Methods, devices, network equipment, and storage media for identity verification

CN115884169BActive Publication Date: 2026-08-14CHINA MOBILE COMM LTD RES INST +1
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-29
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

相关技术中,物联网终端的身份标识方法或容易导致身份标识被篡改或仿冒,或需要较高的软硬件成本,难以实现对物联网终端有效且低成本的安全防护

Benefits of technology

[0054]在本申请实施例中,第一网络设备包括第一芯片和运行于由所述第一芯片支持的TEE中的第一服务端,其中,所述第一芯片包括安全芯片或可信芯片,基于此,所述第一服务端获取第一终端设备发送的第一请求,所述第一请求用于请求生成所述第一终端设备的身份标识,并且所述第一请求携带至少一个用于描述所述第一终端设备的身份的第一信息;所述第一服务端获取所述第一终端设备的第一身份标识;所述第一身份标识通过对第二信息进行加密得到;所述第二信息表征所述至少一个第一信息对应的摘要信息;,再由所述第一服务端将所述第一身份标识发送对所述第一终端设备。基于上述方案,可以避免终端设备的身份标识被篡改或仿冒,从而实现对终端设备有效且低成本的安全防护。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115884169B_ABST
    Figure CN115884169B_ABST
Patent Text Reader

Abstract

This application discloses a method, apparatus, network node, and storage medium for processing identity identifiers. A first network device includes a first chip and a first server running in a TEE (Trusted Execution Environment) supported by the first chip. The first chip includes a security chip or a trusted chip. The method includes: the first server acquiring a first request sent by a first terminal device; the first request requesting the generation of an identity identifier for the first terminal device; the first request carrying at least one first piece of information; the first information representing information describing the identity of the first terminal device; the first chip encrypting the second information to obtain a first identity identifier for the first terminal device; the second information representing a digest corresponding to the at least one piece of first information; and the first server sending the first identity identifier to the first terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of the Internet of Things, and more particularly to a method, apparatus, network device, and storage medium for processing identity identification. Background Technology

[0002] In the sensing and control domain of IoT systems, most IoT terminals, such as sensing terminals and control terminals, require security protection through identification. However, current identification methods for IoT terminals are either prone to tampering or impersonation, or require high hardware and software costs, making it difficult to achieve effective and low-cost security protection for IoT terminals. Summary of the Invention

[0003] To address the related technical issues, embodiments of this application provide a method, apparatus, network device, and storage medium for processing identity identifiers.

[0004] The technical solution of this application embodiment is implemented as follows:

[0005] This application provides an identity processing method applied to a first network device. The first network device includes a first chip and a first server running in a Trusted Execution Environment (TEE) supported by the first chip. The first chip includes a security chip or a trusted chip. The method includes:

[0006] The first server receives a first request sent by the first terminal device; the first request is used to request the generation of an identity identifier for the first terminal device; the first request carries at least one piece of first information; the first information represents information used to describe the identity of the first terminal device.

[0007] The first server obtains a first identity identifier of the first terminal device; the first identity identifier is obtained by encrypting second information; the second information represents the digest information corresponding to at least one piece of first information;

[0008] The first server sends the first identity identifier to the first terminal device.

[0009] In the above scheme, the at least one piece of first information includes at least one of the following pieces of information from the first terminal device:

[0010] Equipment Name;

[0011] Device serial number;

[0012] Media Access Control (MAC) address;

[0013] Work mode;

[0014] Uplink connection information.

[0015] In the above scheme, before the first server obtains the first identity identifier of the first terminal device, the method further includes:

[0016] The first server or the first chip performs a hash operation on the at least one piece of first information to obtain the second information.

[0017] In the above scheme, the first server obtains the first identity identifier of the first terminal device, including:

[0018] The first server sends a second request to the first chip; the second request is used to request the first chip to encrypt the second information;

[0019] The first server obtains the response returned by the first chip based on the second request; the response carries the first identity identifier obtained by the first chip encrypting the second information based on the private key in the first key pair.

[0020] In the above scheme, the network device further includes a first database running in the TEE; the first database stores at least one identity identifier of a terminal device generated by the first network device; the first server sends the first identity identifier to the first terminal device, including:

[0021] If the first server finds that the first identity identifier is not stored in the first database, the first server will send the first identity identifier to the first terminal device.

[0022] The method in the above scheme further includes:

[0023] The first server stores the first identity identifier and at least one of the following pieces of information from the first terminal device into the first database:

[0024] The at least one first piece of information, the second piece of information, the first key pair used to encrypt the second piece of information, and / or the generation time of the first identity identifier.

[0025] In the above scheme, the first network device further includes a first log module running in the TEE; the method further includes:

[0026] The first log module generates and stores the first log; wherein,

[0027] The first log represents the log of operations related to the first identity identifier.

[0028] The method in the above scheme further includes:

[0029] The first server receives a second request sent by the first terminal device; the second request is used to request reconnection to the first network device; the second request carries the first identity identifier.

[0030] If the first server confirms that the first terminal device is bound to the first network device based on the first identity identifier in the second request, the first terminal device is allowed to establish a connection with the first network device.

[0031] The method in the above scheme further includes:

[0032] When the first terminal device is unbound from the first network device, the first server sets the first identity identifier to be invalid.

[0033] The method in the above scheme further includes:

[0034] The first server receives a third request sent by the first terminal device; the third request is used to request the first network device to perform security authentication on the identity of the second network device or the second terminal device.

[0035] Based on the first connection between the first network device and the second network device or the second terminal device, the first server obtains the second identity identifier sent by the second network device or the second terminal device; the second identity identifier represents the identity identifier of the first terminal device obtained by the second network device or the second terminal device.

[0036] If the first server confirms that the second identity identifier is consistent with the first identity identifier and meets the set conditions, it sends third information to the second network device or the second terminal device through the first connection; the third information is used by the second network device or the second terminal device to obtain the security authentication result of the second identity identifier.

[0037] In the above scheme, the setting conditions include at least one of the following:

[0038] The first identity identifier is valid;

[0039] The first terminal device connects to the first network device;

[0040] The time limit for the third request is within the set time limit range.

