Authentication method and device of device identity, storage medium and electronic device
Patent Information
- Application Number
- CN202211349529.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-31
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2042-10-31
AI Technical Summary
[0005]本发明实施例提供了一种设备身份的认证方法及装置、存储介质及电子装置,以至少解决物联网设备连接网络过程中身份认证可能存在单设备欺骗目标云端的问题
[0026] This invention addresses the issue of a first device requesting communication authentication from a target cloud. The first device reports first information, which includes second communication information collected by the first device from other devices in its network and first communication information corresponding to the first device. The communication information comprises at least device characteristics and network characteristics of the network. Based on the first network characteristics, the invention searches the target cloud for second information including the first network characteristics and determines a set of device characteristics corresponding to the second information. The second information is reported by a second device, and the first network characteristics are used to determine that the first and second devices are in the same network. If a target device characteristic matching the first device characteristic exists in the set of device characteristics, authentication of the first device is performed. The first device characteristic is a characteristic possessed by the first device itself. This solution solves the problem of potential single-device deception of the target cloud during IoT device network connection authentication. Building upon existing verification information, it utilizes a mutually recognized device identity authentication method to verify the authenticity of interconnected devices simultaneously accessing the target cloud. This quickly identifies whether a device is forged or assesses the likelihood of forgery, enhancing the security of traditional IoT device identity authentication. Furthermore, this authentication is implemented through software capabilities, without incurring additional costs.
Smart Images

Figure CN115766121B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of smart home technology, and more specifically, to a device authentication method and apparatus, storage medium and electronic device. Background Technology
[0002] Most current device authentication is based on single sign-on. That is, if device A wants to access cloud services, the authentication occurs between device A and the cloud. If device A is hijacked during communication with the cloud, or if some or all of the security information stored on device A is leaked, device A may be forged. This would prevent the cloud from accurately identifying whether it is the real device A, which would threaten the security of the cloud service and could lead to a large number of forged devices accessing the network and generating a large amount of invalid data.
[0003] There is currently no effective solution to the problems in related technologies, such as the inability to effectively eliminate spoofed devices and the inability to verify the trustworthiness of connected devices.
[0004] Therefore, it is necessary to improve the relevant technology to overcome the aforementioned defects. Summary of the Invention
[0005] This invention provides a device authentication method and apparatus, storage medium and electronic device to at least solve the problem that a single device may deceive the target cloud during the authentication process of IoT devices connecting to the network.
[0006] According to one aspect of the present invention, a device identity authentication method is provided, comprising: when a first device applies for communication authentication to a target cloud, determining first information reported by the first device, wherein the first information includes: second communication information collected by the first device from other devices in its network and first communication information corresponding to the first device, wherein the information composition of the communication information includes at least: device characteristics corresponding to the device and network characteristics of the network in which the device is located; searching for second information including the first network characteristics in the target cloud according to the first network characteristics corresponding to the first information, and determining a set of device characteristics corresponding to the second information, wherein the second information is reported by a second device, and the first network characteristics are used to determine that the first device and the second device are in the same network; and if there is a target device characteristic in the set of device characteristics that matches the first device characteristic corresponding to the first device, performing authentication of the first device, wherein the first device characteristic is a device characteristic possessed by the first device itself.
[0007] In an exemplary embodiment, after searching for second information including the first network feature in the target cloud based on the first network feature corresponding to the first information, and determining the device feature set corresponding to the second information, the method further includes: obtaining a list of valid devices of the target object in the target cloud; wherein the list of valid devices consists of devices pre-marked as valid devices by the target object and devices with a communication security level higher than a preset security level; if the second device exists in the list of valid devices, confirming that the device identity of the second device in the target cloud is a valid device, wherein the valid device is used to indicate a real device whose communication security meets the requirements and has an entity; if the second device does not exist in the list of valid devices, confirming that the device identity of the second device in the target cloud is a device to be authenticated.
[0008] In an exemplary embodiment, after confirming that the second device is a valid device in the target cloud, the method further includes: performing auxiliary authentication of the first device's device identity through the second device; and identifying the first device's device identity based on the result of the auxiliary authentication.
[0009] In an exemplary embodiment, assisting the authentication of the first device's device identity through the second device includes: authenticating the first device's device identity as a valid device if a target device feature identical to the device feature exists in the device feature set; and authenticating the first device's device identity as an invalid device if no target device feature identical to the device feature exists in the device feature set.
[0010] In an exemplary embodiment, after confirming that the second device's device identity in the target cloud is a device to be authenticated, the method further includes: determining the similarity value of all device features carried in the first information and all device features carried in the second information in terms of feature content, wherein the feature content includes at least one of the following: the external address of the network where the device is located, the number of nodes within the network where the device is located, the services provided by the device and the version number of the services, the port number of the device responding to requests, the probing requests received by the device from other devices, and the broadcast data and features received by the device from other devices; the similarity value is used to indicate the proportion of the first device features that are identical to the second device features in the first device features; if the similarity value is greater than a dynamic threshold, the device identity of the first device is authenticated as a valid device; if the similarity value is less than or equal to the dynamic threshold, the device identity of the first device is authenticated as an invalid device.
[0011] In an exemplary embodiment, before determining the first information reported by the first device, the method further includes: determining whether the first device is connected to the distributed network corresponding to the target cloud; if the first device has been connected to the distributed network and the first device has the target capability, the first device actively starts a device task to collect other device characteristics corresponding to other devices in the distributed network; if the first device has been connected to the distributed network and the first device does not have the target capability, the first device stops accessing the distributed network.
[0012] In an exemplary embodiment, the method further includes: upon determining the device identity corresponding to the first device, obtaining first verification information sent by the first device, wherein the first verification information includes account information and password information corresponding to the first device; determining the verification result of the first verification information in the target cloud; and determining whether the first device is allowed to interact with the target cloud based on the verification result and the device identity authentication result of the first device.
[0013] In an exemplary embodiment, the method further includes determining whether the first device is allowed to interact with the target cloud based on the verification result and the device identity authentication result of the first device. The method further includes: if the verification result indicates that the first device has passed the verification of the target cloud and the first device is a valid device, determining that the first device has completed communication authentication and is allowed to interact with the target cloud; and if the verification result indicates that the first device has passed the verification of the target cloud and the first device is an invalid device, sending a registration prompt message to the first device to confirm a single connection, wherein the registration prompt message indicates that information collection is performed on the first device when it is determined that the first device is independently accessing the distributed network.
[0014] In an exemplary embodiment, the method further includes determining whether the first device is allowed to interact with the target cloud based on the verification result and the device identity authentication result of the first device. The method also includes: if the verification result indicates that the first device has failed the verification of the target cloud and the first device is a valid device, sending a prompt message to the first device to instruct it to check the first verification information; if the verification result indicates that the first device has failed the verification of the target cloud and the first device is an invalid device, prohibiting the first device from accessing the current distributed network again and adding the first device to the connection blacklist corresponding to the current distributed network.
