Certificate issuance method and system based on matter protocol

By introducing a three-level certificate structure into the Matter protocol and using intermediate devices to issue node certificates, the problem of Matter devices needing to connect to the cloud for network configuration is solved, achieving the effect of reducing the load on both the local network configuration and the cloud.

CN115714975BActive Publication Date: 2026-04-21HANGZHOU TUYA INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HANGZHOU TUYA INFORMATION TECH CO LTD
Filing Date
2022-11-02
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In existing technologies, Matter devices must maintain a connection with the cloud during the network configuration process, making them unusable in offline scenarios. Furthermore, the cloud processing capacity becomes overloaded when issuing large batches of certificates.

Method used

A three-tier certificate structure is adopted, in which intermediate certificates are issued for intermediate devices through the cloud, and the intermediate devices issue node certificates for Matter devices, thereby enabling local network configuration and reducing the processing load on the cloud.

Benefits of technology

This enables Matter devices to be configured for network without needing to connect to the cloud, reducing the processing load on the cloud and improving the applicability of the devices in offline scenarios as well as the processing performance of the cloud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115714975B_ABST
    Figure CN115714975B_ABST
Patent Text Reader

Abstract

The application relates to a certificate issuing method and system based on a Matter protocol, which is applied to an intermediate device and comprises the following steps: in the process of network configuration of a Matter device, in response to a node operation certificate issuing request of the Matter device, issuing a node operation certificate for the Matter device based on an intermediate certificate of the intermediate device, wherein the intermediate certificate is issued based on a root certificate of a cloud; and sending the node operation certificate, the intermediate certificate and the root certificate of the cloud to the Matter device. According to the certificate issuing method and system based on the Matter protocol, the intermediate certificate of the intermediate device is issued based on the root certificate of the cloud, and the node certificate of the network configuration Matter device is issued by the intermediate device, a three-level certificate structure is realized, the connection with the cloud does not need to be maintained when the Matter device is network configured, local network configuration can be realized, and the processing load of the cloud is effectively reduced by issuing the node certificate of the network configuration Matter device by the intermediate device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of smart home technology, and in particular to a certificate issuance method and system based on the Matter protocol. Background Technology

[0002] In the Matter protocol, a group of nodes within the same network share the same security domain, allowing secure communication between them. This group of devices is called Fabric. A node is a uniquely identifiable and addressable resource in the network. A node can be a Matter device or a client. Each node possesses a node certificate issued by the Fabric root certificate, enabling secure communication between nodes.

[0003] Node certificates within the same Fabric are identical, and all node certificates are issued by the same root certificate. In practical applications, it is usually necessary to assign Fabric credentials to new nodes so that they can communicate with other nodes in the same Fabric. This process is called commissioning or network configuration.

[0004] During the network configuration process for Matter devices, certificates need to be issued to them. Current technology typically issues these certificates directly through the cloud, meaning the cloud issues certificates to the Matter devices based on its own root certificate, enabling the devices to perform subsequent authentication communications. Summary of the Invention

[0005] The inventors discovered that if the node certificate for each Matter device is directly issued by the cloud, it will bring some limitations. For example, the Matter device must maintain a connection with the cloud during the network configuration process and must be connected to the network at all times, making it unusable in offline scenarios. In addition, the cloud will directly issue the node certificate for the Matter device each time, which will affect the cloud's processing performance, especially when a large number of certificates are issued concurrently, posing a challenge to the cloud's processing performance.

[0006] In view of this, according to the first aspect of this application, a certificate issuance method based on the Matter protocol is provided, applied to an intermediate device, the method comprising:

[0007] During the network configuration process for Matter devices, in response to a node operation certificate issuance request from a Matter device, a node operation certificate is issued for the Matter device based on the intermediate certificate of the intermediate device, wherein the intermediate certificate is issued based on the root certificate in the cloud; and

[0008] Send the node operation certificate, the intermediate certificate, and the root certificate in the cloud to the Matter device.