[0041] In the above scheme, the first connection between the first network device and the second network device is a trusted connection or a secure connection.

[0042] This application embodiment also provides an identity processing apparatus, which operates in a TEE supported by a first chip in a first network device; the first chip includes a security chip or a trusted chip; the apparatus includes:

[0043] A first processing unit is configured to acquire a first request sent by a first terminal device; the first request is used to request the generation of an identity identifier for the first terminal device; the first request carries at least one piece of first information; the first information represents information used to describe the identity of the first terminal device.

[0044] The second processing unit obtains a first identity identifier of the first terminal device; the first identity identifier is obtained by encrypting second information; the second information represents the digest information corresponding to the at least one piece of first information;

[0045] The third processing unit sends the first identity identifier to the first terminal device.

[0046] This application also provides a first network device, characterized in that the first network device includes a first chip, a first processor, and a first communication interface; the first chip includes a security chip or a trusted chip; wherein...

[0047] The first communication interface is used to obtain a first request sent by the first terminal device in a TEE supported by the first chip; the first request is used to request the generation of an identity identifier for the first terminal device; the first request carries at least one piece of first information; the first information represents information used to describe the identity of the first terminal device;

[0048] The first processor is configured to obtain a first identity identifier of the first terminal device from the TEE; the first identity identifier is obtained by encrypting second information; the second information represents digest information corresponding to at least one piece of first information;

[0049] The first communication interface is also used to send the first identity identifier to the first terminal device in the TEE.

[0050] This application also provides an Internet of Things (IoT) system, characterized in that it includes a first terminal device and a first network device, wherein the first network device includes a first chip and a first server running in a TEE supported by the first chip; the first chip includes a security chip or a trusted chip; wherein...

[0051] The first server is configured to receive a first request sent by the first terminal device; the first request is configured to request the generation of an identity identifier for the first terminal device; the first request carries at least one piece of first information; the first information represents information used to describe the identity of the first terminal device;

[0052] The first server is further configured to obtain a first identity identifier of the first terminal device; the first identity identifier is obtained by encrypting second information; the second information represents digest information corresponding to at least one piece of first information;

[0053] The first server is also configured to send the first identity identifier to the first terminal device.

[0054] In this embodiment, the first network device includes a first chip and a first server running in a TEE supported by the first chip. The first chip includes a security chip or a trusted chip. Based on this, the first server obtains a first request sent by a first terminal device. The first request requests the generation of an identity identifier for the first terminal device, and the first request carries at least one piece of first information describing the identity of the first terminal device. The first server obtains the first identity identifier of the first terminal device. The first identity identifier is obtained by encrypting second information. The second information represents digest information corresponding to the at least one piece of first information. The first server then sends the first identity identifier to the first terminal device. Based on the above scheme, the identity identifier of the terminal device can be prevented from being tampered with or impersonated, thereby achieving effective and low-cost security protection for the terminal device. Attached Figure Description

[0055] Figure 1 This is a schematic diagram of the sensing and control domain networking of an IoT system based on related technologies.

[0056] Figure 2 This is a schematic diagram of the identity verification process in an embodiment of this application;

[0057] Figure 3 This is a schematic diagram illustrating the identity processing flow in an application embodiment of this application;

[0058] Figure 4 This is a schematic diagram of the security authentication process for identity verification in an embodiment of this application;

[0059] Figure 5 This is a schematic diagram of the security authentication process for identity identification in an application embodiment of this application;

[0060] Figure 6 This is a schematic diagram illustrating an application scenario of the identity processing method according to an embodiment of this application.

[0061] Figure 7 This is a schematic diagram of an identity processing device according to an embodiment of this application;

[0062] Figure 8 This is a schematic diagram of the structure of the first network device in the embodiment of this application. Detailed Implementation

[0063] Most IoT terminals in the sensing and control domain of an IoT system, such as sensing terminals and control terminals, are... Figure 1 As shown, local networking is required via network connection devices such as IoT gateways, routers, and / or smart gateways, followed by internet access to communicate with the IoT platform. Typically, IoT terminals such as sensing terminals and control terminals are inexpensive, lack built-in security or trusted chips, and generally have weak computing, storage, and battery life. They do not support complex encryption / decryption operations or secure information storage; therefore, the identification methods for IoT terminals are relatively simple. Common identification methods include: the device manufacturer writing a device serial number as an identification identifier into the device's memory at the factory; or, for IoT terminals with direct network capabilities, using the MAC address or IP address as an identification identifier. These methods are prone to serial number tampering or impersonation. A few IoT terminals use a pre-installed security certificate combined with the product serial number as an identification identifier; or, the IoT terminal uses a built-in trusted central processing unit (CPU), trusted platform module (TPM), or trusted platform control module (TPCM) as an identification identifier. These methods have higher hardware and software costs and poor compatibility. Therefore, it can be seen that the identification methods for IoT terminals in related technologies are difficult to achieve effective and low-cost security protection.

[0064] Based on this, in various embodiments of this application, the first network device includes a first chip and a first server running in a TEE supported by the first chip. The first chip includes a security chip or a trusted chip. The first server receives a first request sent by a first terminal device. The first request requests the generation of an identity identifier for the first terminal device, and the first request carries at least one piece of first information describing the identity of the first terminal device. The first server obtains the first identity identifier of the first terminal device. The first identity identifier is obtained by encrypting the digest information corresponding to the at least one piece of first information. The first server then sends the first identity identifier to the first terminal device. Based on the above scheme, the identity identifier of the terminal device can be prevented from being tampered with or impersonated, thereby achieving effective and low-cost security protection for the terminal device.

[0065] First, the system architecture applicable to the identity processing method in the embodiments of this application will be described:

[0066] This system framework includes network devices and at least one terminal device. In practical applications, network devices include, but are not limited to, secure smart gateways, routers, and other network connection devices. Furthermore, network devices can be secure smart gateways and routers used in IoT systems to connect various IoT terminals located within the same local area network's IoT sensing and control domain. Compared to low-cost IoT terminals, secure smart gateways, routers, and other network devices typically have ample computing and storage resources and are usually equipped with security chips or trusted chips, providing higher security. In this embodiment, the network device acts as the server, and the terminal device acts as the client. They work collaboratively, utilizing the security capabilities of the network device to construct a secure identity for the terminal device.

