Remote access method and storage medium for IoT devices without an account system

Generating unique IDs and electronic credentials through account binding without an account, solving the inconvenience and security risks of account login in the Internet of Things device management, realizing reliable remote access and operation without an account, and improving user experience.

CN115913612BActive Publication Date: 2025-06-10SHENZHEN NETIS TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211122538.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-15
Publication Date
2025-06-10
Estimated Expiration
2042-09-15

AI Technical Summary

Technical Problem

The existing IoT device management method requires users to log in to their account, which poses inconvenience and security risks.

Method used

The remote access method without an account system is adopted, and the account-free binding is performed with the IOT device through a mobile smart terminal, and a unique ID and electronic credentials are generated for authentication and execution of operation instructions.

Benefits of technology

It realizes reliable remote access and operation of IOT devices without an account, improves user experience, and avoids the complexity of personal privacy leakage and account management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913612B_ABST
    Figure CN115913612B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for remotely accessing an IoT device without an account system, which is implemented on the basis that the IoT device management client and the IoT device have been bound without an account. The client uses the unique ID of the IoT device to specify the target, and uses an electronic certificate as the authentication basis to send an operation instruction. After the cloud server preliminarily identifies and locates the target IoT device, the instruction is forwarded. After receiving the instruction information, the target IoT device determines whether the source of the instruction information is legal through the electronic certificate. If it is legal, the operation instruction is executed and the result is feedback, thereby realizing the remote access process. The whole process and the whole system of the present invention do not involve the personal privacy information of users, nor do they need to manage the account information of users, will not disclose user privacy, effectively improve the user experience, and is convenient and fast to use.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to Internet of Things (IoT) link communication technology, and more specifically, to a method for remotely accessing an IoT device without an account system and a storage medium. Background Art

[0002] The Internet of Things (IoT) is a network that links physical devices, vehicles, buildings, and other things embedded with electronic devices, software, sensors, etc., enabling these objects to collect and exchange data. IoT devices are devices used to achieve links within the IoT, such as smart home devices.

[0003] Normally, IoT devices are bound to a user's account for easy management. However, in actual use, it is necessary to log in to the user account on a mobile intelligent terminal such as a mobile phone, which is somewhat inconvenient in terms of operation. Moreover, existing methods of this kind require users to register an account in advance or have a third-party account (such as QQ, WeChat, Facebook, etc.), and user personal privacy is easily leaked during the use of the account. In some cases, it is claimed that the IoT device is bound to a mobile intelligent terminal such as a mobile phone, but in fact, the IoT device is not directly bound to the mobile phone. Instead, the IoT device is first bound to an account, and then the account or the corresponding app is bound to the mobile phone. Its essence is to manage the device based on the user's account, and the mobile intelligent terminal such as a mobile phone also belongs to the device to be managed. When implementing IoT device management operations such as remote access, it is also based on the user's account, and it is necessary to log in to the corresponding user account, which also has security problems and inconvenience in use. Summary of the Invention

[0004] In view of the above problems in the prior art, the present invention provides a method for remotely accessing an IoT device without an account system, which enables a mobile intelligent terminal such as a mobile phone to be directly bound to the IoT device without an account, and then realizes reliable remote access and operation functions.

[0005] To achieve the above object, the technical solution adopted by the present invention is as follows:

[0006] A method for remotely accessing an IoT device without an account system, which is applied to an IoT device management client and configured on a mobile intelligent terminal to have a unique terminal identifier. The remote access method includes:

[0007] After performing an account-free binding with the IoT device, obtaining the unique ID of the IoT device and the electronic certificate generated by the IoT device based on the terminal identifier, forming a mapping relationship between the terminal identifier and the unique ID of the IoT device, and locally saving the mapping relationship and the electronic certificate;

[0008] In response to the confirmation of issuing an operation instruction for the bound IoT device, obtain the unique ID of the IoT device and its electronic certificate saved locally, and construct instruction information together with the operation instruction;

[0009] Send the instruction information to the specified IoT device through the cloud server, so that the specified IoT device authenticates the source of the instruction information and executes the operation instruction after successful authentication. Among them, the specified IoT device is determined by the unique ID of the IoT device, and the source of the instruction information is determined by the electronic certificate;

[0010] Receive the feedback that the specified IoT device has completed the execution of the operation instruction or the feedback that the authentication of the specified IoT device fails.

