Access Authentication Method, Device, Terminal Device and Gateway Device for Internet of Things
By encrypting the authentication information by the terminal device and verifying it by the gateway device using the same key, the security risks of terminal devices when accessing the Internet of Things are solved and higher security is achieved.
Patent Information
- Application Number
- CN202211582295.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-09
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2042-12-09
AI Technical Summary
When terminal devices are connected to the Internet of Things, authentication information is easily obtained illegally, resulting in security risks.
The terminal device encrypts the authentication information according to the first key, and verifies it using the same second key through the gateway device, generating the encryption information to obtain the access authentication result.
Improve the security of terminal devices during access to the Internet of Things and avoid illegally obtaining authentication information.
Smart Images

Figure CN116032548B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and particularly relates to an access authentication method, device, terminal device, and gateway device for the Internet of Things. Background Art
[0002] The interconnection of all things is the development trend of the IT industry. Terminals commonly used in daily life, such as mobile phones, household appliances, etc., are increasingly connected to the Internet and share data. In related technologies, when a terminal accesses the Internet of Things, it sends information such as the hardware physical address or SN code of the terminal to the Internet of Things gateway, so that the Internet of Things gateway authenticates the received information and connects the terminal to the Internet of Things after successful authentication. However, during the process of the terminal accessing the Internet of Things, the information sent by the terminal to the Internet of Things gateway for authentication is public, making it possible for this information to be obtained by devices other than the terminal and the gateway, and there is a possibility of being exploited, resulting in security risks during the process of the terminal accessing the Internet of Things. Summary of the Invention
[0003] This application aims to at least solve one of the technical problems existing in the related technologies. For this reason, this application proposes an access authentication method for the Internet of Things, which can improve the security of the terminal during the process of accessing the Internet of Things.
[0004] According to an embodiment of the first aspect of this application, an access authentication method for the Internet of Things, which is applied to a terminal device, includes:
[0005] Encrypt the authentication information of the terminal device according to the obtained first key to generate encrypted information;
[0006] Send the encrypted information to the gateway device of the Internet of Things, so that the gateway device
[0007] Verify the encrypted information according to a second key that is the same as the first key in at least one security key, and obtain the access authentication result of the Internet of Things;
[0008] Wherein, the authentication information is used for access authentication of the Internet of Things.
[0009] According to an embodiment of this application, the first key is generated in the following manner:
[0010] Obtain a security code;
[0011] Generate the first key according to the security code.
[0012] According to an embodiment of this application, the obtaining of the security code includes:
[0013] Generate the security code based on at least one of the product serial number of the terminal device, the physical address of the terminal device, and the current timestamp.
[0014] According to an embodiment of the present application, generating the first secret
[0015] key includes:
[0016] 5 Obtain a target key algorithm from each key algorithm;
[0017] Encrypt the security code according to the target key algorithm to generate the first key.
[0018] According to an embodiment of the present application, the method further includes:
[0019] Send the security code to the gateway device so that the gateway device generates at least one of the security keys according to the security code.
[0020] According to an embodiment of the present application, sending the security code to the gateway device,
[0021] so that the gateway device generates at least one of the security keys according to the security code, includes:
[0022] Send the security code to the gateway device so that the gateway device encrypts the security code according to each key algorithm to generate a security key corresponding to each key algorithm one by one.
[0023] According to an embodiment of the present application, sending the security code to the gateway device so that the gateway device generates at least one of the security keys according to the security code, includes:
[0024] Send the algorithm code corresponding to the target key algorithm to the gateway device so that the gateway device determines the target key algorithm from each key algorithm according to the algorithm code;
[0025] Send the security code to the gateway device so that the gateway device encrypts the security code according to the target key algorithm to generate the security key.
[0026] According to an embodiment of the present application, it further includes:
[0027] Determine that the first prompt information is obtained from the gateway device and access the Internet of Things;
[0028] Wherein, the first prompt message is generated by the gateway device when the time interval between the timestamp in the encryption information included in the authentication result and the current time point is within a preset time interval, and the authentication information in the encryption information is paired with any preset identifier in the gateway device.