[0015] According to another aspect of the present invention, a device authentication method apparatus is also provided, comprising: a determining module, configured to determine first information reported by the first device when the first device applies for communication authentication to a target cloud, wherein the first information includes: second communication information of other devices in the network where the first device is located collected by the first device and first communication information corresponding to the first device, wherein the information composition of the communication information includes at least: device features corresponding to the device and network features of the network where the device is located; a searching module, configured to search for second information including the first network features in the target cloud according to the first network features corresponding to the first information, and determine a set of device features corresponding to the second information, wherein the second information is reported by the second device, and the first network features are used to determine that the first device and the second device are in the same network; and an authentication module, configured to perform authentication of the first device when there is a target device feature in the set of device features that matches the first device feature corresponding to the first device, wherein the first device feature is a device feature possessed by the first device itself.
[0016] In an exemplary embodiment, the above-described apparatus further includes: a verification module, configured to obtain a list of valid devices of the target object in the target cloud; wherein the list of valid devices consists of devices pre-marked as valid devices by the target object and devices with a communication security level higher than a preset security level; if it is determined that the second device exists in the list of valid devices, verifying the device identity of the second device in the target cloud as a valid device, wherein the valid device is used to indicate a real device whose communication security meets the requirements and has an entity; if it is determined that the second device does not exist in the list of valid devices, verifying the device identity of the second device in the target cloud as a device to be authenticated.
[0017] In an exemplary embodiment, the above-mentioned confirmation module further includes: an auxiliary unit, configured to perform auxiliary authentication of the device identity of the first device through the second device; and to identify the device identity of the first device based on the result of the auxiliary authentication.
[0018] In an exemplary embodiment, the auxiliary unit described above is further configured to authenticate the device identity of the first device as a valid device when there is a target device feature identical to the device feature in the device feature set; and to authenticate the device identity of the first device as an invalid device when there is no target device feature identical to the device feature in the device feature set.
[0019] In an exemplary embodiment, the above-mentioned confirmation module further includes: a similarity unit, configured to determine the similarity value of all device features carried in the first information and all device features carried in the second information in terms of feature content, wherein the feature content includes at least one of the following: the external address of the network where the device is located, the number of nodes within the network where the device is located, the services provided by the device and the version number of the services, the port number of the device responding to requests, the probing requests received by the device from other devices, and the broadcast data and features received by the device from other devices; the similarity value is used to indicate the proportion of the first device features that are identical to the second device features in the first device features; if the similarity value is greater than a dynamic threshold, the device identity of the first device is authenticated as a valid device; if the similarity value is less than or equal to the dynamic threshold, the device identity of the first device is authenticated as an invalid device.
[0020] In an exemplary embodiment, the above-described apparatus further includes: an access module, configured to determine whether the first device is connected to the distributed network corresponding to the target cloud; if the first device has been connected to the distributed network and the first device has the target capability, the first device actively initiates a device task to collect other device characteristics corresponding to other devices in the distributed network; if the first device has been connected to the distributed network and the first device does not have the target capability, the first device stops accessing the distributed network.
[0021] In an exemplary embodiment, the above apparatus further includes: a verification module, configured to, upon determining the device identity corresponding to the first device, obtain first verification information sent by the first device, wherein the first verification information includes account information and password information corresponding to the first device; determine the verification result of the first verification information in the target cloud; and determine whether the first device is allowed to interact with the target cloud based on the verification result and the device identity authentication result of the first device.
[0022] In an exemplary embodiment, the verification module is further configured to: determine that the first device has completed communication authentication and is allowed to interact with the target cloud when the verification result indicates that the first device has passed the verification of the target cloud and the first device is a valid device; and send a registration prompt message to the first device to confirm a single connection when the verification result indicates that the first device has passed the verification of the target cloud and the first device is an invalid device, wherein the registration prompt message indicates that information collection is performed on the first device when it is determined that the first device has accessed the distributed network independently.
[0023] In an exemplary embodiment, the verification module is further configured to: send a prompt message to the first device indicating that the first device has failed the verification of the target cloud and the first device is a valid device; and prohibit the first device from accessing the current distributed network again and add the first device to the connection blacklist corresponding to the current distributed network when the verification result indicates that the first device has failed the verification of the target cloud and the first device is an invalid device.
[0024] According to another aspect of the present invention, a computer-readable storage medium is also provided, wherein a computer program is stored in the computer program, wherein the computer program is configured to execute the above-described device identity authentication method at runtime.
[0025] According to another aspect of the present invention, an electronic device is also provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes an authentication method for the device identity through the computer program.
[0026] This invention addresses the issue of a first device requesting communication authentication from a target cloud. The first device reports first information, which includes second communication information collected by the first device from other devices in its network and first communication information corresponding to the first device. The communication information comprises at least device characteristics and network characteristics of the network. Based on the first network characteristics, the invention searches the target cloud for second information including the first network characteristics and determines a set of device characteristics corresponding to the second information. The second information is reported by a second device, and the first network characteristics are used to determine that the first and second devices are in the same network. If a target device characteristic matching the first device characteristic exists in the set of device characteristics, authentication of the first device is performed. The first device characteristic is a characteristic possessed by the first device itself. This solution solves the problem of potential single-device deception of the target cloud during IoT device network connection authentication. Building upon existing verification information, it utilizes a mutually recognized device identity authentication method to verify the authenticity of interconnected devices simultaneously accessing the target cloud. This quickly identifies whether a device is forged or assesses the likelihood of forgery, enhancing the security of traditional IoT device identity authentication. Furthermore, this authentication is implemented through software capabilities, without incurring additional costs. Attached Figure Description
[0027] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0028] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0029] Figure 1 This is a schematic diagram of the hardware environment for a device identity authentication method according to an embodiment of the present invention;
[0030] Figure 2 This is a flowchart of a device identity authentication method according to an embodiment of the present invention;
[0031] Figure 3 This is a schematic diagram of the structure of a distributed network in a practical application according to an embodiment of the present invention;
[0032] Figure 4 This is a structural block diagram (a) of a device authentication method apparatus according to an embodiment of the present invention;
[0033] Figure 5 This is a structural block diagram (II) of a device authentication method apparatus according to an embodiment of the present invention. Detailed Implementation
[0034] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0035] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0036] According to one aspect of the present invention, a device identity authentication method is provided. This device identity authentication method is widely applicable to whole-house intelligent digital control application scenarios such as smart homes, smart home ecosystems, and intelligence house ecosystems. Optionally, in this embodiment, the above-mentioned device identity authentication method can be applied to, for example... Figure 1 The hardware environment shown consists of terminal device 102 and server 104. For example... Figure 1 As shown, server 104 is connected to terminal device 102 via a network and can be used to provide services (such as application services) to the terminal or clients installed on the terminal. A database can be set up on the server or independently of the server to provide data storage services for server 104. Cloud computing and / or edge computing services can be configured on the server or independently of the server to provide data processing services for server 104.
[0037] The aforementioned network may include, but is not limited to, at least one of the following: wired network, wireless network. The aforementioned wired network may include, but is not limited to, at least one of the following: wide area network, metropolitan area network, local area network. The aforementioned wireless network may include, but is not limited to, at least one of the following: Wi-Fi (Wireless Fidelity), Bluetooth. The terminal device 102 may not be limited to PC, mobile phone, tablet computer, smart air conditioner, smart range hood, smart refrigerator, smart oven, smart stove, smart washing machine, smart water heater, smart washing equipment, smart dishwasher, smart projector, smart TV, smart clothes rack, smart curtains, smart audio-visual equipment, smart socket, smart speaker, smart speaker box, smart fresh air equipment, smart kitchen and bathroom equipment, smart bathroom equipment, smart robot vacuum cleaner, smart window cleaning robot, smart mopping robot, smart air purifier, smart steam oven, smart microwave oven, smart water heater, smart air purifier, smart water dispenser, smart door lock, etc.
