intelligent device fails to initiate multiple reconnection and pairing attempts, the mobile terminal searches for the original intelligent device and sends a loss warning, achieving the technical purpose of improving the connection security between the mobile terminal and the intelligent device and the security of information transmission during the connection process.
[0019] Embodiment 1
[0020] As Figure 1 shown, the present application provides a security authentication method for a mobile terminal and an intelligent device, and the method includes:
[0021] S100: Determine the target intelligent device and the target mobile terminal;
[0022] Specifically, in this embodiment, the target intelligent device is a sensing device configured with a fixed position or configured on parts such as a human arm and that undergoes spatial displacement with human activities. The target mobile terminal is an electronic device with information receiving and transmitting functions, including but not limited to mobile phones, computers, and large-scale Internet of Things monitoring and control systems. The target intelligent device realizes connection and communication with the target mobile terminal through identity authentication, and reliable identity authentication is the basis for ensuring the security of communication connections and the credibility of information data.
[0023] S200: Determine the certificate effective life cycle for issuing the certificate according to the target intelligent device and the target mobile terminal;
[0024] Further, as Figure 2 shown, for determining the certificate effective life cycle for issuing the certificate according to the target intelligent device and the target mobile terminal, the method step S200 provided by the present application further includes:
[0025] S210: Obtain the device model and device function information according to the target intelligent device;
[0026] S220: Match the communication frequency record data set and the communication information record data set according to the device model and the device function information;
[0027] S230: Fit the communication frequency data according to the communication frequency record data set;
[0028] S240: Generate a primary certificate's valid life cycle based on the communication frequency data;
[0029] S250: Evaluate the importance degree of transmission information based on the communication information record data set;
[0030] S260: Optimize the primary certificate's valid life cycle according to the evaluation result of the importance degree of transmission information to obtain the certificate's valid life cycle.
[0031] Specifically, in this embodiment, before the first connection to the target smart device and the target mobile terminal respectively, digital certificates with the same key are issued, and the digital certificates are used for paired connection between the target smart device and the target mobile terminal.
[0032] Before generating and issuing the digital certificate, in this embodiment, by setting the valid life cycle of the digital certificate, it is avoided that during the data transmission process when the target smart device is connected to the target mobile terminal later, information leakage accidents occur due to the long-term lack of identity verification.
[0033] In this embodiment, according to the target smart device, the device model and device function information are obtained, the device model and the device function information are used to generate a retrieval instruction, and the communication information record data set received by the same model smart device and transmitted to the corresponding mobile terminal and the frequency information of the historical information transmission behavior are traversed and matched in the information transmission big data to obtain the communication frequency record data set.
[0034] Data fitting is performed according to the communication frequency record data set, the deviation data deviating from the normal communication frequency is removed, the communication frequency data is obtained by fitting, the communication frequency is evaluated according to the communication frequency data, the period for automatically performing identity verification is obtained, and the period for automatically performing identity verification is used as the valid period for the public key infrastructure (PKI) to issue the digital certificate, that is, the primary certificate's valid life cycle.
[0035] Privacy processing is performed on the communication information record data set to obtain a communication information record data set with user-related information hidden for evaluating the importance degree of transmission information, and the obtained primary certificate's valid life cycle is optimized according to the evaluation result of the importance degree of transmission information to obtain the certificate's valid life cycle.
[0036] In this embodiment, by obtaining the communication frequency and communication content between the target mobile terminal and the target smart device in history to determine the issuance validity period of the short-term digital certificate for identity verification to ensure that user data is not leaked, the technical effect of avoiding information leakage and external program intrusion caused by single identity authentication, resulting in the reduction of the security of the user device and the risk of user privacy leakage is achieved.
[0037] S300: Generate and issue a first digital certificate to the target smart device;
[0038] S400: Generate and issue a second digital certificate to the target mobile terminal, where the first digital certificate and the second digital certificate share a key;
[0039] Specifically, in this embodiment, the digital certificate includes device public key information, identification information, certificate validity period, and PKI digital signature, and the digital certificate is used to ensure the legitimacy of the key during identity authentication. A first digital certificate is generated based on the target smart device basic information combined with the certificate life cycle obtained in step S200 and issued to the target smart device, and a second digital certificate is generated based on the target mobile terminal combined with the certificate life cycle and issued to the target mobile terminal. The first digital certificate and the second digital certificate share a key, and during identity authentication, the legitimacy of the identity is verified based on the key.
