Sharing method and storage medium of IoT device without account system
Through the method of generating credentials without account binding and sharing, the inconvenience and security risks of account registration in IoT device management is solved, and the function of quickly sharing and managing devices is realized, which improves privacy and security.
Patent Information
- Application Number
- CN202211122653.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-15
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2042-09-15
AI Technical Summary
The existing IoT device management method requires users to register an account, which has problems such as inconvenience in use and security risks, especially when others need to assist in managing the equipment, which affects personal privacy and assistance effects.
Using an account-free Internet of Things device sharing method, through the mobile smart terminal and Internet of Things device without an account binding, a unique ID and electronic credentials are generated, a mapping relationship between the terminal identifier and the Internet of Things device is established, and a server is used to generate sharing credentials to achieve rapid sharing and management of the device.
It realizes that the Internet of Things devices can be quickly shared and managed without users registering an account, simplifies the device management process, improves the privacy and security of the system, and avoids the risks caused by account leakage.
Smart Images

Figure CN115766057B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an Internet of Things link communication technology, and in particular to a sharing method and storage medium for an IoT device without an account system. Background Art
[0002] The Internet of Things (IoT) is a network that connects physical devices, vehicles, buildings, and other things embedded with electronic devices, software, sensors, etc. to the Internet, enabling these objects to collect and exchange data. IoT devices are devices used to achieve links within the Internet of Things, such as smart home devices.
[0003] Usually, IoT devices are bound to user accounts for easy management, but in actual use, the user account needs to be logged in on mobile smart terminals such as mobile phones, which is inconvenient to use. In addition, the existing method requires users to register an account in advance or have a third-party account (such as QQ, WeChat, Facebook, etc.), which can easily leak the user's personal privacy during the use of the account. In some cases, it is claimed that IoT devices are bound to mobile smart terminals such as mobile phones, but it is not that the IoT devices are directly bound to the mobile phone. In fact, the IoT devices are first bound to the account, and then the account or the corresponding app is bound to the mobile phone. Its essence is to manage devices based on the user's account, and mobile smart terminals such as mobile phones are also managed devices. When implementing IoT device management operations such as remote access, it is also based on the user's account. The corresponding user account must be logged in, which also has security issues and inconvenience. And when the user needs friends to help manage IoT devices when it is inconvenient for him, the existing method must require friends to register an account, which seriously affects the personal privacy of others and affects the effect of users inviting others to help. Summary of the invention
[0004] In view of the above-mentioned problems of the prior art, the present invention provides a method for sharing IoT devices without an account system. After a mobile smart terminal such as a mobile phone is directly bound to the IoT device without an account, friends can be invited to assist in managing the IoT device conveniently and quickly.
[0005] In order to achieve the above object, the technical solution adopted by the present invention is as follows:
[0006] A method for sharing an IoT device without an account system is applied to an IoT device management client and configured on a mobile smart terminal so that it has a unique terminal identifier. The sharing method includes:
[0007] After binding with the IoT device without an account, the unique ID of the IoT device and the electronic certificate generated by the IoT device based on the terminal identification are obtained, so that the terminal identification and the unique ID of the IoT device form a mapping relationship, and the mapping relationship and the electronic certificate are saved locally;
[0008] In response to confirming the operation of sharing the specified IoT device, obtaining the unique ID of the IoT device and its electronic certificate stored locally, and constructing a request for obtaining the sharing credentials based on them;
[0009] Send the sharing credential acquisition request to the server, so that the server records the sharing information with the unique ID of the IoT device and the electronic credential according to its own database and generates the sharing credential based on the unique ID of the IoT device and the electronic credential;
[0010] In response to the operation of confirming the sharing target, sending the sharing credentials generated by the server to the sharing target;
[0011] After the sharing target obtains the sharing credentials, it obtains the corresponding IoT device unique ID and its electronic certificate from the server and saves them locally, completes the establishment of a mapping relationship between the sharing target and the corresponding IoT device, and completes the temporary binding of the sharing target and the corresponding IoT device.
[0012] Specifically, the terminal identification is configured as a random number of sufficient length or / and the identity information code of the mobile smart terminal; the electronic certificate generated by the IoT device based on the terminal identification is a new string composed of the terminal identification and a random string generated by the IoT device, which is obtained through an irreversible algorithm.
[0013] Specifically, the server records the sharing information with the unique ID of the IoT device and the electronic certificate according to its own database and generates a sharing credential based on the unique ID of the IoT device and the electronic certificate, including:
[0014] Use the unique ID of the IoT device and the electronic certificate to calculate the information summary as the index key, and generate a key-value pair and store it in the server database;
[0015] The index key is then used to generate a QR code as a sharing credential and returned to the IoT device management client.