[0011] Specifically, the terminal identifier is configured as a random number of sufficient length or / and the identity information code of the mobile intelligent terminal; the electronic certificate generated by the IoT device based on the terminal identifier is obtained by an irreversible algorithm from a new string composed of the terminal identifier and a random string generated by the IoT device.

[0012] Specifically, the process for the specified IoT device to authenticate the source of the instruction information is as follows:

[0013] The specified IoT device compares the electronic certificate carried in the instruction information with the electronic certificate saved locally by itself. If the two are consistent, the authentication is successful and the operation instruction is executed. If the two are inconsistent, the authentication fails and the execution of the operation instruction is refused.

[0014] Specifically, the feedback that the specified IoT device has completed the execution of the operation instruction and the feedback that the authentication of the specified IoT device fails are both transmitted to the IoT device management client through the cloud server.

[0015] Further, the process for the IoT device management client to perform accountless binding with the IoT device is as follows:

[0016] In response to the input of the determined IoT device administrator password, form a string with the terminal identifier and the input IoT device administrator password, and calculate the first verification value through an irreversible algorithm;

[0017] Send the terminal identifier and the first verification value to the IoT device to be bound through the local local area network for verification;

[0018] Determine whether the verification is passed. If not, terminate the operation. If so, receive the electronic certificate based on the terminal identifier returned by the IoT device to be bound and the unique ID of the IoT device to be bound, and save the received electronic certificate locally.

[0019] Establish a mapping relationship between the terminal identifier and the unique ID of the iot device to be bound, and save the mapping relationship locally to complete accountless binding.

[0020] Another object of the present invention is to provide the following technical solution:

[0021] A remote access method for an accountless iot device, which is applied to an iot device with a unique ID. The remote access method includes:

[0022] After performing accountless binding with an iot device management client configured on a mobile intelligent terminal and having a unique terminal identifier, generate an electronic voucher according to the terminal identifier, and reply the electronic voucher and the iot device unique ID to the iot device management client to enable it to establish a mapping relationship with the iot device unique ID;

[0023] Receive, through the cloud server, instruction information including an operation instruction and an electronic voucher sent by the iot device management client according to the iot device unique ID;

[0024] Extract the electronic voucher from the received instruction information, compare it with the electronic voucher saved locally, and determine whether the two are consistent. If not, the authentication fails, the operation instruction is refused to be executed, and feedback is sent to the cloud server so that the iot device management client can learn the message of authentication failure;

[0025] If so, the authentication is successful, the operation instruction is executed, and feedback is sent to the cloud server after the operation instruction is completed so that the iot device management client can learn the message of completing the operation instruction.

[0026] Specifically, the process of generating the electronic voucher according to the terminal identifier is as follows:

[0027] Combine the terminal identifier from the iot device management client with a random string generated by the iot device itself to form a new string, and then calculate the result through an irreversible algorithm as the electronic voucher;

[0028] The terminal identifier is configured as a random number of sufficient length or / and the identity information encoding of the mobile intelligent terminal.

[0029] Specifically, the iot device establishes a connection mapping relationship with the cloud server based on the iot device unique ID through an asymmetric encryption method, and generates a symmetric encryption key, and uses the symmetric encryption key for content encryption and decryption when the iot device communicates with the cloud server for instruction information.

[0030] Further, the process of the iot device performing accountless binding with an iot device management client configured on a mobile intelligent terminal and having a unique terminal identifier is:

[0031] Receive a first verification value sent by an IoT device management client via a local area network and a terminal identifier uniquely representing the mobile intelligent terminal, where the first verification value is calculated by an irreversible algorithm from a string composed of the terminal identifier and the administrator password of the IoT device obtained by the mobile intelligent terminal in response to input;

[0032] Extract the administrator password stored locally, form a string by combining the received terminal identifier and the administrator password obtained by extracting the local storage, and calculate a second verification value through an irreversible algorithm;

[0033] Determine whether the second verification value is consistent with the received first verification value. If not, terminate the operation. If so, generate an electronic voucher based on the terminal identifier and save the electronic voucher in a local non-volatile memory;

[0034] Reply the electronic voucher and the unique ID of the IoT device to the IoT device management client, so that the IoT device management client establishes a mapping relationship with the unique ID of the IoT device and saves the mapping relationship and the electronic voucher locally to complete accountless binding.