[0038] To address the aforementioned issues, this embodiment provides a device identity authentication method, including but not limited to applications in terminal devices. Figure 2 This is a flowchart of a device identity authentication method according to an embodiment of the present invention, the process including the following steps:
[0039] Step S202: When the first device requests communication authentication from the target cloud, determine the first information reported by the first device, wherein the first information includes: the second communication information of other devices in the network collected by the first device and the first communication information corresponding to the first device, and the information composition of the communication information includes at least: the device characteristics corresponding to the device and the network characteristics of the network where the device is located;
[0040] Step S204: Based on the first network feature corresponding to the first information, search for second information including the first network feature in the target cloud, and determine the device feature set corresponding to the second information, wherein the second information is reported by the second device, and the first network feature is used to determine that the first device and the second device are in the same network;
[0041] Step S206: If there is a target device feature in the device feature set that matches the first device feature corresponding to the first device, perform authentication of the first device, wherein the first device feature is a device feature that the first device itself possesses.
[0042] Using the above method, when the first device requests communication authentication from the target cloud, the first information reported by the first device is determined. This first information includes: second communication information collected by the first device from other devices in its network and the first communication information corresponding to the first device. The communication information comprises at least: device characteristics corresponding to the device and network characteristics of the network where the device is located. Based on the first network characteristics corresponding to the first information, the second information including the first network characteristics is searched in the target cloud, and a set of device characteristics corresponding to the second information is determined. The second information is reported by the second device, and the first network characteristics are used to determine that the first device and the second device are in the same network. If a target device characteristic matching the first device characteristic corresponding to the first device exists in the set of device characteristics, authentication of the first device is performed. The first device characteristic is a device characteristic possessed by the first device itself. This technical solution solves the problem of potential single-device deception of the target cloud during IoT device network connection authentication. Based on existing verification information, it uses a mutually recognized device identity authentication method to verify the authenticity of interconnected devices simultaneously accessing the target cloud, quickly identifying whether a device is forged or assessing the likelihood of forgery. This enhances the security of traditional IoT device identity authentication, and the authentication is implemented through software capabilities without incurring additional costs.
[0043] Optionally, the network features mentioned above include at least one of the following: the external IP address of the distributed network, the internal IP address allocation strategy of the distributed network, and the number of nodes inside the distributed network; the device features mentioned above include at least one of the following: the services provided by each device inside the distributed network and their version numbers, the port numbers of the devices inside the distributed network responding to requests, the probing requests received by the first device from other devices, and the broadcast data and features received by the first device from other devices.
[0044] It should be noted that when the network feature is the external IP address of a distributed network or the internal IP address allocation strategy corresponding to the distributed network, the main approach is to identify the consistency between the external IP address and / or internal IP address allocation strategy corresponding to the first information (equivalent to the first network feature in the above network embodiment) and the external IP address and / or internal IP address allocation strategy corresponding to the second information (equivalent to the second network feature in the above network embodiment). That is, when the external IP address and / or internal IP address allocation strategy are the same, it indicates that the first device and the second device are in the same network, and the first device is a real network device. This avoids the situation where the first device deceives the cloud service (equivalent to the target cloud in the above embodiment) and improves the security of authenticating the first device.
[0045] Optionally, when the network feature is the number of nodes within a distributed network, the specific number of nodes within the network is mainly used to identify whether the network has the same number of nodes, and to determine the first computing node corresponding to the first device among the nodes within the distributed network. Then, by determining whether the first computing node exists in other computing nodes besides the second computing node corresponding to the second device, the first computing node is used to determine whether the first device and the second device are in the same network based on the nodes.
[0046] It should be noted that the first information mentioned above is a feature information that is encrypted and shared to the target cloud. Specifically, the first information is determined in the following way: on the distributed computing nodes of the local area network corresponding to the current device, a security capability (i.e., the target capability in this embodiment of the invention) is set on each node using software. This security capability can dynamically collect feature information within its local area network and can share the collected feature information to the target cloud in an encrypted manner. The feature information mentioned above includes network features and device features.
[0047] Furthermore, the aforementioned device authentication methods are supplementary to the original authentication methods and need to be used in conjunction with them. Generally, they can only be used to verify authenticity, not authenticity; therefore, these methods can be called auxiliary authentication. However, in practical use, by detecting whether a device is counterfeit or assessing the likelihood of device counterfeiting, the credibility of the original authentication methods is comprehensively improved, greatly enhancing the security of interactions between devices.
[0048] It is understandable that the cloud service (target cloud) can identify (or probabilistically confirm) whether device A is counterfeit by using the network characteristics of device A (equivalent to the first device mentioned above), calling the security capabilities of other nodes in its network, and collecting feature information from different nodes.
[0049] In an exemplary embodiment, after searching for second information including the first network feature in the target cloud based on the first network feature corresponding to the first information, and determining the device feature set corresponding to the second information, the method further includes: obtaining a list of valid devices of the target object in the target cloud; wherein the list of valid devices consists of devices pre-marked as valid devices by the target object and devices with a communication security level higher than a preset security level; if the second device exists in the list of valid devices, confirming that the device identity of the second device in the target cloud is a valid device, wherein the valid device is used to indicate a real device whose communication security meets the requirements and has an entity; if the second device does not exist in the list of valid devices, confirming that the device identity of the second device in the target cloud is a device to be authenticated.
[0050] It should be noted that the aforementioned list of valid devices is dynamically updated within a preset period. For example, when the target adds a new device identified as a valid device on the target cloud, the list of valid devices is refreshed directly; or, if the list of valid devices is pre-set to be updated every 3 minutes, the content of the pre-set list of valid devices is updated after a timer is established, barring any other unforeseen circumstances; or, if the device associated with the cloud is determined to be a device with a high level of communication security, such as one whose communication encryption level exceeds normal encryption requirements, or a network testing device that is not subject to authentication. These are merely examples and do not limit the scope of this invention.
[0051] In an exemplary embodiment, after confirming that the second device is a valid device in the target cloud, the method further includes: performing auxiliary authentication of the first device's device identity using the second device; and identifying the first device's device identity based on the result of the auxiliary authentication. If a target device feature matching the device feature corresponding to the first device exists in the device feature set, authentication of the first device is performed.
[0052] In an exemplary embodiment, assisting the authentication of the first device's device identity through the second device includes: obtaining a set of device features carried by the second information uploaded by the second device; matching the set of device features with the device features corresponding to the first device; authenticating the first device's device identity as a valid device if a target device feature identical to the device feature exists in the set of device features; and authenticating the first device's device identity as an invalid device if no target device feature identical to the device feature exists in the set of device features.
[0053] Before authenticating the identity of the first device, the device identity of the second device, which assists in authenticating the first device, can be identified to improve the authentication efficiency of the first device. For example, if the target cloud is connected to three interconnected devices A, B, and C, where A is the device to be authenticated (i.e., the first device), B is a device already confirmed as valid by the target cloud, and C is a device that reports to the target cloud the characteristics of other devices and the network environment collected in the distributed network. If the target cloud determines that the information collected by B device S contains a feature that matches the characteristics of the device to be authenticated, A, then A and B exist in the same local area network. In this case, A can be directly determined as a valid device that truly exists in the current local area network based on the device identity of B.