[0029] According to an embodiment of the present application, it further includes:
[0030] Determine that the second prompt message is obtained from the gateway device, and regenerate the encryption information according to the first key, so as to resend the encryption information to the gateway device for verification;
[0031] Wherein, the second prompt message is generated by the gateway device when the time interval between the timestamp in the encryption information included in the authentication result and the current time point is outside the preset time interval.
[0032] The access authentication method of the Internet of Things according to the second aspect embodiment of the present application, which is applied to a gateway device, includes:
[0033] Receive the encryption information generated according to the first key of the terminal device sent by the terminal device;
[0034] Verify the encryption information according to the second key identical to the first key in at least one security key, and obtain the access authentication result of the Internet of Things;
[0035] Wherein, the encryption information is generated after encrypting the authentication information of the terminal device with the first key;
[0036] The authentication information is used for access authentication of the Internet of Things.
[0037] According to an embodiment of the present application, it further includes:
[0038] Receive the security code sent by the terminal device for generating the first key;
[0039] Generate at least one of the security keys according to the security code.
[0040] According to an embodiment of the present application, generating at least one of the security keys according to the security code includes:
[0041] Encrypt the security code according to each key algorithm to generate a security key corresponding to each key algorithm one by one;
[0042] Wherein, the target key algorithm in each key algorithm is used to encrypt the security code in the terminal device to generate the first key.
[0043] According to an embodiment of the present application, generating at least one of the security keys according to the security encoding includes:
[0044] Determining a target key algorithm from each key algorithm according to the algorithm encoding received from the terminal device;
[0045] Encrypting the security encoding according to the target key algorithm to generate the security key;
[0046] Wherein, the target key algorithm is the key algorithm for encrypting the security encoding in the terminal device to generate the first key.
[0047] According to an embodiment of the present application, it further includes:
[0048] Determining that the authentication result includes that the time interval between the timestamp in the encrypted information and the current time point is within a preset time interval, and the authentication information in the encrypted information is paired with any preset identifier in the gateway device, and feeding back a first prompt message of successful authentication to the terminal device.
[0049] According to an embodiment of the present application, it further includes:
[0050] Determining that the time interval between the timestamp in the encrypted information and the current time point in the authentication result is outside the preset time interval, and feeding back a second prompt message of authentication timeout to the terminal device, so that the terminal device regenerates the encrypted information according to the first key for verification.
[0051] The access authentication device of the Internet of Things according to the third aspect embodiment of the present application, which is applied to a terminal device, includes:
[0052] An information encryption module, configured to encrypt the authentication information of the terminal device according to the obtained first key to generate encrypted information;
[0053] An information verification module, configured to send the encrypted information to a gateway device of the Internet of Things, so that the gateway device verifies the encrypted information according to a second key identical to the first key in at least one security key, and obtains the access authentication result of the Internet of Things;
[0054] Wherein, the authentication information is used for access authentication of the Internet of Things.
[0055] The access authentication device of the Internet of Things according to the fourth aspect embodiment of the present application, which is applied to a gateway device, includes:
[0056] An information receiving module, configured to receive encrypted information generated according to the first key of the terminal device sent by the terminal device;
[0057] An access authentication module, configured to verify the encrypted information according to a second key that is the same as the first key in at least one security key, and obtain an access authentication result of the Internet of Things;
[0058] Wherein, the encrypted information is generated by encrypting the authentication information of the terminal device with the first key;
[0059] The authentication information is used for access authentication of the Internet of Things.
[0060] A terminal device according to an embodiment of the fifth aspect of the present application includes a processor and a memory storing a computer program. When the processor executes the computer program, the access authentication method of the Internet of Things described in the above embodiment is implemented.