[0035] Another object of the present invention is to provide the following technical solution:

[0036] A remote access method for an accountless IoT device, which is applied to a cloud server that communicates with the IoT device using symmetric encryption. A connection mapping relationship table based on the unique ID of the IoT device is stored on the cloud server. The remote access method includes:

[0037] Receive instruction information sent by an IoT device management client, which includes the unique ID of the IoT device, an electronic voucher, and an operation instruction;

[0038] Extract the unique ID of the IoT device from the instruction information and query the target IoT device corresponding to the unique ID of the IoT device in the connection mapping relationship table;

[0039] Encrypt the instruction information using symmetric encryption and send it to the target IoT device, so that it uses the electronic voucher stored locally for authentication and executes the operation instruction after successful authentication;

[0040] Receive the feedback information after the target IoT device authenticates or executes the operation instruction, and reply the feedback information to the IoT device management client, where the feedback information of the target IoT device is also encrypted using symmetric encryption.

[0041] Specifically, the process of the target IoT device using the electronic voucher stored locally for authentication is:

[0042] The target IoT device extracts the electronic certificate in the instruction information and compares it with the electronic certificate stored in itself. If the two are consistent, the authentication is successful and the operation instruction is executed. If the two are inconsistent, the authentication fails and the execution of the operation instruction is refused.

[0043] Furthermore, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned remote access method for an IoT device without an account system are implemented.

[0044] Compared with the prior art, the present invention has the following beneficial effects:

[0045] Based on the account-free binding between the IoT device management client configured on the mobile intelligent terminal and the IoT device, the present invention uses the electronic certificate obtained during the account-free binding process and the mapping relationship between the terminal identifier and the unique ID of the IoT device as the authentication conditions for the remote access process. The entire process and the entire system do not involve the personal privacy information of users, nor do they need to manage the account information of users, so as not to disclose user privacy, effectively improving the user experience, and being convenient and fast to use. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 It is a schematic flowchart of the remote access method implemented by the client in Embodiment 1 of the present invention.

[0047] Figure 2 It is a schematic flowchart of the account-free binding performed by the client in Embodiment 1 of the present invention.

[0048] Figure 3 It is a schematic flowchart of the remote access method implemented by the IoT device in Embodiment 2 of the present invention.

[0049] Figure 4 It is a schematic flowchart of the account-free binding performed by the IoT device in Embodiment 2 of the present invention.

[0050] Figure 5 It is a schematic flowchart of the remote access method implemented by the cloud server in Embodiment 3 of the present invention.

[0051] Figure 6 It is a schematic flowchart of the remote access method implemented by the three parties of the client, the cloud server, and the IoT device in Embodiment 4 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0052] The present invention will be further described below in conjunction with the drawings and embodiments. The implementation manners of the present invention include but are not limited to the following embodiments.

[0053] Embodiment 1

[0054] As Figure 1 shown, the remote access method for accountless IoT devices provided in this embodiment is applied to an IoT device management client, which is configured on a mobile intelligent terminal to have a unique terminal identifier. The remote access method includes:

[0055] After binding to an IoT device without an account, obtain the unique ID of the IoT device and the electronic certificate generated by the IoT device based on the terminal identifier, form a mapping relationship between the terminal identifier and the unique ID of the IoT device, and locally save the mapping relationship and the electronic certificate;

[0056] In response to a confirmation to issue an operation instruction for the bound IoT device, obtain the unique ID of the IoT device and its electronic certificate saved locally, and jointly construct instruction information with the operation instruction;

[0057] Send the instruction information to a specified IoT device through a cloud server, so that the specified IoT device authenticates the source of the instruction information and executes the operation instruction after successful authentication. Among them, the specified IoT device is determined by the unique ID of the IoT device, and the source of the instruction information is determined by the electronic certificate;

[0058] Receive the feedback that the specified IoT device has completed the execution of the operation instruction or the feedback that the authentication of the specified IoT device fails.

[0059] Specifically, the terminal identifier is configured as a random number of sufficient length or / and the identity information code of the mobile intelligent terminal. When using the identity information code of the mobile intelligent terminal, the identity information code can be generated by a specified code on the mobile intelligent terminal, such as generating a unique string by IMEI + manufacturer code + model code + WIFI MAC + Bluetooth MAC as the terminal identifier; the electronic certificate generated by the IoT device based on the terminal identifier is obtained by an irreversible algorithm from a new string composed of the terminal identifier and a random string generated by the IoT device. Among them, the irreversible algorithm uses the HASH algorithm to calculate a specific HASH value as the corresponding verification value, and the HASH algorithm is such as SHA1, SHA256, etc.