[0067] In this embodiment, a security chip or trusted chip is built into the network device. The identity processing method is implemented in a secure zone supported by the security chip or trusted chip. In other words, the server runs in a TEE supported by the security chip or trusted chip.

[0068] The present application will now be described in further detail with reference to the accompanying drawings and embodiments.

[0069] This application provides a method for processing identity identifiers, such as... Figure 2 As shown, the execution entity of this method is a first network device. As described above, the first network device includes a first chip and a first server running in a TEE supported by the first chip; the first chip includes a security chip or a trusted chip. The method includes:

[0070] Step 201: The first server obtains the first request sent by the first terminal device.

[0071] The first request is used to request the generation of an identity identifier for the first terminal device; the first request carries at least one piece of first information; the first information represents information used to describe the identity of the first terminal device.

[0072] Here, before sending the first request, the first terminal device collects information that represents its identity and has relatively fixed content, according to the information types specified in the configuration. This information includes, but is not limited to, device name, device serial number, MAC address, operating mode, and / or uplink connection information. In practical applications, the first terminal device can send the collected information as a set or sequence to the first network device, requesting the first network device to generate a unique identifier for the first terminal device.

[0073] Step 202: The first server obtains the first identity identifier of the first terminal device.

[0074] The first identity identifier is obtained by encrypting the second information; the second information represents the digest information corresponding to the at least one piece of first information.

[0075] Upon receiving the first request, the first network device uses a digest algorithm built into the security chip / trusted chip to process the information describing the identity of the first terminal device carried in the first request, obtaining at least one digest corresponding to the first information. The generated digest is then encrypted to obtain the first identity identifier of the first terminal device. Since the identity identifier generation process is entirely performed within the TEE supported by the security chip / trusted chip, the security of the identity identifier can be guaranteed.

[0076] In one embodiment, regarding the summary generation process, before the first server obtains the first identity identifier of the first terminal device, the method further includes:

[0077] The first server or the first chip performs a hash operation on the at least one piece of first information to obtain the second information.

[0078] Here, upon receiving the first request, the digest algorithm built into the security chip / trusted chip is used to obtain at least one digest corresponding to the first information through hash calculation. In practical applications, if the security chip / trusted chip does not have a built-in digest algorithm or does not have open digest calculation capabilities, a digest algorithm can also be embedded in the first server within the TEE supported by the security chip / trusted chip to obtain at least one digest corresponding to the first information.

[0079] In practical applications, when the first terminal device sends at least two pieces of first information to the first network device, or when the first terminal device sends an information set or information sequence containing multiple pieces of first information to the first network device, the first network device can combine the multiple pieces of first information before calculating the corresponding summary information. For example, it can process the multiple pieces of first information into a combined information by splicing, merging, or other methods, and then generate the corresponding summary information based on the combined information.

[0080] In one embodiment, the encryption process involves the first server obtaining the first identity identifier of the first terminal device, including:

[0081] The first server sends a second request to the first chip; the second request is used to request the first chip to encrypt the second information;

[0082] The first server obtains the response returned by the first chip based on the second request; the response carries the first identity identifier obtained by the first chip encrypting the second information based on the private key in the first key pair.

[0083] In practical applications, after generating the digest information, the security chip / trusted chip sends it to the first server. Upon receiving the digest information, the first server requests the security chip / trusted chip to generate a key pair for encrypting the digest information. After receiving a second request from the first server for the key pair, the security chip / trusted chip generates a first key pair and encrypts the digest information based on the private key in the first key pair, thereby obtaining the first identity identifier of the first terminal device.

[0084] Here, the first server sends the digest information to the security chip / trusted chip, which then encrypts the digest information. Alternatively, the digest information can be included in a second request sent to the security chip / trusted chip. Upon receiving the second request, the security chip / trusted chip extracts the digest information from it, generates a key pair, and encrypts the extracted digest information using the private key in the key pair. In other words, the security chip / trusted chip does not store the digest information; it only generates or encrypts it.

[0085] In practical applications, if the security chip / trusted chip does not have a built-in encryption algorithm or does not have open encryption capabilities, an encryption algorithm can be embedded in the first server in the TEE supported by the security chip / trusted chip to obtain at least one digest corresponding to the first information.

[0086] Step 203: The first server sends the first identity identifier to the first terminal device.

[0087] The above solution utilizes the high security capabilities and computing power of network equipment without increasing hardware costs, and implements the generation of terminal device identity identifiers in software. This prevents the identity identifiers of terminal devices from being tampered with or impersonated, thereby achieving effective and low-cost security protection for terminal devices.

[0088] In one embodiment, the network device further includes a first database running in the TEE; the first database stores at least one identity identifier of a terminal device generated by the first network device; the first server sends the first identity identifier to the first terminal device, including:

[0089] If the first server finds that the first identity identifier is not stored in the first database, the first server will send the first identity identifier to the first terminal device.

[0090] Here, the first database primarily provides services such as storage, querying, and updating identity identifiers. Specifically, the first database mainly stores the identity identifiers generated by the first network device and supports the first server in querying and / or updating the identity identifiers in the first database. Since the first database runs in a TEE (Telematics Equipment Environment), the identity identifiers stored in the first database can be effectively protected by data security. Furthermore, the identity identifiers can be further protected by methods such as encrypted storage within the first database.

[0091] After obtaining the newly generated first identity identifier, the first server queries whether the first identity identifier already exists in the first database. If the query result is that the first identity identifier does not exist in the first database, the uniqueness of the first identity identifier is confirmed, and the first server sends the first identity identifier to the first terminal device. If the query result is that the first identity identifier already exists in the first database, the first server returns the result that the first identity identifier already exists to the first terminal device.

[0092] In one embodiment, the method further includes:

[0093] The first server stores the first identity identifier and at least one of the following pieces of information from the first terminal device into the first database:

[0094] The at least one first piece of information, the second piece of information, the first key pair used to encrypt the second piece of information, and / or the generation time of the first identity identifier.