[0061] A gateway device according to an embodiment of the sixth aspect of the present application includes a processor and a memory storing a computer program. When the processor executes the computer program, the access authentication method of the Internet of Things described in the above embodiment is implemented.
[0062] One or more of the above technical solutions in the embodiments of the present application have at least one of the following technical effects:
[0063] After the terminal device encrypts the authentication information used for access authentication of the Internet of Things according to the first key to generate encrypted information, the gateway device receives the encrypted information, and the gateway device verifies the received encrypted information according to the second key that is the same as the first key to obtain the access authentication result of the Internet of Things. Thus, when the gateway device performs access authentication of the terminal device, it cannot directly obtain the plaintext of the authentication information, and at the same time, the gateway device can verify the encrypted authentication information of the terminal device with the same key as the terminal device, avoiding the direct acquisition of the authentication information of the terminal device by devices other than the terminal and the gateway during access verification, thereby improving the security of the terminal during the process of accessing the Internet of Things. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] In order to more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill
[0065] in the art, other drawings can also be obtained based on these drawings without creative efforts.
[0066] Figure 1 is a schematic diagram of the application environment of the access authentication method of the Internet of Things provided by the embodiment of the present application;
[0067] Figure 2It is a schematic flowchart of the access authentication method for the Internet of Things provided by an embodiment of the present application;
[0068] Figure 3 It is a schematic flowchart of the access authentication method for the Internet of Things provided by another embodiment of the present application;
[0069] Figure 4 It is for Figure 3 a flowchart for further refining the generation of the security key in the access authentication method for the Internet of Things;
[0070] Figure 5 It is for Figure 3 a flowchart for further refining the generation of the security key in the access authentication method for the Internet of Things by 5;
[0071] Figure 6 It is a schematic structural diagram of the access authentication device for the Internet of Things provided by an embodiment of the present application;
[0072] Figure 7 It is a schematic structural diagram of the access authentication device for the Internet of Things provided by another embodiment of the present application;
[0073] Figure 8 It is a schematic structural diagram of the terminal device provided by an embodiment of the present application;
[0074] Figure 9 It is a schematic structural diagram of the gateway device provided by an embodiment of the present application. Detailed implementation manners
[0075] To make the objectives, technical solutions, and advantages of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0076] Such as Figure 1As shown in the figure, the access authentication method for the Internet of Things provided by the embodiments of the present application is applied to an interaction system composed of a terminal device 110 and a gateway device 120. The terminal device 110 accesses the gateway device 120 in the interaction system. The terminal device 110 can be a desktop terminal or a mobile terminal, and the mobile terminal can be one of a mobile phone, a tablet computer, a laptop computer, a wearable device, etc. The gateway device 120, also known as an internetwork connector and protocol converter, is an intermediate device that connects an internal network of devices to other networks on the Internet and is used to implement the interconnection between the terminal device 110 and the Internet of Things. The terminal device 110 is connected to the gateway device 120. When accessing the Internet of Things is required, the terminal device 110 is used to encrypt the authentication information generated by the terminal device 110 according to the first key and generate encrypted information to be sent to the gateway device 120. The gateway device 120 stores a second key that is the same as the first key and is used to decrypt the encrypted information through the second key when receiving the encrypted information sent by the terminal device 110, obtain the authentication information in the encrypted information for verification, so as to determine whether the terminal device 110 can access the Internet of Things. Among them, if the authentication is successful, the gateway device 120 is used to report the device information of the terminal device to the Internet of Things service platform, so that the terminal device 110 can access the Internet of Things. In this way, when the gateway device performs access authentication on the terminal device, it verifies the encrypted authentication information of the terminal device and cannot directly obtain the plaintext of the authentication information, avoiding the direct acquisition of the authentication information of the terminal device by devices other than the terminal and the gateway during the access verification process, thereby improving the security of the terminal during the process of accessing the Internet of Things.
[0077] Next, several specific embodiments will be used to introduce and illustrate in detail the access authentication method for the Internet of Things provided by the embodiments of the present application.