[0054] In an exemplary embodiment, after confirming that the second device's device identity in the target cloud is a device to be authenticated, the method further includes: if it is determined that the second network feature corresponding to the second device is the same as the first network feature corresponding to the first device, calculating the similarity value of the first device feature in the first information reported by the first device and the first device feature in the second information reported by the second device in feature content information, wherein the feature content information includes at least one of the following: the external IP address of the network where the device is located, the number of nodes within the network where the device is located, the services provided by the device and the version number of the services, the port number of the device responding to requests, the probe requests received by the device from other devices, and the broadcast data and features received by the device from other devices; the similarity value is used to indicate the proportion of the first device feature containing the same feature content information as the second device feature in the first device feature; if the similarity value is greater than a dynamic threshold, authenticating the device identity of the first device as a valid device; if the similarity value is less than or equal to the dynamic threshold, authenticating the device identity of the first device as an invalid device.
[0055] It should be noted that the above dynamic threshold is related to the number of network nodes where the first device is located. In application, the dynamic threshold can be flexibly set according to the actual situation. For example, when there are 3 nodes in the network, the dynamic threshold can be set to 1 / 2, which means that when 1 / 2 of the device characteristics are the same, the first device can be authenticated. That is, when the ratio of the target device characteristics corresponding to the part of the second device characteristics corresponding to the second device characteristics corresponding to the first device characteristics corresponding to the first device characteristics exceeds 1 / 2, the device identity of the first device can be authenticated as a valid device; conversely, when the ratio does not reach 1 / 2, the device identity of the first device can be authenticated as an invalid device.
[0056] Optionally, to avoid errors caused by a single confirmation, the feature content matching between the C device feature information (i.e., the second information in the above embodiment) corresponding to device C and the A device feature information (i.e., the first information in the above embodiment) corresponding to device A can be determined. Based on the matching, it can be determined whether device A and device C are in the same local area network. That is, before performing the identity authentication of the current first device, the device identity of the second device that performs auxiliary authentication of the first device can be identified to improve the authentication efficiency of the device identity of the first device. For example, the target cloud currently has three interconnected devices A, B, and C connected to it. In this scenario, device A is the device to be authenticated (i.e., the first device), while devices B and C simultaneously report their own collected features of other devices and network environment characteristics gathered in the distributed network to the target cloud. At this point, the target cloud determines that device B's feature information contains a feature that matches the feature of device A to be authenticated. This indicates that device A and device B exist in the same local area network. Furthermore, the target cloud determines that device C's feature information contains a feature that matches the feature of device A to be authenticated. This indicates that device A and device C exist in the same local area network. Ultimately, device A is determined to be a valid device that actually exists in the current local area network.
[0057] Optionally, to improve efficiency, a preset threshold for determining if a device is genuine can be established. By combining the results of other devices determining whether device A is genuine, the validity of device A can be determined. Specifically: Suppose that device A is determined to be a fake device (i.e., an invalid device falsely existing in the current local area network) by device C, and a genuine valid device (actually existing in the current local area network) by device B. There are currently three such devices in the local area network. The probability of device A being determined as a valid device by other devices is calculated. This probability is determined by averaging the confirmation results from device B and device C, where the probability of a valid device is 1 and the probability of an invalid device is 0. Therefore, the probability of device A being a valid device is 0.5. The preset threshold for determining if a device is genuine in the current local area network is then obtained. If 0.5 is greater than the preset threshold, it indicates that device A's authentication result is valid; if 0.5 is less than or equal to the preset threshold, it indicates that device A's authentication result is invalid.
[0058] In an exemplary embodiment, before determining the first information reported by the first device, the method further includes: determining whether the first device is connected to the distributed network corresponding to the target cloud; if the first device has been connected to the distributed network and the first device has the target capability, the first device actively starts a device task to collect other device characteristics corresponding to other devices in the distributed network; if the first device has been connected to the distributed network and the first device does not have the target capability, the first device stops accessing the distributed network.
[0059] It is understandable that after the first device has been equipped with the ability to collect feature information (equivalent to the first information in the above embodiment) (equivalent to the target capability mentioned above) through software, when the first device connects to the distributed network (or local area network), it can actively start a device task to collect the features of other devices in the distributed network through the first device. This allows the first device to obtain the corresponding feature information, which includes: the device features and network features corresponding to the first device, and the set of device features and network features corresponding to other devices in the same network as the first device. This feature information is then shared with the cloud service (equivalent to the target cloud) in an encrypted manner. The cloud service can then use the network features of the first device to call the feature capabilities of other nodes in its network and collect feature information from different nodes. The feature information transmitted by the corresponding nodes of other devices can be used to identify (or probabilistically confirm) whether the first device is forged. In addition, when it is determined that the first device does not have the target capability, the current access of the first device to the distributed network is directly stopped to ensure the security of the connection between the target cloud and the first device.
[0060] In an exemplary embodiment, the method further includes: upon determining the device identity corresponding to the first device, obtaining first verification information sent by the first device, wherein the first verification information includes account information and password information corresponding to the first device; determining the verification result of the first verification information in the target cloud; and determining whether the first device is allowed to interact with the target cloud based on the verification result and the device identity authentication result of the first device.
[0061] In an exemplary embodiment, the method further includes determining whether the first device is allowed to interact with the target cloud based on the verification result and the device identity authentication result of the first device. The method further includes: if the verification result indicates that the first device has passed the verification of the target cloud and the first device is a valid device, determining that the first device has completed communication authentication and is allowed to interact with the target cloud; and if the verification result indicates that the first device has passed the verification of the target cloud and the first device is an invalid device, sending a registration prompt message to the first device to confirm a single connection, wherein the registration prompt message indicates that information collection is performed on the first device when it is determined that the first device is independently accessing the distributed network.
[0062] Understandably, when the first device is connecting to the target cloud for the first time and has not interacted with other devices in the network, the first device can initially access the cloud network by sending verification information to the cloud through the target. However, since other devices have not interacted with the first device, the second information they obtain does not include the device characteristics corresponding to the first device. Therefore, the device identity of the first device may be defaulted to an invalid device, indicating that the first device can only interact with the target cloud at this time. Furthermore, the target cloud can confirm that the first device is a real single-connection device by sending a registration prompt message to the first device to confirm the single connection.
[0063] In an exemplary embodiment, the method further includes determining whether the first device is allowed to interact with the target cloud based on the verification result and the device identity authentication result of the first device. The method also includes: if the verification result indicates that the first device has failed the verification of the target cloud and the first device is a valid device, sending a prompt message to the first device to instruct it to check the first verification information; if the verification result indicates that the first device has failed the verification of the target cloud and the first device is an invalid device, prohibiting the first device from accessing the current distributed network again and adding the first device to the connection blacklist corresponding to the current distributed network.
[0064] In other words, while confirming the identity of the first device, it is also necessary to verify whether the first verification information sent by the first device has been registered in the target cloud. If it has been registered and the first device is a valid device, it is determined that the first device is an existing device already connected to the network. After the verification information passes the target cloud verification, data interaction with the second device can be established through the target cloud, or other data information can be obtained from the target cloud. If the first device fails the target cloud verification, it indicates that the first verification information entered by the target object is abnormal, and the target object needs to be prompted to check whether there is an error in the input on the first device. If the first device is an invalid device and the target cloud verification fails, it indicates that the first device is a forged device. The device information corresponding to the first device is added to the connection blacklist of the current distributed network stored in the target cloud to ensure the security of data communication in the distributed network.