[0095] In other words, when storing the generated identity identifier in the first database, the digest information corresponding to the identity identifier, the key pair used when generating the identity identifier, the generation time of the identity identifier, and at least one first piece of information provided by the corresponding terminal device to describe the identity are also stored. In this way, the identity identifier in the first database can be queried and updated based on the stored information.

[0096] In one embodiment, the first network device further includes a first logging module running in the TEE; the method further includes:

[0097] The first log module generates and stores the first log; wherein,

[0098] The first log represents the log of operations related to the first identity identifier.

[0099] The first log module also runs in TEE, which can effectively protect the data security of logs, and thus ensure the effective data security of identity identification.

[0100] Figure 3 In the application example, an IoT security smart gateway / router is used as the first network device, and an IoT terminal device is used as the first terminal device. The process of generating identity identifiers is shown based on the corresponding system architecture.

[0101] See Figure 3 :

[0102] 1. The identity client running on the IoT terminal device collects information that can represent identity characteristics from the IoT terminal device according to the client settings, obtains information set F, and then sends information set F to the identity server running on the IoT security smart gateway / router, and requests to generate a unique security identity for the IoT terminal device.

[0103] 2. Upon receiving a security identity creation request from an IoT terminal device, the identity server running on the IoT security smart gateway / router combines and calculates the elements in the information set F representing the device's identity features to form the combined device identity feature information S. Then, the combined device identity feature information S is sent to the security chip / trusted chip to request the generation of digest information. Here, S = Aggregation(F), where Aggregation() represents the aggregation of information in the information set F.

[0104] 3. The security chip / trusted chip uses built-in cryptographic algorithms to generate a digest message MD from the combined device identity feature information S. s The result is then returned to the identity verification server, where: MD s=Hash(S), Hash() represents performing a hash operation on the combined device identity feature information S.

[0105] 4. The identity identification server receives the digest information MD of the combined device identity feature information S. s Then, request the generation of a public-private key pair from the security chip / trusted chip, and send the digest information MD s Send to the security chip / trusted chip to request MD s Encrypt using the private key.

[0106] 5. The security chip / trusted chip uses built-in cryptographic algorithms to generate a public-private key pair, PrivateKey:PublicKey, and uses the private key, PrivateKey, as the digest information (MD). s The encryption is performed, and the result is then returned to the identity verification server.

[0107] 6. The identity verification server will receive the MD s The encrypted value serves as the SecurityID, the security identifier for IoT terminal devices, and the newly generated SecurityID is sent to the identity database for querying. Here, SecurityID = Crypt(MD) s PrivateKey), Crypt() represents the corresponding encrypted string returned by the identity database.

[0108] 7. Query the identity database to see if the newly generated SecurityID already exists in the database, and return the query result to the identity server.

[0109] 8. Based on the query results, if the new security identity does not yet exist in the identity database, the identity server will store the new security identity (SecurityID) and digest information (MD). s Information such as the public / private key pair PrivateKey:PublicKey, the security identity generation time Time, and the original information set F of the IoT terminal device are stored in the identity database.

[0110] 9. The identity identification server stores the relevant log information of the security identity identification generation in the identity identification log.

[0111] 10. The identity server returns the SecurityID to the identity client running on the IoT terminal device.

[0112] After the above security identity generation process, the newly generated security identity for IoT terminal devices is finally:

[0113] SecurityID=Crypt(Hash(Aggregation(F)),PrivateKey)

[0114] In IoT systems, during actual deployment, IoT terminal devices and IoT security smart gateways / routers are usually paired or configured in a secure manner to establish an initial connection. Therefore, the moment the initial connection is successfully established can be taken as the time for the IoT terminal device to apply for the creation of an identity.

[0115] Based on the above scheme, with the support of a trusted IoT security smart gateway / router, the identity identifier generated for IoT terminal devices is associated with multiple characteristics of the IoT terminal devices, possessing uniqueness and high security. In practical applications, IoT terminal devices can apply the identity identifier to other identification systems, such as Unique Device Identifier (UDID), Universally Unique Identifier (UUID), or IEID, according to the needs of IoT applications.

[0116] In one embodiment, the method further includes:

[0117] The first server receives a second request sent by the first terminal device; the second request is used to request reconnection to the first network device; the second request carries the first identity identifier.

[0118] If the first server confirms that the first terminal device is bound to the first network device based on the first identity identifier in the second request, the first terminal device is allowed to establish a connection with the first network device.

[0119] In an IoT system, when an IoT terminal device is bound to an IoT security smart gateway / router, the IoT terminal device needs to send its identity identifier to the IoT security smart gateway / router for confirmation each time it reconnects. If the identity identifier server in the IoT security smart gateway / router confirms that the IoT terminal device and its identity identifier belong to the bound device, the IoT terminal device is allowed to maintain the connection; if the identity identifier server confirms that the IoT terminal device and its identity identifier do not belong to the bound device, the IoT terminal device is disconnected, and an alarm message is generated and recorded in the identity identifier log.

[0120] In one embodiment, the method further includes:

[0121] When the first terminal device is unbound from the first network device, the first server sets the first identity identifier to be invalid.

[0122] Once an IoT terminal device is unbound from its previous IoT security smart gateway / router and added to a new IoT security smart gateway / router, the IoT security smart gateway / router will invalidate the original identity of the IoT terminal device, and the IoT terminal device will need to apply to the newly bound IoT security smart gateway / router to generate a new SecurityID.

[0123] In practical applications, when the first terminal device interacts with the cloud or a remote device, it can send its identity identifier to the other party to demonstrate its identity. In one embodiment, such as... Figure 4 As shown, the method further includes:

[0124] Step 401: The first server obtains the third request sent by the first terminal device.

[0125] The third request is used to request the first network device to perform security authentication on the identity of the second network device or the second terminal device.