[0078] In one embodiment, an access authentication method for the Internet of Things is provided. This method is applied to the terminal device and the gateway device as Figure 1 shown, and is used to authenticate the terminal device when the terminal device accesses the Internet of Things. As Figure 2 shown, an access authentication method for the Internet of Things provided in this embodiment includes:
[0079] Step 103, the terminal device encrypts the authentication information of the terminal device according to the obtained first key to generate encrypted information;
[0080] Step 104, the gateway device receives the encrypted information and verifies the encrypted information according to the second key that is the same as the first key in at least one security key to obtain the access authentication result of the Internet of Things;
[0081] Among them, the authentication information is used for access authentication of the Internet of Things.
[0082] After the terminal device encrypts the authentication information used for Internet of Things access authentication according to the first key to generate encrypted information, the gateway device receives the encrypted information, and the gateway device verifies the received encrypted information according to the second key that is the same as the first key to obtain the access authentication result of the Internet of Things. Thus, when the gateway device performs access authentication on the terminal device, it cannot directly obtain the plaintext of the authentication information. At the same time, the gateway device can verify the encrypted authentication information of the terminal device with the same key as the terminal device, preventing the authentication information of the terminal device from being directly obtained by devices other than the terminal and the gateway during access verification, thereby improving the security of the terminal during the process of accessing the Internet of Things.
[0083] A key is a parameter that is input in an algorithm for converting plaintext to ciphertext or vice versa. When the terminal device accesses the Internet of Things, it encrypts its authentication information according to a preset first key. Among them, the first key can be obtained by encrypting the security code of the device according to a certain key algorithm. Exemplarily, the first key is obtained by encrypting the security code of the device according to a conventional key algorithm, such as DES (Data Encryption Standard), 3DES (Triple DES), or IDEA (International Data Encryption Algorithm), etc.; or by a one-way hashing algorithm, such as MD5 (Message Digest Algorithm 5), SHA (Secure Hash Algorithm), MAC (Message Authentication Code), or CRC (Cyclic Redundancy Check), etc. to encrypt the security code of the device; or by an encoding algorithm to encrypt the security code of the device.
[0084] Among them, the security code can be a fixed code pre-written inside the terminal device during production, or the product serial number of the terminal device, or the physical address of the terminal device, such as the IP address or MAC address of the terminal device, or a security code input by an external party, such as a user, or a one-time security code generated according to the current timestamp. Or, the security code can also be generated by combining at least two of the above fixed code, product serial number, physical address, externally input security code, or one-time security code generated according to the current timestamp.
[0085] After obtaining the first key, the terminal device transmits the key file of the first key to the gateway device, so that the gateway device stores the first key as a security key. As a result, a second key identical to the first key exists in the security keys stored by the gateway device.
[0086] To avoid the first key being intercepted when transmitted to the gateway device, which may affect the security of the encrypted information in subsequent transmissions, in one embodiment, as Figure 3 shown, it further includes:
[0087] Step 100, the terminal device obtains a security code and generates the first key according to the security code;
[0088] Step 101, the terminal device sends the security code to the gateway device;
[0089] Step 102, the gateway device generates at least one of the security keys according to the security code.
[0090] In one embodiment, when the terminal device needs to access the Internet of Things, the terminal device can generate the security code according to at least one of the product serial number of the terminal device, the physical address of the terminal device, and the current timestamp. After obtaining the security code, the terminal device can encrypt the security code through a pre-set key algorithm to generate the first key. At the same time, the terminal device sends the security code to the gateway device. After receiving the security code, the gateway device encrypts the security code through the pre-set key algorithm in the gateway device to generate a security key for storage.
[0091] Among them, the key algorithms adopted by the terminal device and the gateway device can be the same key algorithm pre-set by the user, so that a second key identical to the first key can exist in the security keys stored by the gateway device, enabling the gateway device to decrypt the encrypted information generated by the first key when obtaining it subsequently.