[0040] S500: The target smart device initiates a connection pairing request to the target mobile terminal based on the first digital certificate;
[0041] S600: The target mobile terminal performs identity authentication with the target smart device based on the second digital certificate to obtain an identity authentication result;
[0042] Specifically, in this embodiment, after determining that identity authentication can be performed and the target mobile terminal and target smart device that are matched and connected to complete information transmission are completed, after the target mobile terminal initiates a connection pairing invitation, the target smart device initiates a connection pairing request to the target mobile terminal, and the target smart device sends the first digital certificate to the target mobile terminal. The target mobile terminal obtains the key information in the first digital certificate and compares it with the key in its own second digital certificate to determine the integrity of the certificate, completes identity authentication, and obtains an identity authentication result. This embodiment issues digital certificates based on public key infrastructure, thereby improving the reliability of the connection between the mobile terminal and the smart device, and avoiding the possibility of external code invading the user's mobile terminal when simply performing identity authentication connection, causing security risks.
[0043] S700: When the identity authentication result is authentication passed, a communication connection is established between the target smart device and the target mobile terminal;
[0044] Furthermore, the method steps provided in this application also include:
[0045] S710: When the identity authentication result is authentication failure, the target smart device sends a connection failure instruction to the user;
[0046] S720: The user reconnects and pairs the target mobile terminal with the target mobile terminal again based on the connection failure instruction.
[0047] Further, the method steps provided by this application further include:
[0048] S730: Preset connection pairing failure parameters;
[0049] S740: When the identity authentication result is authentication failure and the number of times the user fails to connect and pair based on the connection failure instruction reaches the pre-set connection pairing failure parameter;
[0050] S750: The target intelligent device generates a retrieval instruction according to the first digital certificate;
[0051] S760: Based on the retrieval instruction, traverse the certificate database to obtain the original mobile terminal that matches the target intelligent device;
[0052] S770: The target intelligent device sends a loss warning to the original mobile terminal, where the loss warning is the loss location information of the target intelligent device.
[0053] Specifically, in this embodiment, when the identity authentication result is authentication success, it indicates that the identity verification between the target mobile terminal and the target intelligent device is passed, and the current communication connection between the two is highly reliable, and the communication connection between the target intelligent device and the target mobile terminal can be performed.
[0054] On the contrary, when the identity authentication result is authentication failure, the target intelligent device sends a connection failure instruction to the owner user of the mobile terminal participating in the identity authentication connection. The connection failure instruction is attached with a connection failure handling method. Based on the guidance of the connection failure instruction, the user sends a connection pairing invitation for the mobile terminal again, and restarts the connection pairing between the target mobile terminal and the target mobile terminal, avoiding misjudging signal problems during the pairing connection transmission process as a pair of devices without a shared key relationship between the mobile terminal and the intelligent device.
[0055] The preset connection pairing failure parameter is the upper limit of the number of times the mobile terminal and the intelligent device restart the connection failure. When the identity authentication result is authentication failure and the number of times the user fails to connect and pair based on the connection failure instruction reaches the pre-set connection pairing failure parameter, it indicates that there is no pairing relationship between the currently initiated mobile terminal for connection matching and authentication and the target intelligent device, and there may be a situation where the intelligent device is lost.
[0056] In this embodiment, the target intelligent device that cannot be paired generates a retrieval instruction according to the first digital certificate and sends a retrieval request to the certificate database of the public key infrastructure. Since the certificate database is a database storing the digital certificates, public keys and relevant certificate directories issued by the public key infrastructure, the target intelligent device can find the corresponding second digital certificate of the target mobile terminal that matches it in the certificate database according to the issued first digital certificate, and find the original paired target mobile terminal based on the second digital certificate. The target intelligent device sends a loss warning including the lost location information of the target intelligent device to the original mobile terminal, facilitating the target mobile terminal to know the location of the target intelligent device for recovery, and avoiding the leakage of user information caused by the movement of the intelligent device and property losses of the user's intelligent device.
[0057] In this embodiment, when an event of unsuccessful matching between an intelligent device and a mobile terminal occurs, preset connection pairing failure parameters are used to assist in determining whether an event of loss of the intelligent device occurs, achieving the effect of avoiding misidentifying an identity authentication failure caused by poor communication as an event of loss of the intelligent device, improving the accuracy of the anti-theft performance of the intelligent device, and at the same time combining the certificate database traversal retrieval function to find and determine the original paired mobile terminal to send the lost location information, facilitating the user to retrieve the lost intelligent device.