[0060] Specifically, the process for the specified IoT device to authenticate the source of the instruction information is:

[0061] The specified IoT device compares the electronic certificate carried in the instruction information with the electronic certificate saved locally by itself. If the two are the same, the authentication is successful and the operation instruction is executed. If the two are different, the authentication fails and the execution of the operation instruction is refused.

[0062] Specifically, the feedback on the completion of the operation instruction by the specified IoT device and the feedback on the authentication failure of the specified IoT device are both transmitted to the IoT device management client through the cloud server.

[0063] Further, as Figure 2 shown, the process of the IoT device management client binding without an account to the IoT device is as follows:

[0064] In response to determining the input of the IoT device administrator password, a string is formed by combining the terminal identifier and the input IoT device administrator password, and a first verification value is calculated through an irreversible algorithm;

[0065] The terminal identifier and the first verification value are sent to the IoT device to be bound through the local local area network for verification; during verification, the IoT device forms a string by combining the terminal identifier with its stored administrator password, calculates a second verification value using the same irreversible algorithm, and determines whether the first verification value is consistent with the second verification value. If they are consistent, the verification passes; if not, the verification fails.

[0066] Determine whether the verification passes. If not, terminate the operation; if so, receive the electronic certificate based on the terminal identifier returned by the IoT device to be bound and the unique ID of the IoT device to be bound, and save the received electronic certificate locally;

[0067] Establish a mapping relationship between the terminal identifier and the unique ID of the IoT device to be bound, and save the mapping relationship locally to complete the binding without an account.

[0068] Furthermore, for security considerations, an expiration period can also be configured for the electronic certificate when it is saved. When the saving time of the electronic certificate reaches the expiration period, the electronic certificate is deleted or marked as invalid. At this time, the client cannot correctly obtain the electronic certificate, so the remote access operation cannot be performed, and the user is prompted to re-perform the process of binding without an account under the local local area network.

[0069] On the other hand, when the IoT device changes the administrator password, it will cause the electronic certificate comparison in the authentication instruction information to be inconsistent, resulting in authentication failure. After the client receives the corresponding authentication failure feedback, it prompts the user to re-perform the process of binding without an account under the local local area network.

[0070] Embodiment 2

[0071] As Figure 3 shown, the remote access method for the IoT device without an account system provided in this embodiment is applied to an IoT device with a unique ID. The remote access method includes:

[0072] After performing accountless binding with the IoT device management client configured on the mobile intelligent terminal and having a unique terminal identifier, generate an electronic voucher according to the terminal identifier, and reply the electronic voucher and the unique ID of the IoT device to the IoT device management client, so that it establishes a mapping relationship with the unique ID of the IoT device;

[0073] Receive, through the cloud server, instruction information including an operation instruction and an electronic voucher sent by the IoT device management client according to the unique ID of the IoT device;

[0074] Extract the electronic voucher from the received instruction information, compare it with the locally saved electronic voucher, and determine whether the two are consistent. If not, the authentication fails, the operation instruction is refused to be executed, and feedback is sent to the cloud server so that the IoT device management client can learn the message of authentication failure;

[0075] If so, the authentication is successful, the operation instruction is executed, and feedback is sent to the cloud server after the operation instruction is completed so that the IoT device management client can learn the message of completing the operation instruction.

[0076] Specifically, the process of generating the electronic voucher according to the terminal identifier is as follows:

[0077] Combine the terminal identifier from the IoT device management client with the random string generated by the IoT device itself to form a new string, and then calculate the result through an irreversible algorithm as the electronic voucher;

[0078] The terminal identifier is configured as a random number of sufficient length or / and the identity information code of the mobile intelligent terminal. When using the identity information code of the mobile intelligent terminal, the identity information code can be generated by a specified code on the mobile intelligent terminal, such as generating a string with sufficient uniqueness as the terminal identifier by combining IMEI + manufacturer code + model code + WIFI MAC + Bluetooth MAC.