[0009] According to a second aspect of this application, a certificate issuance method based on the Matter protocol is provided, applied in the cloud, the method comprising:

[0010] In response to an intermediate certificate request from an intermediate device, an intermediate certificate is issued for the intermediate device based on the root certificate in the cloud; and

[0011] The intermediate certificate and the root certificate are sent to the intermediate device.

[0012] According to a third aspect of this application, an electronic device is provided, characterized in that it comprises:

[0013] Processor; and

[0014] A memory storing computer instructions that, when executed by the processor, cause the processor to perform the method described in the first aspect.

[0015] According to a fourth aspect of this application, a non-transitory computer storage medium is provided, which stores a computer program that, when executed by a plurality of processors, causes the processors to perform the method described in the first aspect.

[0016] According to the certificate issuance method and system based on the Matter protocol provided in this application, intermediate certificates are issued to intermediate devices through the root certificate in the cloud, and node certificates are issued to Matter devices in the distribution network through the intermediate devices, thus realizing a three-level certificate structure. When configuring Matter devices in the network, there is no need to maintain a connection with the cloud, and local network configuration can be achieved. Moreover, issuing node certificates to Matter devices in the distribution network through intermediate devices effectively reduces the processing load on the cloud. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings, without exceeding the scope of protection claimed by this application.

[0018] Figure 1 This is a schematic diagram of an Internet of Things (IoT) communication system according to this application.

[0019] Figure 2 This is a schematic diagram of a certificate issuance system based on the Matter protocol according to an embodiment of this application.

[0020] Figure 3 This is a flowchart of a certificate issuance method based on the Matter protocol according to an embodiment of this application.

[0021] Figure 4 This is a flowchart of a certificate issuance method based on the Matter protocol according to another embodiment of this application.

[0022] Figure 5 This is a structural diagram of an electronic device provided in an embodiment of this application. Detailed Implementation

[0023] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0024] Figure 1 This is a schematic diagram of an Internet of Things (IoT) communication system according to this application. Figure 1 This includes two types of cloud ecosystems. The dashed line delineates the on-premises or internal cloud ecosystem, while the area outside the dashed line represents the third-party cloud ecosystem. For example... Figure 1 As shown, the internal cloud ecosystem can be described as a graffiti-style cloud ecosystem, which includes the cloud, clients, routers, gateways / hubs, WiFi devices, Bluetooth devices, Zigbee devices, and Thread devices. Clients can be terminal devices such as mobile phones and tablets, which run apps (applications) for WiFi devices, Bluetooth devices, Zigbee devices, and Thread devices to access the cloud and interact with it, including adding and deleting devices. Routers provide internet access channels, and gateways / hubs are used for protocol conversion and device management, including adding and deleting devices and managing device online and offline status. The Matter protocol supports both WiFi and Thread protocols. WiFi and Thread devices can directly access the cloud via the Matter protocol. WiFi devices can access the cloud directly through a router; Thread devices access the cloud through a router and gateway, without requiring protocol conversion by the gateway. The gateway's role is simply to pass information through. Devices that support the Matter protocol are referred to as Matter devices. For protocols not supported by the Matter protocol, such as Bluetooth and Zigbee, Bluetooth and Zigbee devices need to undergo protocol conversion by a gateway when accessing the cloud. Devices that do not support the Matter protocol are referred to as non-Matter devices.

[0025] Figure 1 The diagram illustrates the connectivity and data transmission relationships between the various components or devices of the internal cloud ecosystem, as well as the connectivity relationships between the internal cloud ecosystem and the cloud, WiFi devices, and thread devices of third-party cloud ecosystems. When the internal cloud ecosystem is not associated with a third-party cloud ecosystem, communication and data processing can occur between the cloud and devices, and between devices themselves, according to an internal protocol (for example, for Tuya's internal cloud ecosystem, the internal protocol is a custom protocol defined by Tuya). When the internal cloud ecosystem is associated with a third-party cloud ecosystem, interconnection between the two cloud ecosystems is achieved through the Matter protocol.