[0058] S800: Determine whether the first digital certificate and the second digital certificate reach the valid life cycle of the certificate. When reaching the valid life cycle of the certificate, regenerate the first digital certificate and the second digital certificate.
[0059] Specifically, in this embodiment, after the target mobile terminal and the target intelligent device successfully authenticate their identities and communicate for a certain period of time, to avoid the situation of long-term information transmission without identity authentication, which may lead to accidents such as external code intrusion to steal intelligent device information or intrusion into the mobile terminal to steal information, the first digital certificate and the second digital certificate used for identity authentication and pairing in this embodiment are set with the same valid life cycle of the certificate. When reaching the valid life cycle of the certificate, the public key infrastructure (PKI) automatically regenerates the first digital certificate and the second digital certificate, and the target intelligent device and the target mobile terminal automatically repeat the identity authentication process of steps S500 - S700 to re-establish a communication connection.
[0060] This embodiment determines the target smart device and the target mobile terminal; determines the valid life cycle of the certificate issued according to the target smart device and the target mobile terminal, thereby improving the security of information transmission between devices compared to a one-time ID card, generates and issues a first digital certificate to the target smart device; generates and issues a second digital certificate to the target mobile terminal, the first digital certificate and the second digital certificate share a key; the target smart device initiates a connection pairing request to the target terminal based on the first digital certificate; the target mobile terminal performs identity authentication with the target smart device based on the second digital certificate to obtain an identity authentication result; when the identity authentication result is authentication passed, the communication connection between the target smart device and the target mobile terminal is performed; it is determined whether the first digital certificate and the second digital certificate have reached the valid life cycle of the certificate, and the first digital certificate and the second digital certificate are regenerated when the valid life cycle of the certificate is reached. The technical effect of matching and connecting mobile terminals and smart devices based on a strict identity authentication system is achieved, increasing the cost of crime, increasing the probability of recovering lost mobile terminals, avoiding user privacy leakage, and protecting the property safety of user mobile terminals is achieved.
[0061] Further, such as Figure 3 As shown, the importance of transmission information is evaluated according to the communication information record data set, and step S250 of the method provided by the present application further includes:
[0062] S251: preset information volume threshold;
[0063] S252: Filter the communication information record data set according to the information volume threshold to obtain a communication information sample data set;
[0064] S253: constructing an information importance evaluation model, wherein the information importance evaluation model includes a plurality of information isolation evaluation channels;
[0065] S254: performing semantic recognition on the communication information sample data set to obtain a semantic recognition result;
[0066] S255: Inputting the semantic recognition result into the information importance evaluation model to obtain an output result, wherein the output result includes a plurality of information timeliness evaluation results, information privacy evaluation results and information sensitivity evaluation results;
[0067] S256: Calculate and obtain the evaluation result of the importance of the transmission information according to the output result.
[0068] Further, input the semantic recognition result into the information importance evaluation model to obtain an output result, where the output result includes multiple information timeliness evaluation results, information privacy evaluation results, and information sensitivity evaluation results. The method step S255 provided in this application further includes:
[0069] S255-1: Back up the semantic recognition result and input it into multiple evaluation channels with isolated information respectively;
[0070] S255-2: Output multiple groups of the information timeliness evaluation results, information privacy evaluation results, and information sensitivity evaluation results from multiple evaluation channels with isolated information;
[0071] S255-3: Perform fusion processing on multiple groups of the information timeliness evaluation results, information privacy evaluation results, and information sensitivity evaluation results to obtain an information timeliness fusion evaluation result, an information privacy fusion evaluation result, and an information sensitivity fusion evaluation result;
[0072] S255-4: Calculate the evaluation result of the importance of the transmitted information based on the information timeliness fusion evaluation result, the information privacy fusion evaluation result, and the information sensitivity fusion evaluation result.
[0073] Specifically, it should be understood that based on the communication information record data set obtained by the target intelligent device, the data volume is large, and directly performing the evaluation of the importance of the transmitted information requires high system computing power. Moreover, there are often a large number of data in the communication information record data set that do not have evaluation value. Therefore, in this embodiment, the communication information record data set is screened to reduce the waste of system computing power caused by invalid information and improve the evaluation accuracy and evaluation efficiency of the system for evaluating the importance of the transmitted information.