[0126] In an IoT system, the second network device can be understood as an IoT cloud platform, and the second terminal device can be understood as an IoT terminal device located on the same local area network as the first terminal device. In practical applications, before step 401, the first terminal device sends its identity identifier to the second network device or the second terminal device. After receiving the identity identifier, the second network device or the second terminal device needs to verify it. Therefore, the second network device or the second terminal device sends an identity verification request to the first terminal device. After receiving the identity verification request, the first terminal device sends a third request to the first network device, including the address information of the second network device or the second terminal device, such as its IP address, in the third request.

[0127] Step 402: Based on the first connection between the first network device and the second network device or the second terminal device, the first server obtains the second identity identifier sent by the second network device or the second terminal device.

[0128] The second identity identifier represents the identity identifier of the first terminal device obtained by the second network device or the second terminal device.

[0129] Here, upon receiving the third request, the first network device first records the third request and its time. Then, it sets a validity period for the authentication certificate and starts timing. Next, it sends its IP address to the first terminal device, which then forwards the IP address to the second network device or the second terminal device. In this way, both the first and second network devices / terminal devices know each other's true address information. Based on this, they establish a trusted / secure connection (the first connection) through secure processes such as trusted remote authentication or two-way authentication. Based on this first connection, the first network device obtains a second identity identifier sent by the second network device / terminal device. This second identity identifier is the same one sent by the first terminal device to the second network device / terminal device.

[0130] Step 403: If the first server confirms that the second identity identifier is consistent with the first identity identifier and meets the set conditions, it sends the third information to the second network device or the second terminal device through the first connection.

[0131] The third information is used by the second network device or the second terminal device to obtain the security authentication result of the second identity identifier.

[0132] Here, after receiving the second identity identifier, the first network device verifies the second identity identifier and determines whether the second identity identifier sent by the first terminal device to the second network device or the second terminal device is consistent with the first identity identifier generated by the first network device for the first terminal device. Alternatively, if the two are consistent, the first network device further determines whether the first identity identifier is valid, thereby obtaining the security authentication result of the corresponding identity identifier, and returning the security authentication result to the second network device or the second terminal device through the first connection.

[0133] Specifically, the setting conditions include at least one of the following:

[0134] The first identity identifier is valid;

[0135] The first terminal device connects to the first network device;

[0136] The time limit for the third request is within the set time limit range.

[0137] Figure 5 In this application example, an IoT security smart gateway / router is used as the first network device, and an IoT terminal device is used as the first terminal device. Based on the corresponding system architecture, a secure authentication process for identity verification is illustrated. See also... Figure 5 :

[0138] 1. IoT terminal devices send their identity identifier, SecurityID, to the IoT cloud platform / remote device.

[0139] 2. If the IoT cloud platform / remote device needs to verify the SecurityID, it sends an identity verification request to the IoT terminal device.

[0140] 3. The IoT terminal device will inform the identity identification server in the IoT security smart gateway / router of the identity verification request and relevant information of the IoT cloud platform / remote device, such as the IP address of the IoT cloud platform / remote device.

[0141] 4. The identity server in the IoT security smart gateway / router records the identity verification request information and request time sent by the IoT terminal device, sets an validity period for the verification, and then uses the IP address of the IoT security smart gateway / router as the IP address of the identity generator / verifier and sends it to the IoT terminal device.

[0142] 5. The IoT terminal device sends the IP address of the identity generator / certifier to the IoT cloud platform / remote device.

[0143] 6. The IoT cloud platform / remote device attempts to establish a connection with the IoT security smart gateway / router based on the IP address of the identity generator / certifier provided by the IoT terminal device. A trusted / secure connection is established after both parties complete a secure process such as trusted remote verification or two-way authentication.

[0144] 7. Through a trusted / secure connection, the IoT cloud platform / remote device sends the SecurityID of the IoT terminal device to be verified to the IoT security smart gateway / router to request verification of the identity of the SecurityID.

[0145] 8. After receiving the application from the IoT cloud platform / remote device, the identity server of the IoT security smart gateway / router first checks whether the SecurityID sent by the IoT cloud platform / remote device is in the database, and confirms whether the IoT terminal device corresponding to the SecurityID is currently connected to this IoT security smart gateway / router. Then, it confirms whether the identity verification application has been registered by the IoT terminal device corresponding to the SecurityID, and whether the application is still within the set time limit. If all the above conditions are met, the MDs, PublicKey, and asymmetric cryptographic algorithm type corresponding to the SecurityID are returned to the IoT cloud platform / remote device through a trusted / secure connection. It should be noted that during the above security authentication process of the IoT security smart gateway / router, any abnormality will generate an alarm message, and the security authentication event must be recorded in the identity log.

[0146] 9. After receiving MDs, PublicKey, and the asymmetric cryptographic algorithm type, the IoT cloud platform / remote device uses PublicKey to decrypt SecurityID to obtain MDs', and then determines whether MDs' is consistent with MDs. If they are consistent, it proves that the SecurityID of the IoT terminal device is real and secure.

[0147] The aforementioned identity authentication process can be applied not only to the security authentication of the SecurityID of IoT terminal devices connected to the IoT security smart gateway / router by the IoT cloud platform / remote device, but also to the security authentication of the SecurityID between two IoT terminal devices connected to the same IoT security smart gateway / router. In both application scenarios, the identity authentication process is essentially similar, with the only difference being that when two IoT terminal devices connected to the same IoT security smart gateway / router are authenticating the SecurityID, the IoT terminal device initiating the authentication and the IoT security smart gateway / router do not need to undergo trusted remote proof or two-way authentication to establish a trusted / secure connection. This is because the IoT terminal device initiating the authentication is also connected to the IoT security smart gateway / router, and their connection is a confirmed local connection, which is secure and trusted.

[0148] Furthermore, the identity authentication scheme provided in this application can also be applied to devices with trusted functionality and direct internet connectivity. For example, it can be applied to the IoT security smart gateway / router itself, with the identity client installed and running in the normal operating area of ​​the trusted IoT security smart gateway / router. Figure 6 As shown, the identity client and identity server communicate through an internal local network. Furthermore, when the identity client is installed and run in the normal operating zone of a trusted IoT security smart gateway / router, the methods for generating and using the identity are completely consistent with the implementation of the relevant schemes in the embodiments of this application.