[0079] Specifically, the IoT device establishes a connection mapping relationship based on the unique ID of the IoT device with the cloud server through an asymmetric encryption method, and generates a symmetric encryption key, so that the symmetric encryption key is used for content encryption and decryption when the IoT device communicates with the cloud server for instruction information. Specifically, the IoT device initiates a TCP connection establishment request to the cloud server, encrypts the unique ID of the IoT device and the device MAC with the device public key and sends them to the cloud server. The cloud server decrypts them with the server private key, obtains the unique ID of the IoT device and the corresponding device MAC, and saves them in the server database, thereby establishing a corresponding TCP connection mapping relationship; then the cloud server generates a random number of a specified length as the symmetric encryption key, such as an AES key, encrypts the symmetric encryption key with the server private key, and then sends it to the IoT device; the IoT device decrypts it with the device public key, extracts the symmetric encryption key and saves it, so that the subsequent communication between the IoT device and the cloud server uses the symmetric encryption key for encryption and decryption processing.

[0080] Further, as Figure 4 shown, the process for the IoT device to perform account-free binding with the IoT device management client configured on the mobile intelligent terminal and having a unique terminal identifier is as follows:

[0081] Receive the first verification value sent by the IoT device management client and the terminal identifier uniquely representing the mobile intelligent terminal through the local local area network. The first verification value is calculated by an irreversible algorithm from a string composed of the terminal identifier and the administrator password of the IoT device obtained by the mobile intelligent terminal in response to the input;

[0082] Extract the administrator password stored in itself, form a string with the received terminal identifier and the administrator password obtained by extracting the stored one in itself, and calculate a second verification value through an irreversible algorithm;

[0083] Judge whether the second verification value is consistent with the received first verification value. If not, terminate the operation. If so, generate an electronic certificate based on the terminal identifier and save the electronic certificate in the local non-volatile memory;

[0084] Reply the electronic certificate and the unique ID of the IoT device to the IoT device management client, so that the IoT device management client establishes a mapping relationship with the unique ID of the IoT device and saves the mapping relationship and the electronic certificate locally to complete the account-free binding.

[0085] Further, an expiration period is configured for the electronic certificate stored in the IoT device. When the storage time of the electronic certificate reaches this expiration period, the electronic certificate is deleted or marked as invalid. Similarly, if the administrator password of the IoT device is modified, the originally saved electronic certificate is also deleted or marked as invalid. When the electronic certificate locally saved in the IoT device is deleted or in an invalid state, it will inevitably lead to authentication failure during the process of comparing and authenticating the electronic certificate in the received instruction information. At this time, after the information of authentication failure is fed back to the client, the client prompts the user to re - perform the process of account - less binding.

[0086] Embodiment 3

[0087] As Figure 5 shown, the remote access method for the account - less system IoT device provided in this embodiment is applied to a cloud server that communicates with the IoT device using symmetric encryption. A connection mapping relationship table based on the unique ID of the IoT device is saved on the cloud server. The remote access method includes:

[0088] Receiving instruction information containing the unique ID of the IoT device, an electronic certificate, and an operation instruction sent from an IoT device management client;

[0089] Extracting the unique ID of the IoT device from the instruction information and querying the target IoT device corresponding to this unique ID of the IoT device in the connection mapping relationship table; At this time, if the corresponding IoT device cannot be queried in the connection mapping relationship table, it indicates that the unique ID is incorrect, and the user is prompted with error information or try again after device binding;

[0090] Encrypting the instruction information using symmetric encryption and sending it to the target IoT device, enabling it to authenticate using the electronic certificate stored in itself and execute the operation instruction after successful authentication;

[0091] Receiving the feedback information after the target IoT device authenticates or executes the operation instruction, and replying this feedback information to the IoT device management client, where the feedback information of the target IoT device is also encrypted using symmetric encryption.

[0092] Specifically, the process of the target IoT device authenticating using the electronic certificate stored in itself is as follows:

[0093] The target IoT device extracts the electronic certificate in the instruction information and compares it with the electronic certificate stored in itself. If the two are the same, the authentication is successful, and the operation instruction is executed. If the two are different, the authentication fails, and the operation instruction is refused to be executed.

[0094] For the process of symmetric encryption communication between IoT devices and cloud servers, and the preservation of a connection mapping relationship table based on the unique ID of IoT devices on the cloud server. Specifically, the IoT device initiates a TCP connection establishment request to the cloud server, encrypts the unique ID of the IoT device and the device MAC using the device public key, and sends them to the cloud server. The cloud server decrypts them using the server private key, obtains the unique ID of the IoT device and the corresponding device MAC, saves them in the server database, and thus establishes the corresponding TCP connection mapping relationship. Then, the cloud server generates a random number of a specified length as the symmetric encryption key, such as an AES key, encrypts the symmetric encryption key using the server private key, and sends it to the IoT device. The IoT device decrypts it using the device public key, extracts and saves the symmetric encryption key, and uses this symmetric encryption key for encryption and decryption processing in the subsequent communication between the IoT device and the cloud server.