[0074] Specifically, preset an information volume threshold, where the information volume threshold includes a screening information time threshold and a screening information density threshold. Based on the information volume threshold, invalid low-density information and historical information from a long time ago in the communication information record data set can be screened out.
[0075] Screen the communication information record data set according to the information volume threshold to obtain a communication information sample data set, and perform semantic recognition on the communication information sample data set to obtain the semantic recognition result that is convenient for experts in the field of semantic analysis to evaluate the information importance.
[0076] Construct an information importance evaluation model to evaluate the communication importance. The information importance evaluation model includes multiple information-isolated evaluation channels. At the input end of the model, taking semantic analysis domain experts as units, each expert is assigned an information-isolated evaluation channel. The semantic recognition results are backed up and input into multiple information-isolated evaluation channels respectively for semantic analysis experts corresponding to the channels to conduct information evaluation from three dimensions: the timeliness angle reflecting the reference timeliness of the information to the user, the privacy angle reflecting the degree of privacy infringement of the information leakage to the user, and the information sensitivity reflecting the legal risk of information leakage, so as to obtain the evaluation results of the three dimensions given by the semantic analysis experts in each channel. Obtain multiple groups of the information timeliness evaluation results, information privacy evaluation results, and information sensitivity evaluation results output from multiple information-isolated evaluation channels. The information timeliness evaluation results, information privacy evaluation results, and information sensitivity evaluation results are all in the form of scores.
[0077] Perform fusion processing on multiple groups of the information timeliness evaluation results, information privacy evaluation results, and information sensitivity evaluation results to obtain the information timeliness fusion evaluation result, information privacy fusion evaluation result, and information sensitivity fusion evaluation result;
[0078] Perform summation calculation according to the information timeliness fusion evaluation result, information privacy fusion evaluation result, and information sensitivity fusion evaluation result to obtain the evaluation result of the importance degree of the transmitted information.
[0079] In this embodiment, by screening the communication information record data set to obtain information that meets the evaluation requirements, and constructing an information importance evaluation model to obtain the information importance evaluation conclusions provided by multiple experts from multiple dimensions, the subjectivity of the importance evaluation of the information transmitted between the target mobile terminal and the target intelligent device is reduced, achieving the technical effect of obtaining a relatively referenceable evaluation result of the importance degree of the transmitted information.
[0080] Further, optimize the effective life cycle of the primary certificate according to the evaluation result of the importance degree of the transmitted information to obtain the effective life cycle of the certificate. The method step S260 provided in this application further includes:
[0081] S261: Preset a threshold for the importance degree of the transmitted information;
[0082] S262: When the evaluation result of the importance degree of the transmitted information is higher than the threshold for the importance degree of the transmitted information, optimize the effective life cycle of the primary certificate according to the evaluation result of the importance degree of the transmitted information to obtain the effective life cycle of the certificate;
[0083] S263: When the evaluation result of the importance degree of the transmitted information falls within the threshold for the importance degree of the transmitted information, use the effective life cycle of the primary certificate as the effective life cycle of the certificate.
[0084] Specifically, it should be understood that theoretically, determining the valid life cycle of a digital certificate based on communication frequency data can meet the requirements for the accuracy and reliability of identity authentication between a mobile terminal and an intelligent device. However, when the importance of the information transmitted between the mobile terminal and the intelligent device is relatively high, it is necessary to increase the frequency of automatic identity authentication and shorten the valid life cycle of the digital certificate.
[0085] In this embodiment, the valid life cycle of the primary certificate obtained based on communication frequency data is optimized according to the evaluation result of the importance degree of the transmitted information. A threshold for the importance degree of the transmitted information is preset. The threshold for the importance degree of the transmitted information is a specification requirement for the importance degree of information transmission between the mobile terminal and the intelligent device. When the evaluation result of the importance degree of the transmitted information is higher than the threshold for the importance degree of the transmitted information, it indicates that circularly issuing the digital certificate based on the valid life cycle of the primary certificate cannot effectively avoid the occurrence of user information leakage risk events. Therefore, in this embodiment, the valid life cycle of the primary certificate is optimized with reference to the evaluation result of the importance degree of the transmitted information to obtain the valid life cycle of the certificate.