[0092] By sending the security code of the terminal device to the gateway device, the terminal device and the gateway device respectively generate the first key and the security key according to the security code, thus eliminating the need to synchronize the first key from the terminal device to the gateway device and avoiding the interception of the first key of the terminal device during the synchronization process. And since the terminal device only synchronizes the security code to the gateway device, even if the security code is intercepted, it will be unable to decrypt the encrypted information generated by the first key subsequently because it does not know the key algorithm of the terminal device, thereby improving the security of the encrypted information in subsequent transmissions.
[0093] To further improve the security of the generated keys, in one embodiment, as Figure 4As shown, the generation of the first key and the security key includes:
[0094] Step 201, the terminal device obtains a target key algorithm from each key algorithm, and encrypts the security code according to the target key algorithm to generate the first key;
[0095] Step 202, the terminal device sends the security code to the gateway device;
[0096] Step 203, the gateway device encrypts the security code according to each key algorithm to generate security keys corresponding to each key algorithm one by one.
[0097] In an embodiment, a same key algorithm set may be preset in the terminal device and the gateway device. The key algorithm set includes multiple key algorithms, such as DES, 3DES, IDEA, MD5, SHA, MAC, and CRC, etc. When generating keys, the terminal device may randomly select a key algorithm from each key algorithm in the key algorithm set as the target key algorithm, and then encrypt the security code according to the target key algorithm to generate the first key. At the same time, the terminal device sends the security code to the gateway device. After receiving the security code, the gateway device encrypts the security code with each key algorithm in the key algorithm set respectively. After each key algorithm encrypts the security code, a security code can be generated. For example, if the key algorithms include DES, 3DES, and IDEA, etc., and the security code is A, then in the gateway device, encrypt the security code A according to DES to generate the security key A1; encrypt the security code A according to 3DES to generate the security key A2; encrypt the security code A according to IDEA to generate the security key A3. Thus, after all key algorithms in the key algorithm set encrypt the security code respectively, the security keys corresponding to each key algorithm one by one can be obtained. In this way, no matter which key algorithm the terminal device selects to generate the first key subsequently, among the security keys stored in the gateway device, there must be a second key that is the same as the first key, so that the gateway device can decrypt the encrypted information generated by the first key. And since the target key algorithm is one of the key algorithms, the first key formed by it is more uncertain, thus improving the security of the generated first key.
[0098] After the terminal device obtains the target key algorithm from each key algorithm, encrypt the security code according to the target key algorithm to generate the first key, and send the security code to the gateway device. The gateway device encrypts the security code according to each key algorithm to generate security keys corresponding one by one to each key algorithm, so that the first key formed by the terminal device is more uncertain. And no matter which key algorithm the terminal device selects to generate the first key, among the security keys stored in the gateway device, there must be a second key that is the same as the first key. Furthermore, while improving the security of the generated first key, it is ensured that the first key can be decrypted by the gateway device.
[0099] Considering that if the gateway device stores multiple security keys, there may be a situation of wasted storage space. And usually there are multiple terminal devices connected to the gateway device, which leads to a great waste of storage space when each terminal device has to generate multiple security keys correspondingly. For this reason, in an embodiment, as Figure 5 shown, the generation of the first key and the security key includes:
[0100] Step 301, the terminal device obtains the target key algorithm from each key algorithm;
[0101] Step 302, the terminal device sends the algorithm code corresponding to the target key algorithm to the gateway device;
[0102] Step 303, the gateway device determines the target key algorithm from each of the key algorithms according to the algorithm code;
[0103] Step 304, the terminal device encrypts the security code according to the target key algorithm to generate the first key;
[0104] Step 305, the terminal device sends the security code to the gateway device;
[0105] Step 306, the gateway device encrypts the security code according to the target key algorithm to generate the security key.