[0016] Specifically, after the sharing target obtains the sharing credentials, it identifies the index key in the sharing credentials, obtains the corresponding IoT device unique ID and its electronic certificate from the server database according to the index key, and saves them locally in the sharing target to establish a mapping relationship between the sharing target and the corresponding IoT device.
[0017] Furthermore, after the sharing target obtains the corresponding IoT device unique ID and its electronic certificate from the server database according to the index key, the entry of the index key is deleted from the server database or marked as invalid.
[0018] Specifically, after obtaining the sharing credentials, the sharing target uses the IoT device management client on different mobile smart terminals to obtain the corresponding IoT device unique ID and its electronic certificate.
[0019] Furthermore, the process of binding the IoT device management client with the IoT device without an account is as follows:
[0020] In response to determining that an IoT device administrator password is input, the terminal identifier and the input IoT device administrator password are combined into a character string, and a first verification value is calculated by an irreversible algorithm;
[0021] Sending the terminal identification and the first verification value to the IoT device to be bound through the local area network for verification;
[0022] Determine whether the verification is passed, if not, terminate the operation, if yes, receive the electronic certificate based on the terminal identification and the unique ID of the IoT device to be bound returned by the IoT device to be bound, and save the received electronic certificate locally;
[0023] A mapping relationship between the terminal identifier and the unique ID of the IoT device to be bound is established, and the mapping relationship is saved locally to complete account-free binding.
[0024] Furthermore, the present invention also provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps of the above-mentioned method for sharing IoT devices without an account system are implemented.
[0025] Compared with the prior art, the present invention has the following beneficial effects:
[0026] The present invention uses the unique ID of the IoT device and its electronic certificate stored locally on the client to generate sharing credentials from the corresponding server on the basis of the account-free binding between the IoT device management client configured on the mobile smart terminal and the IoT device, so that the sharing target can use the sharing credentials to directly and quickly obtain the unique ID and electronic certificate required for binding from the server, and then establish a mapping binding relationship with the IoT device on different mobile smart terminals, so as to realize the management operation of the specified IoT device by different mobile smart terminals. The implementation of this process does not require the user to register the account information himself, nor does it require the sharing target to register the account information. It not only greatly simplifies the implementation process of IoT device sharing management, but also does not require the server to manage the user account information, and will not leak the user privacy, effectively improving the privacy security of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 The figure is a flow chart of a sharing method implemented by a client in an embodiment of the present invention.
[0028] Figure 2 This is a schematic diagram of the process of performing account-free binding on a client in an embodiment of the present invention.
[0029] Figure 3 This is a schematic diagram of an application example of an embodiment of the present invention. DETAILED DESCRIPTION
[0030] The present invention is further described below in conjunction with the accompanying drawings and examples. The embodiments of the present invention include but are not limited to the following examples.
[0031] Example
[0032] like Figures 1 to 3 As shown, the sharing method of the IoT device without an account system provided in this embodiment is applied to the IoT device management client, configured in the mobile smart terminal so that it has a unique terminal identification, and the sharing method includes:
[0033] After binding with the IoT device without an account, the unique ID of the IoT device and the electronic certificate generated by the IoT device based on the terminal identification are obtained, so that the terminal identification and the unique ID of the IoT device form a mapping relationship, and the mapping relationship and the electronic certificate are saved locally;
[0034] In response to confirming the operation of sharing the specified IoT device, obtaining the unique ID of the IoT device and its electronic certificate stored locally, and constructing a request for obtaining the sharing credentials based on them;
[0035] Send the sharing credential acquisition request to the server, so that the server records the sharing information with the unique ID of the IoT device and the electronic credential according to its own database and generates the sharing credential based on the unique ID of the IoT device and the electronic credential;
[0036] In response to the operation of confirming the sharing target, sending the sharing credentials generated by the server to the sharing target;
[0037] After the sharing target obtains the sharing credentials, it obtains the corresponding IoT device unique ID and its electronic certificate from the server and saves them locally, completes the establishment of a mapping relationship between the sharing target and the corresponding IoT device, and completes the temporary binding of the sharing target and the corresponding IoT device.
[0038] Specifically, the terminal identification is configured as a random number of sufficient length or / and the identity information code of the mobile smart terminal. When the identity information code of the mobile smart terminal is used, the identity information code can be generated by a specified code on the mobile smart terminal, such as generating a string that is unique enough by IMEI+manufacturer code+model code+WIFI MAC+Bluetooth MAC as the terminal identification; the electronic certificate generated by the IoT device based on the terminal identification is a new string composed of the terminal identification and a random string generated by the IoT device, which is obtained by an irreversible algorithm, wherein the irreversible algorithm uses a HASH algorithm to calculate a specific HASH value as the corresponding verification value, and the HASH algorithm is such as SHA1, SHA256, etc.