[0065] Obviously, the embodiments described above are merely some embodiments of the present invention, and not all embodiments. To better understand the above method, the following description, in conjunction with embodiments, illustrates the process, but is not intended to limit the technical solutions of the embodiments of the present invention. Specifically:
[0066] In related technologies, IoT devices need to be authenticated when accessing a network. The authentication methods commonly used by both parties in a communication are as follows:
[0067] 1. Two-way certificate authentication, also known as public key infrastructure authentication, is the most commonly used method.
[0068] 2. Pre-shared key authentication, in which both parties pre-store all or part of the authentication information before initiating authentication, and after initiating authentication, both parties use this reserved information to perform trust authentication.
[0069] 3. Combination method: This involves combining the methods mentioned above, or even proprietary standalone authentication algorithms, to achieve higher security.
[0070] However, the above methods are not very effective at identifying counterfeit devices, making it easy for a large number of counterfeit devices to access the cloud server, generating a lot of invalid data and reducing security.
[0071] As an optional implementation, a device authentication method based on distributed computing is provided. This method introduces a multi-device collaborative authentication mechanism within a distributed computing scenario and implements a security capability, referred to as the S-capability (i.e., the target capability in this embodiment), on each node of the distributed computing network. This security capability dynamically collects feature information within its network environment and can share the collected information to a cloud service in an encrypted manner. This shared feature information is called S-information. The S-information includes: device features and network features corresponding to the current device, and sets of device features and network features corresponding to other devices belonging to the same network as the current device. Furthermore, the S-information is shared by the current device to the cloud service (equivalent to the target cloud) in an encrypted manner. This allows the cloud service to determine other feature information shared by other devices in the same network as the current device by the network features included in the current device's feature information. Then, it compares the other feature information transmitted by other devices with the feature information corresponding to the current device to identify (or probabilistically confirm) whether the current device is forged. Additionally, when it is determined that the current device does not possess the target capability, the current device's access to the distributed network is directly stopped, ensuring the security of the connection between the target cloud and the current device. The above method can supplement the original authentication. By combining it with the original authentication methods, it can detect whether the device is counterfeit or assess the possibility of device counterfeiting before device interaction in actual use, thereby improving the credibility level of device authentication.
[0072] Optional, Figure 3 This is a schematic diagram of the structure of a distributed network in practical application according to an embodiment of the present invention. As shown in the figure, devices A, B, and C report information to the target cloud through a local area network gateway. Assume that device A applies for communication authentication to the target cloud and reports the corresponding first information to the target cloud. The first information includes: the device characteristics corresponding to device A and the network characteristics of the network where device A is located, as well as the device characteristics corresponding to other devices (device B and device C) and the network characteristics of the networks where other devices are located.
[0073] Furthermore, device B can also report corresponding second information to the target cloud. This second information includes: the device characteristics of device B and the network characteristics of the network where device B is located, as well as the device characteristics of other devices (device A and device C) and the network characteristics of the networks where those devices are located. Device C can also report corresponding third information to the target cloud. This third information includes: the device characteristics of device C and the network characteristics of the network where device C is located, as well as the device characteristics of other devices (device A and device B) and the network characteristics of the networks where those devices are located. It should be noted that the aforementioned first, second, and third information are all obtained through the S-capabilities existing on the distributed computing nodes corresponding to devices A, B, and C. These S-capabilities can be configured in the devices through software capabilities without changing the current device hardware.
[0074] Optionally, the network features in the first, second, and third information can be used to determine whether devices A, B, and C are in the same network. If the network features are the same, it is determined that devices A, B, and C are in the same network. At this time, further authentication of device A can be performed by determining whether there are matching device features among the device features of other devices corresponding to device B or device C.
[0075] It should be noted that, to improve authentication efficiency, the above authentication process also involves determining whether device B or device C is a valid device on the target cloud. Device B or device C, whose identity has been confirmed as a valid device, is used to authenticate device A. For example, if the target cloud has three interconnected devices A, B, and C, where device A is the device to be authenticated (i.e., the first device), device B has been confirmed as a valid device by the target cloud, and device C reports its own collected network environment characteristics and other device features collected in the distributed network to the target cloud. In this case, if the target cloud determines that the second information collected by device B (i.e., the second device) contains device features and network features that match those of device A to be authenticated, the same network features indicate that device A and device B exist in the same local area network. Therefore, device A's device identity can be directly determined based on device B's device identity. That is, if device B has been confirmed as a valid device by the target cloud, device A is determined to be a valid device that truly exists in the current local area network.
[0076] Furthermore, when it is impossible to determine whether devices B and C are valid devices in the target cloud, the similarity value can be compared between the first device feature in the first information corresponding to device A and the second device feature in the second information corresponding to device B or the third device feature in the third information corresponding to device C. When the similarity value exceeds the dynamic threshold, it indicates that device A has many identical features with device B or device C. Based on the settings, device A can be directly determined to be a valid device that actually exists in the current local area network.
[0077] In practical applications, A is a device awaiting confirmation, while B and C are devices that report simultaneously. The target cloud determines A to be false based on the second piece of information reported by B, and confirms A to be true based on the third piece of information reported by C. With a preset device threshold of 50%, device A is determined to be true by default. Alternatively, if A is a device awaiting confirmation, and B and C are devices that report simultaneously, and device B is the currently authenticated genuine device on the cloud platform, then device A's authenticity can be quickly determined based on device B, thus confirming device A's authentication result.
[0078] In summary, the process involves determining whether the device characteristics reported by device A are genuine (i.e., whether they are consistent with the information reported by other devices), and combining the content of the device characteristics to determine whether the cooperative business between device A and devices B and C within the network is normal; finally, the identity authentication of device A is completed based on the first, second, or third information.
[0079] Furthermore, this invention introduces a distributed computing node collaboration method into the device authentication method, employing multi-node collaborative authentication to improve the credibility of device authentication, thereby more effectively preventing devices from spoofing. It also introduces an S-capability implemented in a computer system that can be remotely invoked. This capability can collect network information around the device and output S-information in a pre-defined manner. The S-information reported by different devices can effectively eliminate spoofed devices, improving the efficiency of verifying device credibility. Through the above solutions, the security of traditional IoT device authentication is enhanced. Moreover, the S-capability is implemented in software, without incurring additional costs, making it low-cost and easy to deploy; it only requires integrating software with the S-capability into the device firmware.
[0080] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.
[0081] This embodiment also provides a device authentication method apparatus for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0082] Figure 4 This is a structural block diagram (a) of a device identity authentication method apparatus according to an embodiment of the present invention, the apparatus comprising:
[0083] The determination module 42 is used to determine the first information reported by the first device when the first device applies for communication authentication to the target cloud. The first information consists of the second communication information of other devices in the network collected by the first device and the first communication information corresponding to the first device. The information composition of the communication information includes at least the device characteristics corresponding to the device and the network characteristics of the network where the device is located.