[0026] exist Figure 1 In this context, for clients within the internal cloud ecosystem controlling third-party Matter devices (including WiFi and thread devices), according to one embodiment, the client can control the third-party Matter devices via the cloud, routers, and gateways; according to another embodiment, the client can control the third-party Matter devices via routers and gateways. During the process of client control of third-party Matter devices, the Matter protocol is used to achieve interconnection between the two cloud ecosystems, enabling clients in the internal cloud ecosystem to control third-party Matter devices. Similarly, or correspondingly, clients in the third-party cloud ecosystem can also control Matter devices in the internal cloud ecosystem via the Matter protocol.

[0027] exist Figure 1 In order to gain control of other cloud ecosystems, non-Matter devices (including Bluetooth and Zigbee devices) need to be mapped to a Matter gateway via a gateway.

[0028] This application is Figure 1 The system shown presents a solution for certificate issuance during the Matter device network configuration process. In general, this application provides a certificate issuance scheme based on the Matter protocol. A root certificate exists in the cloud. Upon a certificate issuance request from an intermediate device, the cloud issues an intermediate certificate to the intermediate device using the root certificate. The intermediate device then issues node certificates to the Matter devices configured on the network using the intermediate certificate. This eliminates the need to maintain a connection with the cloud during Matter device network configuration, enabling local network configuration. Furthermore, issuing node certificates to the Matter devices via intermediate devices instead of the cloud effectively reduces the processing load on the cloud.

[0029] Figure 2 This is a schematic diagram of a certificate issuance system based on the Matter protocol according to an embodiment of this application. Figure 2As shown, the system includes a cloud platform, intermediate devices, and Matter devices. The intermediate devices can be an app client, a gateway device, or a combination of both. The Matter devices are nodes that are configured on the network.

[0030] For intermediate devices, they are equipped with an intermediate certificate, which can be called an ICAC (Intermediate CA Certificate). This intermediate certificate is issued by the cloud after the intermediate device sends an Intermediate Certificate Signing Request (ICSR) to the cloud, based on its root certificate. Specifically, after a user logs into the intermediate device, a key pair is generated in its system security zone or keychain, and an ICSR is generated. The intermediate device sends the ICSR to the cloud, and the cloud issues the ICAC intermediate certificate based on its root certificate. The intermediate certificate has an expiration date; it does not need to be regenerated within the expiration period, but it needs to be reissued by the cloud after the expiration date. The root certificate in the cloud, called an RCAC (Root CA Certificate), can be self-signed using the cloud's private key or issued by a Certificate Authority (CA). After issuing the ICAC intermediate certificate, the cloud sends both the root certificate and the intermediate certificate to the intermediate device.

[0031] During the Matter device network configuration process, after the intermediate device establishes a connection with the Matter device and performs a series of security authentications, the Matter device sends a Node Certificate Request (NOCR) to the intermediate device. Upon receiving this request, the intermediate device issues a Node Operational Certificate (NOC) to the Matter device using its intermediate certificate and the key pair in the security zone. The intermediate device then sends the root certificate RCAC, intermediate certificate ICAC, and NOC to the Matter device. The Matter device will subsequently use these certificates to establish secure communication. The NOC may carry the Fabric ID and a unique identifier for the node, such as NodeId (Node Operational Identifier). NodeId can be a 64-bit number used to uniquely identify each node in the Fabric. For the Matter device being configured, the NOC includes the unique identifier of the Matter device and the identifier of the current Fabric.

[0032] According to one embodiment, an intermediate device can issue Node Operation Certificates (NOCs) for all nodes in the current Fabric through an intermediate certificate. The intermediate device in this application, as a node in the Fabric, can also issue its own Node Operation Certificates (NOCs) through an intermediate certificate.

[0033] exist Figure 2 Based on the system shown, according to one aspect of this application, a certificate issuance method based on the Matter protocol is provided. Figure 3 This is a flowchart of a certificate issuance method based on the Matter protocol according to an embodiment of this application. Figure 3 The method shown is applied to intermediate devices and includes the following steps.