[0086] Conversely, when the evaluation result of the importance degree of the transmitted information falls within the threshold for the importance degree of the transmitted information, it indicates that the importance degree of the information currently transmitted between the target mobile terminal and the target intelligent device can ensure the security of information transmission based on the digital certificate issuance and identity authentication with the valid life cycle of the primary certificate. In this case, the valid life cycle of the primary certificate can be used as the valid life cycle of the certificate.
[0087] In this embodiment, by setting a threshold for the importance degree of the transmitted information and comparing and judging the evaluation result of the importance degree of the transmitted information obtained, the technical effect of avoiding immediately changing the valid life cycle of the issued digital certificate once the transmitted information is important and avoiding high-frequency identity authentication between the mobile terminal and the intelligent device is achieved.
[0088] Embodiment 2
[0089] Based on the same inventive concept as a method for secure authentication between a mobile terminal and an intelligent device in the foregoing embodiment, as Figure 4 shown, the present application provides a system for secure authentication between a mobile terminal and an intelligent device, wherein the system includes:
[0090] A connection object determination module 11, configured to determine a target intelligent device and a target mobile terminal;
[0091] A certificate term calculation module 12, configured to determine the valid life cycle of the issued certificate according to the target intelligent device and the target mobile terminal;
[0092] The device certificate issuance module 13 is used to generate and issue a first digital certificate to the target intelligent device;
[0093] The terminal certificate issuance module 14 is used to generate and issue a second digital certificate to the target mobile terminal, and the first digital certificate and the second digital certificate share a key;
[0094] The connection and pairing initiation module 15 is used for the target intelligent device to initiate a connection and pairing request to the target mobile terminal based on the first digital certificate;
[0095] The authentication execution module 16 is used for the target mobile terminal to perform authentication with the target intelligent device based on the second digital certificate to obtain an authentication result;
[0096] The communication connection execution module 17 is used to establish a communication connection between the target intelligent device and the target mobile terminal when the authentication result is authentication passed;
[0097] The certificate verification and update module 18 is used to determine whether the first digital certificate and the second digital certificate reach the valid life cycle of the certificate, and regenerate the first digital certificate and the second digital certificate when the valid life cycle of the certificate is reached.
[0098] Furthermore, the certificate term calculation module 12 further includes:
[0099] The device information collection unit is used to obtain the device model and device function information according to the target intelligent device;
[0100] The historical information matching unit is used to match the communication frequency record data set and the communication information record data set according to the device model and the device function information;
[0101] The communication frequency fitting unit is used to fit and obtain communication frequency data according to the communication frequency record data set;
[0102] The certificate cycle generation unit is used to generate a primary certificate valid life cycle according to the communication frequency data;
[0103] The communication information evaluation unit is used to evaluate the importance degree of the transmitted information according to the communication information record data set;
[0104] The certificate cycle determination unit is used to optimize the primary certificate valid life cycle according to the evaluation result of the importance degree of the transmitted information to obtain the certificate valid life cycle.
[0105] Furthermore, the communication information evaluation unit further includes:
[0106] An information threshold presetting unit for presetting an information quantity threshold;
[0107] An information screening execution unit for screening the communication information record data set according to the information quantity threshold to obtain a communication information sample data set;
[0108] An evaluation model construction unit for constructing an information importance evaluation model, wherein the information importance evaluation model includes a plurality of information-isolated evaluation channels;
[0109] A semantic recognition execution unit for performing semantic recognition on the communication information sample data set to obtain a semantic recognition result;
[0110] An evaluation result obtaining unit for inputting the semantic recognition result into the information importance evaluation model to obtain an output result, where the output result includes a plurality of information timeliness evaluation results, information privacy evaluation results, and information sensitivity evaluation results;
[0111] An evaluation result generating unit for calculating an evaluation result of the importance degree of the transmission information according to the output result.
[0112] Further, the evaluation result obtaining unit further includes:
[0113] An analysis data input unit for backing up the semantic recognition result and inputting it into the plurality of information-isolated evaluation channels respectively;
[0114] An evaluation result output unit for outputting multiple groups of the information timeliness evaluation results, information privacy evaluation results, and information sensitivity evaluation results from the plurality of information-isolated evaluation channels;
[0115] An evaluation result fusion unit for performing a fusion process on multiple groups of the information timeliness evaluation results, information privacy evaluation results, and information sensitivity evaluation results to obtain an information timeliness fusion evaluation result, an information privacy fusion evaluation result, and an information sensitivity fusion evaluation result;
[0116] An evaluation result calculation unit for calculating an evaluation result of the importance degree of the transmission information according to the information timeliness fusion evaluation result, the information privacy fusion evaluation result, and the information sensitivity fusion evaluation result.