[0095] Embodiment 4

[0096] As Figure 6 As shown, the remote access method for accountless IoT devices provided in this embodiment realizes the interaction of the remote access process between the IoT device management client and the IoT device through the cloud server, where the IoT device management client is configured on the mobile intelligent terminal to have a unique terminal identifier, and the IoT device has a unique ID. The implementation process is as follows:

[0097] First is the interaction process of enhancing the security between the IoT device and the cloud server: The IoT device initiates a TCP connection establishment request to the cloud server, encrypts the unique ID of the IoT device and the device MAC using the device public key, and sends them to the cloud server. The cloud server decrypts them using the server private key, obtains the unique ID of the IoT device and the corresponding device MAC, saves them in the server database, and thus establishes the corresponding TCP connection mapping relationship. Then, the cloud server generates a random number of a specified length as the symmetric encryption key, such as an AES key, encrypts the symmetric encryption key using the server private key, and sends it to the IoT device. The IoT device decrypts it using the device public key, extracts and saves the symmetric encryption key, and uses this symmetric encryption key for encryption and decryption processing in the subsequent communication between the IoT device and the cloud server.

[0098] Then, in response to the user's confirmation, the client issues an operation instruction for the bound IoT device, obtains the unique ID of the IoT device and its electronic certificate saved locally, constructs instruction information together with the operation instruction, and sends the instruction information to the cloud server.

[0099] The cloud server receives instruction information sent from a client, which includes the unique ID of the IoT device, an electronic certificate, and an operation instruction; extracts the unique ID of the IoT device from the instruction information, and queries the target IoT device, device MAC, and connection mapping relationship corresponding to the unique ID of the IoT device in the connection mapping relationship table of the server database; then encrypts the instruction information using a symmetric encryption method and sends it to the target IoT device;

[0100] After receiving the instruction information, the IoT device extracts the electronic certificate therein, compares it with the electronic certificate locally saved in the IoT device, and determines whether the two are consistent. If not, the authentication fails, the operation instruction is refused to be executed, and a feedback is sent to the cloud server; if so, the authentication is successful, the operation instruction is executed, and a feedback is sent to the cloud server after the operation instruction is completed;

[0101] The cloud server receives the feedback information after the target IoT device authenticates or executes the operation instruction, and replies the feedback information to the IoT device management client;

[0102] The client receives the feedback information that the target IoT device has completed the execution of the operation instruction or the feedback information that the authentication of the target IoT device fails, and completes the remote access process.

[0103] Embodiment 5

[0104] This embodiment provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the remote access method for IoT devices without an account system are implemented.

[0105] The computer storage medium of the embodiments of the present application can adopt any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device.

[0106] A computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which computer-readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0107] The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to wireless, wire, optical fiber cable, RF, etc., or any suitable combination of the above.

[0108] The computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).

[0109] The present invention also provides the following application examples to further illustrate the process of the remote access method for accountless IoT devices:

[0110] Taking the IoT device as an intelligent router as an example, the same applies to smart home devices such as smart lights and smart gateways that do not have display devices and input devices. Taking the mobile intelligent terminal as a mobile phone as an example, the same applies to intelligent terminals such as tablet computers and PDAs that have display devices and input devices. The IoT device management client APP is installed and configured on the mobile phone.

[0111] On the mobile phone APP, a unique terminal identifier is generated through an identifier generation module. This identifier generation module generates a mobile phone ID (terminal identifier) by generating a random number of a specified length or by extracting the combination of IMEI + manufacturer code + model code + WIFI MAC + Bluetooth MAC of the mobile phone. When the intelligent router is started for the first time or restored to the default settings, it automatically generates a 16-byte random string as the router ID. It can also extract the corresponding information to form the router ID according to the rules similar to those for generating the terminal identifier on the mobile phone APP and save it in its local FLASH. The administrator password of the intelligent router is configured by the user according to the router operation requirements and can also be modified according to the user's needs.

[0112] First, the intelligent router interacts with the cloud server to determine the connection mapping relationship and the encryption key:

[0113] The intelligent router initiates a TCP connection establishment request to the cloud server, encrypts the router ID and MAC using the router public key, and sends them to the cloud server.