[0149] Based on the embodiments of this application, with the support of a trusted IoT security smart gateway / router, the identity identifier generated for IoT terminal devices is associated with multiple characteristics of the IoT terminal devices. These characteristics include the ability to incorporate scenario features of the IoT terminal devices during actual deployment, reflecting the identity status of the IoT terminal devices, possessing uniqueness, and exhibiting high security. Furthermore, the identity identifier generated by this solution can be widely used as a public identity identifier in various scenarios. Moreover, only a lightweight identity identifier client needs to be integrated into the IoT terminal device, and the IoT terminal device does not need to participate in any encryption calculations or store the identity identifier during its generation and use. Therefore, the application of this solution has minimal impact on the performance and cost of the IoT terminal devices themselves, and is easy to use. In addition, when an IoT terminal device is migrated, the IoT security smart gateway / router will invalidate the corresponding identity identifier, thus providing a certain degree of security protection against the migration and theft of IoT terminal devices.

[0150] To implement the method of the embodiments of this application, the embodiments of this application also provide an identity processing device, disposed on a first network device, the device operating in a TEE supported by a first chip in the first network device; the first chip includes a security chip or a trusted chip; such as Figure 7 As shown, the device includes:

[0151] The first processing unit 701 is configured to acquire a first request sent by a first terminal device; the first request is used to request the generation of an identity identifier for the first terminal device; the first request carries at least one piece of first information; the first information represents information used to describe the identity of the first terminal device.

[0152] The second processing unit 702 obtains a first identity identifier of the first terminal device; the first identity identifier is obtained by encrypting second information; the second information represents the digest information corresponding to the at least one piece of first information;

[0153] The third processing unit 703 sends the first identity identifier to the first terminal device.

[0154] In one embodiment, the at least one piece of first information includes at least one of the following pieces of information from the first terminal device:

[0155] Equipment Name;

[0156] Device serial number;

[0157] MAC address;

[0158] Work mode;

[0159] Uplink connection information.

[0160] In one embodiment, the device further includes:

[0161] The fourth processing unit is configured to perform a hash operation on the at least one piece of first information to obtain the second information before the first server obtains the first identity identifier of the first terminal device.

[0162] In one embodiment, the second processing unit 702 is configured to:

[0163] Send a second request to the first chip; the second request is used to request the first chip to encrypt the second information;

[0164] Obtain the response returned by the first chip based on the second request; the response carries the first identity identifier obtained by the first chip encrypting the second information based on the private key in the first key pair.

[0165] In one embodiment, the network device further includes a first database running in the TEE; the first database stores at least one identity identifier of a terminal device generated by the first network device; the third processing unit 703 is configured to:

[0166] If the first identity identifier is not found in the first database, the first identity identifier is sent to the first terminal device.

[0167] In one embodiment, the device further includes:

[0168] The fifth processing unit is configured to store the first identity identifier and at least one of the following information of the first terminal device into the first database:

[0169] The at least one first piece of information, the second piece of information, the first key pair used to encrypt the second piece of information, and / or the generation time of the first identity identifier.

[0170] In one embodiment, the first network device further includes a first logging module running in the TEE; the apparatus further includes:

[0171] The sixth processing unit is used to generate and store the first log; wherein,

[0172] The first log represents the log of operations related to the first identity identifier.

[0173] In one embodiment, the device further includes:

[0174] The seventh processing unit is configured to acquire a second request sent by the first terminal device; the second request is for requesting reconnection to the first network device; the second request carries the first identity identifier.

[0175] If the first terminal device is confirmed to be bound to the first network device based on the first identity identifier in the second request, the first terminal device is allowed to establish a connection with the first network device.

[0176] In one embodiment, the device further includes:

[0177] The eighth processing unit is used to set the first identity identifier to invalid when the first terminal device is unbound from the first network device.

[0178] In one embodiment, the device further includes:

[0179] The ninth processing unit is configured to acquire a third request sent by the first terminal device; the third request is configured to request the first network device to perform security authentication on the identity of the second network device or the second terminal device regarding the identity of the first terminal device.

[0180] Based on the first connection between the first network device and the second network device or the second terminal device, a second identity identifier sent by the second network device or the second terminal device is obtained; the second identity identifier represents the identity identifier of the first terminal device obtained by the second network device or the second terminal device.

[0181] If the first server confirms that the second identity identifier is consistent with the first identity identifier and meets the set conditions, it sends third information to the second network device or the second terminal device through the first connection; the third information is used by the second network device or the second terminal device to obtain the security authentication result of the second identity identifier.

[0182] In one embodiment, the setting conditions include at least one of the following:

[0183] The first identity identifier is valid;

[0184] The first terminal device connects to the first network device;

[0185] The time limit for the third request is within the set time limit range.

[0186] In one embodiment, the first connection between the first network device and the second network device is a trusted connection or a secure connection.

[0187] In practical applications, the first processing unit 701, the third processing unit 703, the seventh processing unit, and the ninth processing unit can be implemented by the communication interface in the identity processing device; the second processing unit 702 and the fourth, fifth, sixth, and eighth processing units can be implemented by the processor in the identity processing device.

[0188] It should be noted that the identity processing device provided in the above embodiments is only illustrated by the division of the above-described program modules. In practical applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. Furthermore, the identity processing device and the identity processing method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.

[0189] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of this application, the embodiments of this application also provide a first network device, such as... Figure 8 As shown, the first network device 800 includes:

[0190] The first communication interface 801 is capable of exchanging information with other network nodes;

[0191] The first processor 802 is connected to the first communication interface 801 to enable information interaction with other network nodes and to execute the methods provided by one or more of the above-mentioned technical solutions when running a computer program. The computer program is stored in the first memory 803.

[0192] Specifically, the first communication interface 801 is used to obtain a first request sent by the first terminal device in the TEE supported by the first chip; the first request is used to request the generation of an identity identifier for the first terminal device; the first request carries at least one piece of first information; the first information represents information used to describe the identity of the first terminal device;

[0193] The first processor 802 is configured to obtain a first identity identifier of the first terminal device in the TEE; the first identity identifier is obtained by encrypting second information; the second information represents digest information corresponding to at least one piece of first information;

[0194] The first communication interface 801 is also used to send the first identity identifier to the first terminal device in the TEE.