[0084] The search module 44 is used to search in the target cloud for second information reported by the second device that carries the same network characteristics as the first information, and to determine the set of device characteristics corresponding to the second information;
[0085] The authentication module 46 is used to perform authentication of the first device when there is a target device feature in the device feature set that matches the device feature corresponding to the first device.
[0086] Using the above-described device, when a first device requests communication authentication from a target cloud, the device determines the first information reported by the first device. This first information includes: second communication information collected by the first device from other devices in its network and the first communication information corresponding to the first device. The communication information comprises at least: device characteristics corresponding to the device and network characteristics of the network where the device resides. Based on the first network characteristics corresponding to the first information, the device searches the target cloud for second information including the first network characteristics and determines the set of device characteristics corresponding to the second information. The second information is reported by the second device, and the first network characteristics are used to determine that the first device and the second device are in the same network. If a target device characteristic matching the first device characteristic corresponding to the first device exists in the set of device characteristics, authentication of the first device is performed. The first device characteristic is a device characteristic possessed by the first device itself. This technical solution solves the problem of potential single-device deception of the target cloud during IoT device network connection authentication. Based on existing verification information, it utilizes a mutually recognized device identity authentication method to verify the authenticity of interconnected devices simultaneously accessing the target cloud, quickly identifying whether a device is forged or assessing the likelihood of forgery. This enhances the security of traditional IoT device identity authentication, and the authentication is implemented through software capabilities without incurring additional costs.
[0087] Optionally, the network features mentioned above include at least one of the following: the external IP address of the distributed network, the internal IP address allocation strategy of the distributed network, and the number of nodes inside the distributed network; the device features mentioned above include at least one of the following: the services provided by each device inside the distributed network and their version numbers, the port numbers of the devices inside the distributed network responding to requests, the probing requests received by the first device from other devices, and the broadcast data and features received by the first device from other devices.
[0088] It should be noted that when the network feature is the external IP address of a distributed network or the internal IP address allocation strategy corresponding to the distributed network, the main approach is to identify the consistency between the external IP address and / or internal IP address allocation strategy corresponding to the first information (equivalent to the first network feature in the above network embodiment) and the external IP address and / or internal IP address allocation strategy corresponding to the second information (equivalent to the second network feature in the above network embodiment). That is, when the external IP address and / or internal IP address allocation strategy are the same, it indicates that the first device and the second device are in the same network, and the first device is a real network device. This avoids the situation where the first device deceives the cloud service (equivalent to the target cloud in the above embodiment) and improves the security of authenticating the first device.
[0089] Optionally, when the network feature is the number of nodes within a distributed network, the specific number of nodes within the network is mainly used to identify whether the network has the same number of nodes, and to determine the first computing node corresponding to the first device among the nodes within the distributed network. Then, by determining whether the first computing node exists in other computing nodes besides the second computing node corresponding to the second device, the first computing node is used to determine whether the first device and the second device are in the same network based on the nodes.
[0090] It should be noted that the first information mentioned above is a feature information that is encrypted and shared to the target cloud. Specifically, the first information is determined in the following way: on the distributed computing nodes of the local area network corresponding to the current device, a security capability (i.e., the target capability in this embodiment of the invention) is set on each node using software. This security capability can dynamically collect feature information within its local area network and can share the collected feature information to the target cloud in an encrypted manner. The feature information mentioned above includes network features and device features.
[0091] Furthermore, the aforementioned device authentication methods are supplementary to the original authentication methods and need to be used in conjunction with them. Generally, they can only be used to verify authenticity, not authenticity; therefore, these methods can be called auxiliary authentication. However, in practical use, by detecting whether a device is counterfeit or assessing the likelihood of device counterfeiting, the credibility of the original authentication methods is comprehensively improved, greatly enhancing the security of interactions between devices.
[0092] It is understandable that the cloud service (target cloud) can identify (or probabilistically confirm) whether device A is forged by using the network characteristics of device A (equivalent to the first device mentioned above), invoking the security capabilities of other nodes in its network, and collecting feature information from different nodes. As an optional implementation method, Figure 5 This is a structural block diagram (II) of a device identity authentication method apparatus according to an embodiment of the present invention, which includes, in addition to... Figure 4 After all the devices, it also includes: access module 40, verification module 48, and confirmation module 50.
[0093] In an exemplary embodiment, the confirmation module 50 is configured to obtain a list of valid devices of the target object in the target cloud; wherein the list of valid devices consists of devices pre-marked as valid devices by the target object and devices with a communication security level higher than a preset security level; if it is determined that the second device exists in the list of valid devices, the device identity of the second device in the target cloud is confirmed as a valid device, wherein the valid device is used to indicate a real device whose communication security meets the requirements and has an entity; if it is determined that the second device does not exist in the list of valid devices, the device identity of the second device in the target cloud is confirmed as a device to be authenticated.
[0094] It should be noted that the aforementioned list of valid devices is a dynamically updated list within a preset period. For example, when the target object adds a new device identified as a valid device on the target cloud, the list of valid devices is refreshed directly; or, if the list of valid devices is pre-set to be updated every 3 minutes, the content of the pre-set list of valid devices is updated after a timer reaches 3 minutes, unless other conditions are met; or, if the device associated with the cloud is determined to be a device with a high level of communication security, such as a communication encryption level exceeding normal encryption requirements, or a network testing device that is exempt from authentication. The above are merely examples and do not limit the scope of the invention. In an exemplary embodiment, the above confirmation module further includes: an auxiliary unit, used to perform auxiliary authentication of the first device's identity through the second device; and to identify the first device's identity based on the result of the auxiliary authentication.
[0095] In an exemplary embodiment, the auxiliary unit is further configured to obtain a set of device features carried by the second information uploaded by the second device; match the set of device features with the device features corresponding to the first device; if there is a target device feature in the set of device features that is the same as the device feature, authenticate the device identity of the first device as a valid device; if there is no target device feature in the set of device features that is the same as the device feature, authenticate the device identity of the first device as an invalid device.
[0096] Before authenticating the identity of the first device, the device identity of the second device, which assists in authenticating the first device, can be identified to improve the authentication efficiency of the first device. For example, if the target cloud is connected to three interconnected devices A, B, and C, where A is the device to be authenticated (i.e., the first device), B is a device already confirmed as valid by the target cloud, and C is a device that reports to the target cloud the characteristics of other devices and the network environment collected in the distributed network. If the target cloud determines that the information collected by B device S contains a feature that matches the characteristics of the device to be authenticated, A, then A and B exist in the same local area network. In this case, A can be directly determined as a valid device that truly exists in the current local area network based on the device identity of B. In an exemplary embodiment, the above-mentioned confirmation module further includes: a similarity unit, configured to determine the similarity value of all device features carried in the first information and all device features carried in the second information in terms of feature content, wherein the feature content includes at least one of the following: the external address of the network where the device is located, the number of nodes within the network where the device is located, the services provided by the device and the version number of the services, the port number of the device responding to requests, the probing requests received by the device from other devices, and the broadcast data and features received by the device from other devices; the similarity value is used to indicate the proportion of the first device features that are identical to the second device features in the first device features; if the similarity value is greater than a dynamic threshold, the device identity of the first device is authenticated as a valid device; if the similarity value is less than or equal to the dynamic threshold, the device identity of the first device is authenticated as an invalid device.