[0114] The cloud server decrypts using the server private key, extracts the router ID and MAC, stores them in the server Redis, and establishes the corresponding TCP connection mapping relationship. Then the cloud server generates a 16-byte random number as the subsequent AES key, encrypts the AES key itself using the server RSA private key, and then sends it to the intelligent router.

[0115] After receiving the encrypted information, the intelligent router decrypts it using the router public key, extracts the AES key and saves it. In the subsequent process, all communications between the cloud server and the intelligent router use this AES key for AES encryption and decryption.

[0116] When the user operates the mobile phone APP and selects an intelligent router from the device binding list for remote access operation, the client extracts the router ID and its corresponding electronic certificate saved locally.

[0117] Initiate a remote management call with the router ID and the electronic certificate as parameters, such as http / / : server domain name / Url of the instruction to be executed? key = electronic certificate & routerID = router ID & mac = router mac address. The parameters are submitted in the body in the POST manner and sent to the cloud server through this http request.

[0118] The cloud server obtains the router ID + mac in the request, searches in the server Redis for the specific iot device and TCP connection corresponding to this router ID. Then it obtains the electronic certificate in the request, encrypts the electronic certificate and the specific request content using AES, and sends them to the intelligent router.

[0119] After the intelligent router receives the encrypted content, it uses AES decryption to obtain the electronic certificate and the specific request content, and verifies whether the electronic certificates are consistent. If they are not consistent, it refuses to execute the operation instruction, returns a failure to the mobile APP, and prompts the user that the execution has failed and asks the user to re-execute the local binding process. If they are consistent, it executes the operation instruction and returns the execution result. The execution result is encrypted by AES and sent to the cloud server, further decrypted by AES, and then fed back to the mobile APP through an https response to prompt the user of the execution result, thus completing the remote access process.

[0120] The above embodiments are only the preferred embodiments of the present invention and do not limit the protection scope of the present invention. Any changes made using the design principles of the present invention and non-creative labor based thereon shall fall within the protection scope of the present invention.

Claims

1. A remote access method for an accountless IoT device, characterized in that, applied to an IoT device management client, configured on a mobile intelligent terminal to have a unique terminal identifier, the remote access method includes: After performing accountless binding with the IoT device, obtain the unique ID of the IoT device and the electronic certificate generated by the IoT device based on the terminal identifier, form a mapping relationship between the terminal identifier and the unique ID of the IoT device, and locally save the mapping relationship and the electronic certificate; In response to confirming the issuance of an operation instruction for the bound IoT device, obtain the unique ID of the IoT device and its electronic certificate saved locally, and jointly construct instruction information with the operation instruction; Send the instruction information to the specified IoT device through a cloud server, so that the specified IoT device authenticates the source of the instruction information and executes the operation instruction after successful authentication, wherein the specified IoT device is determined by the unique ID of the IoT device, and the source of the instruction information is determined by the electronic certificate; Receive the feedback that the specified IoT device has completed the execution of the operation instruction or the feedback that the authentication of the specified IoT device has failed.

2. The remote access method according to claim 1, characterized in that, The terminal identifier is configured as a random number of a specified length or / and the identity information code of the mobile intelligent terminal; the electronic certificate generated by the IoT device based on the terminal identifier is obtained by an irreversible algorithm from a new string composed of the terminal identifier and a random string generated by the IoT device.

3. The remote access method according to claim 1, characterized in that, The process for the specified IoT device to authenticate the source of the instruction information is: The specified IoT device compares the electronic certificate carried in the instruction information with the electronic certificate saved locally by itself. If the two are consistent, the authentication is successful and the operation instruction is executed. If the two are inconsistent, the authentication fails and the execution of the operation instruction is refused.

4. The remote access method according to claim 1, characterized in that, The feedback that the specified IoT device has completed the execution of the operation instruction and the feedback that the authentication of the specified IoT device has failed are both transmitted to the IoT device management client through the cloud server.

5. The remote access method according to any one of claims 1 to 4, characterized in that, The process for the IoT device management client to perform accountless binding with the IoT device is: In response to determining the input of the IoT device administrator password, form a string with the terminal identifier and the input IoT device administrator password, and calculate a first verification value through an irreversible algorithm; Send the terminal identifier and the first verification value to the IoT device to be bound through the local local area network for verification; Determine whether the verification is passed. If not, terminate the operation. If so, receive the electronic certificate based on the terminal identifier returned by the IoT device to be bound and the unique ID of the IoT device to be bound, and locally save the received electronic certificate; Establish a mapping relationship between the terminal identifier and the unique ID of the iot device to be bound, and save this mapping relationship locally to complete accountless binding.