[0039] Specifically, the server records the sharing information with the unique ID of the IoT device and the electronic certificate according to its own database and generates a sharing credential based on the unique ID of the IoT device and the electronic certificate, including:
[0040] Use the unique ID of the IoT device and the electronic certificate to calculate the information summary as the index key, and generate a key-value pair and store it in the server database;
[0041] The index key is then used to generate a QR code as a sharing credential and returned to the IoT device management client.
[0042] Specifically, after the sharing target obtains the sharing credentials, it identifies the index key in the sharing credentials, obtains the corresponding IoT device unique ID and its electronic certificate from the server database according to the index key, and saves them locally in the sharing target to establish a mapping relationship between the sharing target and the corresponding IoT device.
[0043] Furthermore, after the sharing target obtains the corresponding IoT device unique ID and its electronic certificate from the server database according to the index key, the entry of the index key is deleted from the server database or marked as invalid.
[0044] Specifically, after obtaining the sharing credentials, the sharing target uses the IoT device management client on different mobile smart terminals to obtain the corresponding IoT device unique ID and its electronic certificate.
[0045] Furthermore, the process of binding the IoT device management client with the IoT device without an account is as follows:
[0046] In response to determining that an IoT device administrator password is input, the terminal identifier and the input IoT device administrator password are combined into a character string, and a first verification value is calculated by an irreversible algorithm;
[0047] The terminal identification and the first verification value are sent to the IoT device to be bound through the local area network for verification; during verification, the IoT device combines the terminal identification and the administrator password stored therein into a character string, and uses the same irreversible algorithm to calculate the second verification value, and determines whether the first verification value and the second verification value are consistent. If they are consistent, the verification is passed, and if they are inconsistent, the verification is not passed;
[0048] Determine whether the verification is passed, if not, terminate the operation, if yes, receive the electronic certificate based on the terminal identification and the unique ID of the IoT device to be bound returned by the IoT device to be bound, and save the received electronic certificate locally;
[0049] A mapping relationship between the terminal identifier and the unique ID of the IoT device to be bound is established, and the mapping relationship is saved locally to complete account-free binding.
[0050] Furthermore, this embodiment provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned method for sharing IoT devices without an account system are implemented.
[0051] The computer storage medium of the embodiment of the present application can adopt any combination of one or more computer-readable media. Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable storage media can be, for example, - but not limited to - electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or devices, or any combination of the above. More specific examples (non-exhaustive lists) of computer-readable storage media include: electrical connections with one or more wires, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory FLASH), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this document, computer-readable storage media can be any tangible medium containing or storing a program, which can be used by an instruction execution system, device or device or used in combination with it.
[0052] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, which carry computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0053] Program code embodied on a computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0054] Computer program code for performing the operations of the present application may be written in one or more programming languages or a combination thereof, including object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0055] like Figure 3 As shown, the present invention also provides the following application examples to further illustrate the sharing method process of the IoT device without an account system:
[0056] Taking smart routers as an example of iot devices, smart home devices such as smart lights and smart gateways that do not have display devices and input devices can also be used; taking mobile phones as an example of mobile smart terminals, smart terminals such as tablets and PDAs that have display devices and input devices can also be used, and the iot device management client APP is installed and configured on the mobile phone.
[0057] The mobile phone APP generates a unique terminal identification through the identification generation module. The identification generation module generates a mobile phone ID (terminal identification) by generating a random number of a specified length or extracting the mobile phone's IMEI + manufacturer code + model code + WIFI MAC + Bluetooth MAC combination. When the smart router is started for the first time or restored to default, it automatically generates a 16-byte random string as the router ID. It can also use rules similar to those for generating terminal identification on the mobile phone APP to extract corresponding information to form the router ID and save it in its local FLASH; the administrator password of the smart router is configured by the user according to the router operation requirements and can also be modified according to user needs.