[0195] In one embodiment, the at least one piece of first information includes at least one of the following pieces of information from the first terminal device:

[0196] Equipment Name;

[0197] Device serial number;

[0198] MAC address;

[0199] Work mode;

[0200] Uplink connection information.

[0201] In one embodiment, the first processor 802 is further configured to perform a hash operation on the at least one first piece of information in the TEE before the first server obtains the first identity identifier of the first terminal device, so as to obtain the second information.

[0202] In one embodiment, the first processor 802 is configured to send a second request to the first chip in the TEE; the second request is configured to request the first chip to encrypt the second information; obtain a response returned by the first chip based on the second request; the response carries the first identity identifier obtained by the first chip encrypting the second information based on the private key in the first key pair.

[0203] In one embodiment, the network device further includes a first database running in the TEE; the first database stores at least one identity identifier of a terminal device generated by the first network device; the first communication interface 801 is further configured to send the first identity identifier to the first terminal device if the first identity identifier is not stored in the first database when queried in the TEE.

[0204] In one embodiment, the first processor 802 is configured to store the first identity identifier and at least one of the following information of the first terminal device into the first database in the TEE:

[0205] The at least one first piece of information, the second piece of information, the first key pair used to encrypt the second piece of information, and / or the generation time of the first identity identifier.

[0206] In one embodiment, the first network device further includes a first logging module running in the TEE; the first processor 802 is configured to generate and store a first log in the TEE; wherein,

[0207] The first log represents the log of operations related to the first identity identifier.

[0208] In one embodiment, the first communication interface 801 is further configured to obtain a second request sent by the first terminal device in the TEE; the second request is used to request reconnection to the first network device; the second request carries the first identity identifier;

[0209] If the first terminal device is confirmed to be bound to the first network device based on the first identity identifier in the second request, the first terminal device is allowed to establish a connection with the first network device.

[0210] In one embodiment, when the first terminal device is unbound from the first network device, the first processor 802 is used to set the first identity identifier to be invalid in the TEE.

[0211] In one embodiment, the first communication interface 801 is further configured to acquire a third request sent by the first terminal device; the third request is used to request the first network device to perform security authentication on the identity identifier of the first terminal device for the second network device or the second terminal device; based on the first connection between the first network device and the second network device or the second terminal device, the first server acquires a second identity identifier sent by the second network device or the second terminal device; the second identity identifier represents the identity identifier of the first terminal device acquired by the second network device or the second terminal device; if it is confirmed that the second identity identifier is consistent with the first identity identifier and meets the set conditions, third information is sent to the second network device or the second terminal device through the first connection; the third information is used by the second network device or the second terminal device to acquire the security authentication result of the second identity identifier.

[0212] In one embodiment, the setting conditions include at least one of the following:

[0213] The first identity identifier is valid;

[0214] The first terminal device connects to the first network device;

[0215] The time limit for the third request is within the set time limit range.

[0216] In one embodiment, the first connection between the first network device and the second network device is a trusted connection or a secure connection.

[0217] It should be noted that the specific processing procedures of the first processor 802 and the first communication interface 801 can be understood by referring to the above method.

[0218] Of course, in practical applications, the various components in the first network device 800 are coupled together through the bus system 804. It can be understood that the bus system 804 is used to implement communication between these components. In addition to a data bus, the bus system 804 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 8 The general labeled all buses as Bus System 804.

[0219] The first memory 803 in this embodiment is used to store various types of data to support the operation of the first network device 800. Examples of such data include any computer program used to operate on the first network device 800.

[0220] The methods disclosed in the above embodiments of this application can be applied to the first processor 802, or implemented by the first processor 802. The first processor 802 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware or by instructions in the form of software in the first processor 802. The first processor 802 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 802 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly reflected as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the first memory 803. The first processor 802 reads the information in the first memory 803 and completes the steps of the aforementioned method in combination with its hardware.

[0221] In an exemplary embodiment, the first network device 800 may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.

[0222] It is understood that the first memory 803 in this embodiment can be volatile memory or non-volatile memory, or both. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); the magnetic surface memory can be disk storage or magnetic tape storage. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memories.

[0223] In an exemplary embodiment, this application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, such as a first memory 803 storing a computer program, which can be executed by the first processor 802 of the first network device 800 to complete the steps described in the aforementioned method. The computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.

[0224] It should be noted that terms such as "first" and "second" are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0225] In this document, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. Furthermore, the term "at least one" in this document means any combination of at least two of any one or more elements. For example, including at least one of A, B, and C can mean including any one or more elements selected from the set consisting of A, B, and C.

[0226] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.

[0227] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.

Claims

1. A method for processing identity identifiers, characterized in that, The first network device includes a first chip and a first server running in a Trusted Execution Environment (TEE) supported by the first chip; the first chip includes a security chip or a trusted chip. The first network device is used to connect various IoT terminals located in the same local area network within the IoT sensing and control domain; the method includes: The first server receives a first request sent by the first terminal device; the first request is used to request the generation of an identity identifier for the first terminal device; the first request carries at least one piece of first information; the first information represents information used to describe the identity of the first terminal device. The first server obtains the first identity identifier of the first terminal device; the first identity identifier is obtained by encrypting second information in a TEE supported by the security chip or trusted chip; the second information represents the digest information corresponding to the at least one first information; before the first server obtains the first identity identifier of the first terminal device, the first server or the first chip performs a hash operation on the at least one first information to obtain the second information; The first server sends the first identity identifier to the first terminal device; The first server receives a fourth request sent by the first terminal device; the fourth request is used to request reconnection to the first network device; the fourth request carries the first identity identifier. If the first server confirms that the first terminal device is bound to the first network device based on the first identity identifier in the fourth request, the first terminal device is allowed to establish a connection with the first network device.

2. The method according to claim 1, characterized in that, The at least one piece of first information includes at least one of the following pieces of information from the first terminal device: Equipment Name; Device serial number; Media Access Control (MAC) address; Work mode; Uplink connection information.