[0117] Further, the certificate cycle determination unit further includes:
[0118] An evaluation threshold presetting unit for presetting a threshold for the importance degree of the transmission information;
[0119] A certificate term calculation unit, configured to optimize the effective life cycle of the primary certificate according to the evaluation result of the importance degree of the transmission information and obtain the effective life cycle of the certificate when the evaluation result of the importance degree of the transmission information is higher than the threshold of the importance degree of the transmission information;
[0120] A certificate term determination unit, configured to use the effective life cycle of the primary certificate as the effective life cycle of the certificate when the evaluation result of the importance degree of the transmission information falls within the threshold of the importance degree of the transmission information.
[0121] Further, the communication connection execution module 17 further includes:
[0122] A failure instruction sending unit, configured to send a connection failure instruction to the user by the target intelligent device when the authentication result is authentication failure;
[0123] A reconnection pairing specifying unit, configured to perform connection pairing between the target mobile terminal and the target mobile terminal again by the user based on the connection failure instruction.
[0124] Further, the method steps provided in this application further include:
[0125] A frequency parameter presetting unit, configured to preset a connection pairing failure parameter;
[0126] A reconnection frequency comparison unit, configured to when the authentication result is authentication failure and the number of times of connection pairing failure by the user based on the connection failure instruction reaches the preset failure parameter of pre-connection pairing;
[0127] A retrieval instruction generating unit, configured to generate a retrieval instruction by the target intelligent device according to the first digital certificate;
[0128] An original device matching unit, configured to traverse the certificate database based on the retrieval instruction to obtain an original mobile terminal matching the target intelligent device;
[0129] A loss warning sending unit, configured to send a loss warning to the original mobile terminal by the target intelligent device, where the loss warning is the loss location information of the target intelligent device.
[0130] Any of the above methods or steps can be stored as computer instructions or programs in various types of computer memories, and the computer instructions or programs are recognized by various types of computer processors, thereby implementing any of the above methods or steps.
[0131] Based on the above specific embodiments of the present invention, those skilled in the art of this technical field, without departing from the principle of the present invention, any improvements and modifications made to the present invention shall fall within the patent protection scope of the present invention.
Claims
1. A method for security authentication of a mobile terminal and a smart device, It is characterized in that The method comprises: Determine the target smart device and target mobile terminal; Determine the valid life cycle of the certificate for issuing the certificate according to the target smart device and the target mobile terminal; Generating and issuing a first digital certificate to the target smart device; Generating and issuing a second digital certificate to the target mobile terminal, wherein the first digital certificate and the second digital certificate share a key; The target smart device initiates a connection pairing request to the target mobile terminal based on the first digital certificate; The target mobile terminal performs identity authentication with the target smart device based on the second digital certificate to obtain an identity authentication result; When the identity authentication result is authentication passed, a communication connection is established between the target smart device and the target mobile terminal; Determine whether the first digital certificate and the second digital certificate have reached the valid life cycle of the certificates, and regenerate the first digital certificate and the second digital certificate when the valid life cycle of the certificates has been reached; Determining the certificate validity life cycle of the issued certificate according to the target smart device and the target mobile terminal includes: Obtain device model and device function information according to the target smart device; According to the device model and the device function information, matching the communication frequency record data set and the communication information record data set; Obtaining communication frequency data according to the communication frequency record data set fitting; Generate a primary certificate validity life cycle according to the communication frequency data; Evaluate the importance of the transmitted information based on the communication information record data set; The effective life cycle of the primary certificate is optimized according to the evaluation result of the importance of the transmitted information to obtain the effective life cycle of the certificate.
2. The method according to claim 1, It is characterized in that The importance of the transmitted information is evaluated according to the communication information record data set, including: Preset information volume threshold; Filtering the communication information record data set according to the information volume threshold to obtain a communication information sample data set; Constructing an information importance evaluation model, wherein the information importance evaluation model includes a plurality of information isolation evaluation channels; Performing semantic recognition on the communication information sample data set to obtain a semantic recognition result; Inputting the semantic recognition result into the information importance evaluation model to obtain an output result, wherein the output result includes a plurality of information timeliness evaluation results, information privacy evaluation results and information sensitivity evaluation results; The importance evaluation result of the transmission information is obtained by calculation according to the output result.