[0034] Step S301: During the network configuration process for the Matter device, in response to the node operation certificate issuance request of the Matter device, a node operation certificate is issued for the Matter device based on the intermediate certificate of the intermediate device.

[0035] According to one specific embodiment, the intermediate certificate of the intermediate device is issued based on the root certificate in the cloud. During the Matter device's network configuration process, after the intermediate device establishes a connection with the Matter device and performs a series of security authentications, the Matter device sends a Node Certificate Request (NOCR) to the intermediate device. Upon receiving the request, the intermediate device issues a Node Operation Certificate (NOC) to the Matter device using the intermediate certificate and the key pair in the security zone.

[0036] Step S302: Send the node operation certificate, the intermediate certificate, and the root certificate in the cloud to the Matter device.

[0037] After issuing the Node Operation Certificate (NOC), the intermediate device also sends the root certificate (RCAC), intermediate certificate (ICAC), and Node Operation Certificate (NOC) to the Matter device. The Matter device will then use these certificates to establish secure communication.

[0038] The intermediate certificate of an intermediate device is issued by the cloud based on its root certificate after the intermediate device sends an Intermediate Certificate Issuance Request (ICSR). Specifically, after a user logs into the intermediate device, a key pair is generated in its system security zone or keychain, and an Intermediate Certificate Issuance Request (ICSR) is generated. The intermediate device then sends the ICSR to the cloud, and the cloud issues the intermediate certificate ICAC based on its root certificate.

[0039] so, Figure 3 The method further includes: sending an intermediate certificate issuance request to the cloud; and receiving the intermediate certificate and the cloud's root certificate, both issued based on the cloud's root certificate.

[0040] According to one embodiment, an intermediate device can issue Node Operation Certificates (NOCs) for all nodes in the current Fabric through an intermediate certificate. The intermediate device in this application, as a node in the Fabric, can also issue its own Node Operation Certificates (NOCs) through an intermediate certificate.

[0041] so, Figure 3 The method also includes: issuing a node operation certificate for the intermediate device itself based on the intermediate certificate.

[0042] exist Figure 2 Based on the system shown, according to another aspect of this application, a certificate issuance method based on the Matter protocol is provided. Figure 4 This is a flowchart of a certificate issuance method based on the Matter protocol according to another embodiment of this application. Figure 4 The method shown is applied in the cloud and includes the following steps.

[0043] Step S401: In response to the intermediate certificate request from the intermediate device, issue an intermediate certificate for the intermediate device based on the root certificate in the cloud.

[0044] According to one embodiment, after a user logs into the intermediate device, a key pair is generated in its system security zone or keychain, and an Intermediate Certificate Issuance Request (ICSR) is generated. The intermediate device sends the ICSR to the cloud, and the cloud issues an intermediate certificate ICAC based on its root certificate. The intermediate certificate has an expiration date; it does not need to be regenerated within the expiration period, but needs to be reissued by the cloud after the expiration date.

[0045] According to one embodiment, the root certificate in the cloud can be self-signed by the private key in the cloud or issued by a certificate authority.

[0046] Step S402: Send the intermediate certificate and the root certificate to the intermediate device.

[0047] In one embodiment, after issuing the intermediate certificate ICAC, the cloud sends both the root certificate and the intermediate certificate to the intermediate device. The intermediate device then issues node certificates for the nodes within the Fabric based on the intermediate certificate.

[0048] According to the certificate issuance method and system based on the Matter protocol provided in this application, intermediate certificates are issued to intermediate devices through the root certificate in the cloud, and node certificates are issued to Matter devices in the distribution network through the intermediate devices, thus realizing a three-level certificate structure. When configuring Matter devices in the network, there is no need to maintain a connection with the cloud, and local network configuration can be achieved. Moreover, issuing node certificates to Matter devices in the distribution network through intermediate devices effectively reduces the processing load on the cloud.