3. The method according to claim 1, characterized in that, The first server obtains the first identity identifier of the first terminal device, including: The first server sends a second request to the first chip; the second request is used to request the first chip to encrypt the second information; The first server obtains the response returned by the first chip based on the second request; the response carries the first identity identifier obtained by the first chip encrypting the second information based on the private key in the first key pair.

4. The method according to claim 1, characterized in that, The network device further includes a first database running in the TEE; the first database stores at least one identity identifier of a terminal device generated by the first network device; The first server sends the first identity identifier to the first terminal device, including: If the first server finds that the first identity identifier is not stored in the first database, the first server will send the first identity identifier to the first terminal device.

5. The method according to claim 4, characterized in that, The method further includes: The first server stores the first identity identifier and at least one of the following pieces of information from the first terminal device into the first database: The at least one first piece of information, the second piece of information, the first key pair used to encrypt the second piece of information, and / or the generation time of the first identity identifier.

6. The method according to claim 1, characterized in that, The first network device further includes a first logging module running in the TEE; the method further includes: The first log module generates and stores the first log; wherein, The first log represents the log of operations related to the first identity identifier.

7. The method according to claim 1, characterized in that, The method further includes: When the first terminal device is unbound from the first network device, the first server sets the first identity identifier to be invalid.

8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: The first server receives a third request sent by the first terminal device; the third request is used to request the first network device to perform security authentication on the identity of the second network device or the second terminal device. Based on the first connection between the first network device and the second network device or the second terminal device, the first server obtains the second identity identifier sent by the second network device or the second terminal device; the second identity identifier represents the identity identifier of the first terminal device obtained by the second network device or the second terminal device. If the first server confirms that the second identity identifier is consistent with the first identity identifier and meets the set conditions, it sends third information to the second network device or the second terminal device through the first connection; the third information is used by the second network device or the second terminal device to obtain the security authentication result of the second identity identifier.

9. The method according to claim 8, characterized in that, The setting conditions include at least one of the following: The first identity identifier is valid; The first terminal device connects to the first network device; The time limit for the third request is within the set time limit range.

10. The method according to claim 8, characterized in that, The first connection between the first network device and the second network device is a trusted connection or a secure connection.

11. An identification processing device, characterized in that, Applied to a first server, the device operates in a TEE supported by a first chip in a first network device; the first chip includes a security chip or a trusted chip; The first network device is used to connect various IoT terminals located in the same local area network within the IoT sensing and control domain; the device includes: A first processing unit is configured to acquire a first request sent by a first terminal device; the first request is used to request the generation of an identity identifier for the first terminal device; the first request carries at least one piece of first information; the first information represents information used to describe the identity of the first terminal device. The second processing unit obtains a first identity identifier of the first terminal device; the first identity identifier is obtained by encrypting second information in a TEE supported by the security chip or trusted chip; the second information represents digest information corresponding to at least one piece of first information; The third processing unit sends the first identity identifier to the first terminal device; The fourth processing unit is configured to perform a hash operation on the at least one piece of first information to obtain the second information before the first server obtains the first identity identifier of the first terminal device; The seventh processing unit is configured to acquire a fourth request sent by the first terminal device; the fourth request is for requesting reconnection to the first network device; the fourth request carries the first identity identifier; and if the first server confirms that the first terminal device is bound to the first network device based on the first identity identifier in the fourth request, it allows the first terminal device to establish a connection with the first network device.

12. A first network device, characterized in that, The first network device includes a first chip and a first server running in a Trusted Execution Environment (TEE) supported by the first chip; the first server includes a first processor and a first communication interface; the first chip includes a security chip or a trusted chip; the first network device is used to connect various IoT terminals located in the same local area network within an IoT sensing and control domain; wherein... The first communication interface is used to obtain a first request sent by a first terminal device in a TEE supported by the first chip; the first request is used to request the generation of an identity identifier for the first terminal device; the first request carries at least one piece of first information; the first information represents information describing the identity of the first terminal device; the first processor is used to obtain the first identity identifier of the first terminal device in the TEE; the first identity identifier is obtained by encrypting second information in the TEE supported by the security chip or trusted chip; the second information represents digest information corresponding to the at least one piece of first information; The first communication interface is further configured to send the first identity identifier to the first terminal device in the TEE; and to obtain a fourth request sent by the first terminal device in the TEE; the fourth request is used to request reconnection to the first network device; the fourth request carries the first identity identifier; and if the first server confirms that the first terminal device is bound to the first network device based on the first identity identifier in the fourth request, the first terminal device is allowed to establish a connection with the first network device. The first processor is further configured to perform a hash operation on the at least one first piece of information in the TEE before the first server obtains the first identity identifier of the first terminal device, so as to obtain the second information.

13. An Internet of Things (IoT) system, characterized in that, The device includes a first terminal device and a first network device. The first network device includes a first chip and a first server running in a TEE supported by the first chip. The first chip includes a security chip or a trusted chip. The first network device is used to connect various IoT terminals located in the same local area network within an IoT sensing and control domain. The first server is configured to receive a first request sent by the first terminal device; the first request is configured to request the generation of an identity identifier for the first terminal device; the first request carries at least one piece of first information; the first information represents information used to describe the identity of the first terminal device; The first server is further configured to obtain a first identity identifier of the first terminal device; the first identity identifier is obtained by encrypting second information in a TEE supported by the security chip or trusted chip; the second information represents digest information corresponding to at least one piece of first information; The first server is further configured to send the first identity identifier to the first terminal device; The first server is further configured to perform a hash operation on the at least one first piece of information to obtain the second information before the first server obtains the first identity identifier of the first terminal device; The first server is further configured to obtain a fourth request sent by the first terminal device; the fourth request is used to request reconnection to the first network device; the fourth request carries the first identity identifier; and, if the first server confirms that the first terminal device is bound to the first network device based on the first identity identifier in the fourth request, allow the first terminal device to establish a connection with the first network device.

Citation Information

Patent Citations

  • Equipment identity information distribution method, device and system

    CN106453246A

  • Method and apparatus for assigning device identity identifiers

    CN106960148A

  • Information interaction method and device thereof and computing equipment

    CN111464486A