[0058] When the user opens the mobile phone APP and selects the target smart router to be shared, the router ID and corresponding electronic certificate of the selected smart router are extracted;
[0059] Send a sharing request to the server using the router ID and electronic certificate as parameters, such as https: / / :server domain name / share / router?key=electronic certificate&routerId=router ID;
[0060] Based on the https request, the server extracts the router ID and electronic certificate, calculates the MD5 code using the router ID + electronic certificate as the index key, and generates a key-value pair and stores it in the server database; then it generates a QR code with the index key as the content and returns it to the mobile phone APP;
[0061] The mobile APP prompts the user to send the QR code to the target object to be shared;
[0062] The target object uses the mobile phone APP to scan the received QR code on different mobile smart terminals to obtain the index key;
[0063] Then the target object's mobile APP initiates a server call with the index key as a parameter, such as https / / :server domain name / qecode? key = index key in the QR code;
[0064] The server extracts the corresponding router ID + electronic certificate from the database according to the index key and returns it to the target object's mobile phone APP. At the same time, the server deletes the entry in the database. In order to ensure that it becomes invalid immediately after being shared once, to prevent others from misidentifying and obtaining it, and to ensure data security, if you want to share it again, you need to regenerate the QR code;
[0065] The target object's mobile phone APP saves the corresponding router ID and electronic certificate received and completes the establishment of the mapping relationship;
[0066] The sharing process is now complete, and the target user can manage and operate the corresponding router through the saved router ID and electronic certificate.
[0067] The above embodiments are only preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any changes made by adopting the design principles of the present invention and performing non-creative work on this basis should fall within the protection scope of the present invention.
Claims
1. A method for sharing IoT devices without an account system. It is characterized in that Applied to the IoT device management client, configured on the mobile smart terminal so that it has a unique terminal identification, the sharing method includes: After binding with the IoT device without an account, the unique ID of the IoT device and the electronic certificate generated by the IoT device based on the terminal identification are obtained, so that the terminal identification and the unique ID of the IoT device form a mapping relationship, and the mapping relationship and the electronic certificate are saved locally; In response to confirming the operation of sharing the specified IoT device, obtaining the unique ID of the IoT device and its electronic certificate stored locally, and constructing a request for obtaining the sharing credentials based on them; Send the sharing credential acquisition request to the server, so that the server records the sharing information with the unique ID of the IoT device and the electronic credential according to its own database and generates the sharing credential based on the unique ID of the IoT device and the electronic credential; In response to the operation of confirming the sharing target, sending the sharing credentials generated by the server to the sharing target; After the sharing target obtains the sharing credentials, it obtains the corresponding IoT device unique ID and its electronic certificate from the server and saves them locally, completes the establishment of a mapping relationship between the sharing target and the corresponding IoT device, and completes the temporary binding of the sharing target and the corresponding IoT device.
2. The sharing method according to claim 1, It is characterized in that The terminal identification is configured as a random number of a specified length and / or the identity information code of the mobile smart terminal; the electronic certificate generated by the IoT device based on the terminal identification is a new string composed of the terminal identification and a random string generated by the IoT device, which is obtained through an irreversible algorithm.
3. The sharing method according to claim 1, It is characterized in that The method of causing the server to record the sharing information with the unique ID of the IoT device and the electronic certificate according to its own database and generate a sharing credential based on the unique ID of the IoT device and the electronic certificate includes: Use the unique ID of the IoT device and the electronic certificate to calculate the information summary as the index key, and generate a key-value pair and store it in the server database; The index key is then used to generate a QR code as a sharing credential and returned to the IoT device management client.
4. The sharing method according to claim 3, It is characterized in that After the sharing target obtains the sharing credentials, it identifies the index key in the sharing credentials, obtains the corresponding IoT device unique ID and its electronic certificate from the server database based on the index key, and saves them locally in the sharing target to establish a mapping relationship between the sharing target and the corresponding IoT device.
5. The sharing method according to claim 4, It is characterized in that After the sharing target obtains the corresponding IoT device unique ID and its electronic certificate from the server database according to the index key, the entry of the index key is deleted from the server database or marked as invalid.
6. The sharing method according to claim 5, It is characterized in that After obtaining the sharing credentials, the sharing target uses the IoT device management client on different mobile smart terminals to obtain the corresponding IoT device unique ID and its electronic certificate.
7. The sharing method according to any one of claims 1 to 6, It is characterized in that The process of binding the IoT device management client with the IoT device without an account is as follows: In response to determining that an IoT device administrator password is input, the terminal identifier and the input IoT device administrator password are combined into a character string, and a first verification value is calculated by an irreversible algorithm; Sending the terminal identification and the first verification value to the IoT device to be bound through the local area network for verification; Determine whether the verification is passed, if not, terminate the operation, if yes, receive the electronic certificate based on the terminal identification and the unique ID of the IoT device to be bound returned by the IoT device to be bound, and save the received electronic certificate locally; A mapping relationship between the terminal identifier and the unique ID of the IoT device to be bound is established, and the mapping relationship is saved locally to complete account-free binding.
8. A computer-readable storage medium having a computer program stored thereon, It is characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Intelligent home appliance configuration method and apparatus
CN107181651A
Sharing system based on smart home system
CN110830340A