[0097] Optionally, to avoid errors caused by a single confirmation, the feature content matching between the C device feature information (i.e., the second information in the above embodiment) corresponding to device C and the A device feature information (i.e., the first information in the above embodiment) corresponding to device A can be determined. Based on the matching, it can be determined whether device A and device C are in the same local area network. That is, before performing the identity authentication of the current first device, the device identity of the second device that performs auxiliary authentication of the first device can be identified to improve the authentication efficiency of the device identity of the first device. For example, the target cloud currently has three interconnected devices A, B, and C connected to it. Let A be the device to be authenticated (i.e., the first device). B and C simultaneously report their own collected network environment characteristics and other device features gathered in the distributed network to the target cloud. The target cloud determines that device B's feature information matches those of device A, indicating that device A and device B exist in the same local area network (LAN). Similarly, the target cloud determines that device C's feature information matches those of device A, indicating that device A and device C exist in the same LAN. Therefore, device A is ultimately determined to be a valid device truly existing in the current LAN. Optionally, to improve efficiency, a preset threshold for determining if a device is genuine can be set. By combining the results of other devices' assessments of device A's authenticity, the validity of device A can be determined. Specifically: Suppose that device A is identified as a fake device (i.e., an invalid device falsely existing in the current local area network) by device C, and is identified as a valid device genuinely existing in the current local area network by device B. There are a total of three devices in this local area network. The probability that device A is identified as a valid device by other devices is calculated. This probability is determined by averaging the confirmation results from device B and device C, where the probability of a valid device is 1 and the probability of an invalid device is 0. Therefore, the probability of device A being a valid device is 0.5. A preset threshold for determining whether a device in the current local area network is genuine is then calculated. If 0.5 is greater than the preset threshold, it indicates that device A's authentication result is valid; if 0.5 is less than or equal to the preset threshold, it indicates that device A's authentication result is invalid.
[0098] In an exemplary embodiment, the above-described apparatus further includes: an access module 40, configured to determine whether the first device is connected to the distributed network corresponding to the target cloud; if the first device has been connected to the distributed network and the first device has the target capability, the first device actively initiates a device task to collect other device characteristics corresponding to other devices in the distributed network; if the first device has been connected to the distributed network and the first device does not have the target capability, the access of the first device to the distributed network is stopped.
[0099] It is understandable that after the first device has been equipped with the ability to collect feature information (equivalent to the first information in the above embodiment) (equivalent to the target capability mentioned above) through software, when the first device connects to the distributed network (or local area network), it can actively start a device task to collect the features of other devices in the distributed network through the first device. This allows the first device to obtain the corresponding feature information, which includes: the device features and network features corresponding to the first device, and the set of device features and network features corresponding to other devices in the same network as the first device. This feature information is then shared with the cloud service (equivalent to the target cloud) in an encrypted manner. The cloud service can then use the network features of the first device to call the feature capabilities of other nodes in its network and collect feature information from different nodes. The feature information transmitted by the corresponding nodes of other devices can be used to identify (or probabilistically confirm) whether the first device is forged. In addition, when it is determined that the first device does not have the target capability, the current access of the first device to the distributed network is directly stopped to ensure the security of the connection between the target cloud and the first device. In an exemplary embodiment, the above-described apparatus further includes: a verification module 48, configured to, upon determining the device identity corresponding to the first device, obtain first verification information sent by the first device, wherein the first verification information includes account information and password information corresponding to the first device; determine the verification result of the first verification information in the target cloud; and determine whether the first device is allowed to interact with the target cloud based on the verification result and the device identity authentication result of the first device.
[0100] In an exemplary embodiment, the verification module 48 is further configured to: determine that the first device has completed communication authentication and is allowed to interact with the target cloud when the verification result indicates that the first device has passed the verification of the target cloud and the first device is a valid device; and send a registration prompt message to the first device to confirm a single connection when the verification result indicates that the first device has passed the verification of the target cloud and the first device is an invalid device, wherein the registration prompt message indicates that information collection is performed on the first device when it is determined that the first device is accessing the distributed network independently.
[0101] Understandably, when the first device is connecting to the target cloud for the first time and has not interacted with other devices in the network, the first device can initially access the cloud network by sending verification information to the cloud through the target. However, since other devices are not interacting with the first device, the second information they obtain does not include the device characteristics corresponding to the first device. Therefore, the device identity of the first device may be defaulted to an invalid device, indicating that the first device can only interact with the target cloud at this time. Furthermore, the target cloud can confirm that the first device is a genuine single-connection device by sending a registration prompt message to the first device to confirm a single connection. In an exemplary embodiment, the verification module 48 is further configured to send a prompt message to the first device to indicate that the first device has failed the verification of the target cloud and the first device is a valid device, when the verification result indicates that the first device has failed the verification of the target cloud and the first device is a valid device; and when the verification result indicates that the first device has failed the verification of the target cloud and the first device is an invalid device, prohibit the first device from accessing the current distributed network again and add the first device to the connection blacklist corresponding to the current distributed network.
[0102] That is, while determining the identity of the first device, it is also necessary to verify whether the first verification information sent by the first device has been registered in the target cloud. If it has been registered and the first device is a valid device, it is determined that the first device is an old device already connected to the network. After the verification information is verified by the target cloud, data interaction with the second device can be established through the target cloud, or other data information can be obtained from the target cloud. When the first device fails the verification by the target cloud, it indicates that the first verification information entered by the target object is abnormal, and the target object needs to be prompted to check whether there is an error in the input on the first device. When the first device is an invalid device and the verification by the target cloud fails, it indicates that the first device is a counterfeit device, and the device information corresponding to the first device is added to the connection blacklist of the current distributed network stored in the target cloud to ensure the security of data communication in the distributed network. The embodiments of the present invention also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the steps of any of the above method embodiments when running.
[0103] Optionally, in this embodiment, the storage medium may be configured to store a computer program for performing the following steps:
[0104] S1, when the first device applies for communication authentication to the target cloud, the first information reported by the first device is determined, wherein the first information includes: the second communication information of other devices in the network collected by the first device and the first communication information corresponding to the first device, and the information composition of the communication information includes at least: the device characteristics corresponding to the device and the network characteristics of the network where the device is located;
[0105] S2, based on the first network feature corresponding to the first information, search for second information including the first network feature in the target cloud, and determine the device feature set corresponding to the second information, wherein the second information is reported by the second device, and the first network feature is used to determine that the first device and the second device are in the same network;
[0106] S3, if there is a target device feature in the device feature set that matches the first device feature corresponding to the first device, then perform authentication of the first device, wherein the first device feature is a device feature that the first device itself possesses.
[0107] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.
[0108] Specific examples in this embodiment can be found in the examples described in the above embodiments and exemplary implementations, and will not be repeated here.
[0109] Embodiments of the present invention also provide an electronic device including a memory and a processor, the memory storing a computer program and the processor being configured to run the computer program to perform the steps in any of the above method embodiments.