[0106] In an embodiment, a same key algorithm set can be preset in the terminal device and the gateway device. The key algorithm set includes multiple key algorithms, such as DES, 3DES, IDEA, MD5, SHA, MAC, and CRC, etc. Each key algorithm corresponds to a unique algorithm code. For example, the algorithm code corresponding to DES is 1, and the algorithm code corresponding to 3DES is 2, etc.
[0107] When generating a key, the terminal device can randomly select a key algorithm from each key algorithm in the key algorithm set as the target key algorithm, and then encrypt the security code according to the target key algorithm to generate a first key. At the same time, the terminal device sends the algorithm code and the security code of the target key algorithm to the gateway device, and the gateway device can obtain the target key algorithm from each key algorithm in the key algorithm set according to the algorithm code to encrypt the security code to generate a security key, so that the key algorithm used by the gateway device is the same as the key algorithm used by the terminal device. In this way, the security key generated by the gateway device at this time is the same second key as the first key.
[0108] By having the terminal device send the algorithm code corresponding to the selected target key algorithm to the gateway device, the gateway device can determine the target key algorithm according to the algorithm code, so that the terminal device and the gateway device can generate the first key and the security key according to the same target key algorithm. Furthermore, while ensuring that the first key can be decrypted by the gateway device, there is no need for the gateway device to generate security keys corresponding to each key algorithm one by one, reducing the storage pressure of the gateway device and the waste of the storage space of the gateway device.
[0109] In addition, since the terminal device only sends one algorithm code to the gateway device, even if the algorithm code is intercepted, it is impossible to know the encryption algorithm used by the terminal device, thus improving the security of the generated first key.
[0110] In addition to having the terminal device randomly select a key algorithm from each key algorithm in the key algorithm set as the target key algorithm and send the algorithm code of the target key algorithm to the gateway device, so that the gateway device selects the same target key algorithm as the terminal device according to the algorithm code, in an embodiment, it can also be that the gateway device randomly selects a key algorithm from each key algorithm in the key algorithm set as the target key algorithm and sends the algorithm code of the target key algorithm to the terminal device, so that the terminal device selects the same target key algorithm as the gateway device according to the algorithm code.
[0111] In an embodiment, after the terminal device generates the first key, it encrypts the authentication information used for Internet of Things access authentication to generate encrypted information and sends the encrypted information to the gateway device. Among them, the authentication information may include a message authentication code and the original message content. The message authentication code can use the HMAC algorithm, and the original message content may include the unique identifier of the terminal device such as the SN code of the device and the timestamp.
[0112] After receiving the encrypted information, the gateway device can parse the encrypted information by using the second key that is the same as the first key among at least one stored security key to verify the encrypted information. To ensure the accuracy of verifying the encrypted information, in one embodiment, after obtaining the encrypted information, the gateway device can decrypt the encrypted information by using the second key, and then detect whether the time interval between the timestamp in the encrypted information and the current time point is within a preset time interval. If the time interval between the timestamp and the previous time point is within the preset time interval, it is detected whether the unique identifier in the encrypted information is the same as any preset identifier in the gateway device. Among them, multiple preset identifiers can be pre-stored in the gateway device, and the preset identifier is an identifier uniquely corresponding to a certain terminal device generated when the terminal device performs Internet of Things access registration. If there is a preset identifier in the gateway device that is the same as the unique identifier in the encrypted information, it indicates that the terminal device is a registered device. At this time, it is determined that the encrypted information authentication is successful. At this time, a first prompt message for prompting the success of the encrypted information authentication can be generated and sent to the terminal device, and the device information of the terminal device, that is, the unique identifier in the encrypted information, is reported to the Internet of Things service platform to enable the terminal device to access the Internet of Things.
[0113] If the gateway device detects that the time interval between the timestamp in the authentication information and the current time point is outside the preset time interval, it indicates that the reception of the encrypted information has timed out. At this time, the gateway device generates a second prompt message for prompting the timeout of the encrypted information sending and sends the second prompt message to the terminal device. When the terminal device receives the second prompt message, it regenerates the encrypted information according to the first key and sends the newly generated encrypted information to the gateway device for verification again.