6. A remote access method for an iot device without an account system, characterized in that, applied to an iot device with a unique ID, the remote access method includes: After performing accountless binding with an iot device management client configured on a mobile intelligent terminal and having a unique terminal identifier, generate an electronic voucher according to the terminal identifier, and reply the electronic voucher and the iot device unique ID to the iot device management client, so that it establishes a mapping relationship with the iot device unique ID; Receive instruction information including an operation instruction and an electronic voucher sent by the iot device management client according to the iot device unique ID through a cloud server; Extract the electronic voucher from the received instruction information, compare it with the electronic voucher saved locally, and judge whether the two are the same. If not, the authentication fails, reject the execution of the operation instruction, and feedback to the cloud server, so that the iot device management client can learn the message of authentication failure; If so, the authentication is successful, execute the operation instruction, and feedback to the cloud server after completing the operation instruction, so that the iot device management client can learn the message of completing the operation instruction.

7. The remote access method according to claim 6, characterized in that, The process of generating the electronic voucher according to the terminal identifier is: Combine the terminal identifier from the iot device management client with a random string generated by the iot device itself to form a new string, and then calculate the result through an irreversible algorithm as the electronic voucher; The terminal identifier is configured as a random number of a specified length or / and the identity information code of the mobile intelligent terminal.

8. The remote access method according to claim 6, characterized in that, The iot device establishes a connection mapping relationship based on the iot device unique ID with the cloud server through an asymmetric encryption method, and generates a symmetric encryption key, so that the iot device uses this symmetric encryption key for content encryption and decryption when communicating instruction information with the cloud server.

9. The remote access method according to any one of claims 6 to 8, characterized in that, The process of the iot device performing accountless binding with an iot device management client configured on a mobile intelligent terminal and having a unique terminal identifier is: Receive a first verification value and a terminal identifier uniquely representing the mobile intelligent terminal sent by the iot device management client through a local local area network. The first verification value is calculated by an irreversible algorithm from a string composed of the terminal identifier and the administrator password of the iot device obtained by the mobile intelligent terminal in response to an input; Extract the administrator password stored in itself, combine the received terminal identifier and the administrator password obtained by extracting and storing in itself to form a string, and calculate a second verification value through an irreversible algorithm; Determine whether the second verification value is consistent with the received first verification value. If not, terminate the operation. If so, generate an electronic certificate based on the terminal identifier and save the electronic certificate in the local non-volatile memory; Reply the electronic certificate and the unique ID of the iot device to the iot device management client, so that the iot device management client establishes a mapping relationship with the unique ID of the iot device and saves the mapping relationship and the electronic certificate locally to complete the account-free binding.

10. A remote access method for an account-free iot device Characterized in that It is applied to a cloud server that communicates with an iot device using symmetric encryption. A connection mapping relationship table based on the unique ID of the iot device is stored on the cloud server. The remote access method includes: Receive instruction information sent from an iot device management client, which includes the unique ID of the iot device, an electronic certificate, and an operation instruction; the iot device management client is configured on a mobile intelligent terminal to have a unique terminal identifier, and the electronic certificate is generated by the iot device with a unique ID based on the terminal identifier; Extract the unique ID of the iot device from the instruction information and query the target iot device corresponding to the unique ID of the iot device in the connection mapping relationship table; Encrypt the instruction information using symmetric encryption and send it to the target iot device, so that it uses the electronic certificate stored in itself for authentication and executes the operation instruction after successful authentication; Receive the feedback information after the target iot device authenticates or executes the operation instruction, and reply the feedback information to the iot device management client.

11. The remote access method according to claim 10 Characterized in that The process of the target iot device using the electronic certificate stored in itself for authentication is: The target iot device extracts the electronic certificate in the instruction information and compares it with the electronic certificate stored in itself. If the two are consistent, the authentication is successful and the operation instruction is executed. If the two are inconsistent, the authentication fails and the operation instruction is refused to be executed.

12. A computer-readable storage medium, on which a computer program is stored Characterized in that When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Cloud service accessing control method of cross-cloud application facing to cloud television terminal

    CN103179115A

  • Equipment control method and equipment

    CN110336720A