[0110] Optionally, in this embodiment, the processor can be configured to perform the following steps via a computer program:
[0111] S1, when the first device applies for communication authentication to the target cloud, the first information reported by the first device is determined, wherein the first information includes: the second communication information of other devices in the network collected by the first device and the first communication information corresponding to the first device, and the information composition of the communication information includes at least: the device characteristics corresponding to the device and the network characteristics of the network where the device is located;
[0112] S2, based on the first network feature corresponding to the first information, search for second information including the first network feature in the target cloud, and determine the device feature set corresponding to the second information, wherein the second information is reported by the second device, and the first network feature is used to determine that the first device and the second device are in the same network;
[0113] S3, if there is a target device feature in the device feature set that matches the first device feature corresponding to the first device, then perform authentication of the first device, wherein the first device feature is a device feature that the first device itself possesses.
[0114] In one exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.
[0115] Specific examples in this embodiment can be found in the examples described in the above embodiments and exemplary implementations, and will not be repeated here.
[0116] It is obvious to those skilled in the art that the modules or steps of the present invention described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. They can be implemented using computer-executable program code, and thus can be stored in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those described herein, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.
[0117] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for authenticating device identity, characterized in that, include: When the first device requests communication authentication from the target cloud, the first information reported by the first device is determined. The first information includes: the second communication information of other devices in the network collected by the first device and the first communication information corresponding to the first device. The information composition of the communication information includes at least: the device characteristics corresponding to the device and the network characteristics of the network where the device is located. Based on the first network feature corresponding to the first information, search for second information including the first network feature in the target cloud, and determine the set of device features corresponding to the second information. The second information is reported by the second device, and the first network feature is used to determine that the first device and the second device are in the same network. The second information is the device feature corresponding to the second device reported by the second device that is connected in the target cloud and the network feature of the network where the second device is located. If there is a target device feature in the device feature set that matches the first device feature corresponding to the first device, then authentication of the first device is performed, wherein the first device feature is a device feature that the first device itself possesses; The network features include at least one of the following: the external IP address of the distributed network, the internal IP address allocation strategy of the distributed network, and the number of nodes within the distributed network; the device features include at least one of the following: the services provided by each device within the distributed network and their version numbers, the port numbers of the devices within the distributed network responding to requests, the probing requests received by the first device from other devices, and the broadcast data and features received by the first device from other devices. After authenticating the first device, the method further includes: If the authentication result indicates that the first device is a valid device, the first verification information sent by the first device is obtained, wherein the first verification information includes the account information and password information corresponding to the first device; if the verification result of the first verification information on the target cloud is successful, the first device is allowed to interact with the target cloud; if the verification result of the first verification information on the target cloud is unsuccessful, a prompt message is sent to the first device to instruct it to check the first verification information.
2. The device identity authentication method according to claim 1, characterized in that, After searching for second information including the first network feature in the target cloud based on the first network feature corresponding to the first information, and determining the set of device features corresponding to the second information, the method further includes: Obtain a list of valid devices of the target object in the target cloud; wherein, the list of valid devices consists of devices pre-marked as valid devices by the target object and devices with a communication security level higher than a preset security level; If it is determined that the second device exists in the list of valid devices, the device identity of the second device in the target cloud is confirmed as a valid device, wherein the valid device is used to indicate that the device communication security meets the requirements and that there is a real device with a physical entity; If it is determined that the second device does not exist in the list of valid devices, the device identity of the second device in the target cloud is confirmed as a device to be authenticated.
3. The device identity authentication method according to claim 2, characterized in that, After confirming that the second device is a valid device on the target cloud, the method further includes: The second device is used to perform auxiliary authentication of the first device's identity; The device identity is identified for the first device based on the result of the auxiliary authentication.
4. The device identity authentication method according to claim 3, characterized in that, The second device performs auxiliary authentication of the first device's identity, including: If a target device feature identical to the first device feature exists in the set of device features, the device identity of the first device is authenticated as a valid device. If no target device feature identical to the device feature exists in the set of device features, the device identity of the first device is authenticated as an invalid device.
5. The device identity authentication method according to claim 2, characterized in that, After confirming that the second device's identity on the target cloud is the device to be authenticated, the method further includes: The similarity value between all device features carried in the first information and all device features carried in the second information is determined in terms of feature content. The feature content includes at least one of the following: the external address of the network where the device resides, the number of nodes within the network where the device resides, the services provided by the device and their version numbers, the port number used by the device to respond to requests, probing requests received by the device from other devices, and broadcast data and features received by the device from other devices. The similarity value is used to indicate the proportion of the first device features that are identical to the second device features within the first device features. If the similarity value is greater than the dynamic threshold, the device identity of the first device will be authenticated as a valid device; If the similarity value is less than or equal to the dynamic threshold, the device identity of the first device is authenticated as an invalid device.
6. The device identity authentication method according to claim 1, before determining the first information reported by the first device, the method further includes: Determine whether the first device is connected to the distributed network corresponding to the target cloud; When the first device has been connected to the distributed network and has the target capability, the first device actively initiates a device task to collect the characteristics of other devices corresponding to other devices in the distributed network. If the first device has already connected to the distributed network and the first device does not have the target capability, then stop the first device from connecting to the distributed network.
7. The device identity authentication method according to claim 1, characterized in that, The method further includes: If the verification result indicates that the first device has passed the verification of the target cloud and the first device is an invalid device, a registration prompt message for confirming a single connection is sent to the first device, wherein the registration prompt message indicates that information is collected from the first device when it is determined that the first device has accessed the distributed network independently.
8. The device identity authentication method according to claim 1, characterized in that, The method further includes: If the verification result indicates that the first device has failed the verification of the target cloud and the first device is an invalid device, the first device is prohibited from accessing the current distributed network again, and the first device is added to the connection blacklist corresponding to the current distributed network.
9. A device authentication device, characterized in that, include: The determination module is used to determine the first information reported by the first device when the first device applies for communication authentication to the target cloud. The first information includes: second communication information of other devices in the network collected by the first device and first communication information corresponding to the first device. The information composition of the communication information includes at least: device characteristics corresponding to the device and network characteristics of the network where the device is located. The search module is used to search for second information including the first network feature in the target cloud according to the first network feature corresponding to the first information, and to determine the set of device features corresponding to the second information. The second information is reported by the second device, the first network feature is used to determine that the first device and the second device are in the same network, and the second information is the device feature corresponding to the second device reported by the second device that is connected in the target cloud and the network feature of the network where the second device is located. The authentication module is used to perform authentication of the first device when there is a target device feature in the device feature set that matches the first device feature corresponding to the first device, wherein the first device feature is a device feature that the first device itself has; The network features include at least one of the following: the external IP address of the distributed network, the internal IP address allocation strategy of the distributed network, and the number of nodes within the distributed network; the device features include at least one of the following: the services provided by each device within the distributed network and their version numbers, the port numbers of the devices within the distributed network responding to requests, the probing requests received by the first device from other devices, and the broadcast data and features received by the first device from other devices. The device further includes: a verification module, configured to: acquire first verification information sent by the first device when the authentication result indicates that the first device is a valid device, wherein the first verification information includes account information and password information corresponding to the first device; allow the first device to interact with the target cloud when the verification result of the first verification information on the target cloud is successful; and send a prompt message to the first device to instruct it to check the first verification information when the verification result of the first verification information on the target cloud is unsuccessful.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein the program is executed by a processor to perform the method of any one of claims 1 to 8.
11. An electronic device comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to execute the method of any one of claims 1 to 8 through the computer program.
Citation Information
Patent Citations
Network device authentication method and device
CN106375301A
User identity verification method and device
CN109889474A
Authentication of device in communication network of automation installation
CN115085964A