[0049] See Figure 5 , Figure 5 An electronic device is provided, including a processor; and a memory storing computer instructions that, when executed by the processor, cause the processor to perform the computer instructions as follows: Figure 3 and Figure 4 The method and its detailed scheme are shown.

[0050] It should be understood that the above-described device embodiments are merely illustrative, and the device disclosed in this invention can be implemented in other ways. For example, the division of units / modules described in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, integrated into another system, or some features may be ignored or not executed.

[0051] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of the present invention can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.

[0052] If the integrated unit / module is implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor or chip can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the on-chip cache, off-chip memory, and storage can be any suitable magnetic or magneto-optical storage medium, such as resistive random access memory (RRAM), dynamic random access memory (DRAM), static random access memory (SRAM), enhanced dynamic random access memory (EDRAM), high-bandwidth memory (HBM), hybrid memory cube (HMC), etc.

[0053] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this disclosure. The aforementioned memory includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0054] This application embodiment also provides a non-transitory computer storage medium storing a computer program, which, when executed by one or more processors, causes the processors to perform actions such as... Figure 3 and Figure 4 The method and its detailed scheme are shown.

[0055] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.

[0056] The embodiments of this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are only for the purpose of helping to understand the method and core ideas of this application. Furthermore, any changes or modifications made by those skilled in the art based on the ideas of this application, and on the specific implementation methods and application scope of this application, are all within the scope of protection of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A certificate issuance method based on the Matter protocol, applied to an intermediate device, the method comprising: During the network configuration process for Matter devices, in response to the node operation certificate issuance request of the Matter devices, a node operation certificate is issued for the Matter devices based on the intermediate certificate of the intermediate device and the key in the security zone. The intermediate certificate is issued based on the root certificate issued in the cloud. Send the node operation certificate, the intermediate certificate, and the root certificate in the cloud to the Matter device; The certificate issuance method based on the Matter protocol further includes: Send an intermediate certificate issuance request to the cloud; Receive the intermediate certificate issued by the cloud-based root certificate and the cloud-based root certificate sent by the cloud; The intermediate device issues its own node operation certificate based on the intermediate certificate; wherein the node operation certificate includes: the unique identifier of the Matter device and the identifier of the current Fabric.

2. The method as described in claim 1, wherein, The intermediate device includes a client, a gateway device, and / or a combination of a client and a gateway device.

3. A certificate issuance method based on the Matter protocol, applied in the cloud, the method comprising: In response to an intermediate certificate request from an intermediate device, an intermediate certificate is issued for the intermediate device based on the root certificate in the cloud. The intermediate certificate and the root certificate are sent to the intermediate device, and the intermediate device issues node certificates for the nodes in Fabric based on the intermediate certificate. The certificate issuance method based on the Matter protocol further includes: During the network configuration process for Matter devices, the intermediate device responds to the node operation certificate issuance request of the Matter devices and issues a node operation certificate for the Matter devices based on the intermediate certificate of the intermediate device and the key in the security zone. The intermediate certificate is issued based on the root certificate in the cloud.

4. The method of claim 3, wherein, The root certificate in the cloud is generated by self-signing the private key in the cloud or issued by a certificate authority.

5. A certificate issuance system based on the Matter protocol, comprising a cloud, an intermediate device, and a Matter device, wherein: The Matter is used to send a node operation certificate issuance request to the intermediate device during the network configuration process, and to receive the node operation certificate, the intermediate certificate of the intermediate device, and the root certificate of the cloud from the intermediate device. The intermediate device performs the method as described in any one of claims 1 to 2; The cloud performs the method as described in claim 3 or 4.

6. An electronic device, characterized in that, include: processor; as well as A memory storing computer instructions that, when executed by the processor, cause the processor to perform the method according to any one of claims 1-4.

7. A non-transitory computer storage medium storing a computer program that, when executed by a plurality of processors, causes the processors to perform the method of any one of claims 1-4.

Citation Information

Patent Citations

  • Digital certificate issuing method, device, terminal entity and system

    CN114598455A