3. The method according to claim 2, It is characterized in that The semantic recognition result is input into the information importance evaluation model to obtain an output result, wherein the output result includes a plurality of information timeliness evaluation results, information privacy evaluation results and information sensitivity evaluation results, including: Backing up the semantic recognition results and inputting them into the evaluation channels of multiple information isolations respectively; Outputting a plurality of groups of information timeliness evaluation results, information privacy evaluation results and information sensitivity evaluation results from a plurality of information-isolated evaluation channels; Fusion processing is performed on the timeliness evaluation results, information privacy evaluation results, and information sensitivity evaluation results of multiple groups of the said information to obtain the timeliness fusion evaluation result, information privacy fusion evaluation result, and information sensitivity fusion evaluation result of the information; The importance evaluation result of the transmitted information is calculated based on the timeliness fusion evaluation result, information privacy fusion evaluation result, and information sensitivity fusion evaluation result of the said information.
4. The method according to claim 2, characterized in that, Optimizing the effective life cycle of the primary certificate according to the importance evaluation result of the transmitted information to obtain the effective life cycle of the certificate, including: Presetting a threshold for the importance evaluation result of the transmitted information; When the importance evaluation result of the transmitted information is higher than the threshold for the importance evaluation result of the transmitted information, optimizing the effective life cycle of the primary certificate according to the importance evaluation result of the transmitted information to obtain the effective life cycle of the certificate; When the importance evaluation result of the transmitted information falls within the threshold for the importance evaluation result of the transmitted information, taking the effective life cycle of the primary certificate as the effective life cycle of the certificate.
5. The method according to claim 1, characterized in that, The method further includes: When the identity authentication result is authentication failure, the target intelligent device sends a connection failure instruction to the user; The user reconnects and pairs the target intelligent device with the target mobile terminal based on the connection failure instruction.
6. The method according to claim 5, characterized in that, The method further includes: Presetting a connection pairing failure parameter; When the identity authentication result is authentication failure and the number of connection pairing failures by the user based on the connection failure instruction reaches the pre-set connection pairing failure parameter; The target intelligent device generates a retrieval instruction according to the first digital certificate; Traversing the certificate database based on the retrieval instruction to obtain the original mobile terminal matching the target intelligent device; The target intelligent device sends a loss warning to the original mobile terminal, where the loss warning is the loss location information of the target intelligent device.
7. A security authentication system for a mobile terminal and an intelligent device, characterized in that, The system includes: A connection object determination module for determining a target intelligent device and a target mobile terminal; A certificate term calculation module for determining the effective life cycle of the issued certificate according to the target intelligent device and the target mobile terminal; A device certificate issuance module for generating and issuing a first digital certificate to the target intelligent device; A terminal certificate issuance module for generating and issuing a second digital certificate to the target mobile terminal, where the first digital certificate and the second digital certificate share a key; A connection pairing start module for the target intelligent device to initiate a connection pairing request to the target mobile terminal based on the first digital certificate; An identity verification execution module for the target mobile terminal to perform identity authentication with the target intelligent device based on the second digital certificate to obtain an identity authentication result; A communication connection execution module, configured to perform a communication connection between the target intelligent device and the target mobile terminal when the identity authentication result is authentication passed; A certificate verification and update module, configured to determine whether the first digital certificate and the second digital certificate reach the valid life cycle of the certificate, and regenerate the first digital certificate and the second digital certificate when reaching the valid life cycle of the certificate; The certificate term calculation module further includes: A device information collection unit, configured to obtain a device model and device function information according to the target intelligent device; A historical information matching unit, configured to match a communication frequency record data set and a communication information record data set according to the device model and the device function information; A communication frequency fitting unit, configured to obtain communication frequency data by fitting according to the communication frequency record data set; A certificate cycle generation unit, configured to generate a primary certificate valid life cycle according to the communication frequency data; A communication information evaluation unit, configured to evaluate the importance degree of transmitted information according to the communication information record data set; A certificate cycle determination unit, configured to optimize the primary certificate valid life cycle according to the evaluation result of the importance degree of transmitted information to obtain the certificate valid life cycle.
Citation Information
Patent Citations
Intelligent fitness equipment and data transmission control method
CN107469281A