[0114] If the time interval between the timestamp and the previous time point is within the preset time interval, but it is detected that the unique identifier in the encrypted information is not the same as each preset identifier in the gateway device, it indicates that the terminal device has not performed network access registration. At this time, a third prompt message for prompting the failure of the terminal device authentication is generated and sent to the terminal device.
[0115] The access authentication device of the Internet of Things provided by the present application is described below. The access authentication device of the Internet of Things described below can be correspondingly referred to the access authentication method of the Internet of Things described above.
[0116] In one embodiment, as Figure 6 shown, an access authentication device of the Internet of Things is provided, which is applied to a terminal device and includes:
[0117] An information encryption module 210, configured to encrypt the authentication information of the terminal device according to the obtained first key to generate encrypted information;
[0118] An information verification module 220, configured to send the encrypted information to a gateway device of the Internet of Things, so that the gateway device verifies the encrypted information according to a second key in at least one security key that is the same as the first key, and obtains an access authentication result of the Internet of Things;
[0119] wherein the authentication information is used for access authentication of the Internet of Things.
[0120]
[0121] In one embodiment, the information encryption module 210 is further configured to:
[0122] Obtain a security code;
[0123] Generate the first key according to the security code.
[0124]
[0125] In one embodiment, the information encryption module 210 is specifically configured to:
[0126] Generate the security code according to at least one of a product serial number of the terminal device, a physical address of the terminal device, and a current timestamp.
[0127] In one embodiment, the information encryption module 210 is specifically configured to: Obtain a target key algorithm from various key algorithms;
[0128] Encrypt the security code according to the target key algorithm to generate the first key.
[0129] In one embodiment, the information encryption module 210 is further configured to:
[0130] Send the security code to the gateway device, so that the gateway device generates at least one of the security keys according to the security code.
[0131] In one embodiment, the information encryption module 210 is specifically configured to:
[0132] Send the security code to the gateway device, so that the gateway device encrypts the security code according to each of the key algorithms to generate security keys corresponding to each of the key algorithms one by one.
[0133] In one embodiment, the information encryption module 210 is specifically configured to:
[0134] Send an algorithm code corresponding to the target key algorithm to the gateway device, so that the gateway device determines the target key algorithm from each of the key algorithms according to the algorithm code;
[0135] Send the security code to the gateway device so that the gateway device encrypts the security code according to the target key algorithm to generate the security key.
[0136] In one embodiment, the information verification module 220 is further configured to:
[0137] Determine that a first prompt message is obtained from the gateway device and access the Internet of Things;
[0138] Wherein, the first prompt message is generated by the gateway device when the time interval between the timestamp in the encrypted information and the current time point in the authentication result is within a preset time interval, and the authentication information in the encrypted information is paired with any preset identifier in the gateway device.
[0139] In one embodiment, the information verification module 220 is further configured to:
[0140] Determine that a second prompt message is obtained from the gateway device, and regenerate the encrypted information according to the first key, so as to resend the encrypted information to the gateway device for verification;
[0141] Wherein, the second prompt message is generated by the gateway device when the time interval between the timestamp in the encrypted information and the current time point in the authentication result is outside the preset time interval.
[0142] In one embodiment, as Figure 7 shown, an access authentication device for the Internet of Things is provided, which is applied to a gateway device and includes:
[0143] An information receiving module 310, configured to receive the encrypted information generated according to the first key of the terminal device sent by the terminal device;
[0144] An access authentication module 320, configured to verify the encrypted information according to a second key identical to the first key in at least one security key, and obtain the access authentication result of the Internet of Things;
[0145] Wherein, the encrypted information is generated by encrypting the authentication information of the terminal device with the first key;
[0146] The authentication information is used for access authentication of the Internet of Things.
[0147] In one embodiment, the information receiving module 310 is further configured to:
[0148] Receive the security code for generating the first key sent by the terminal device;
[0149] Generate at least one of the security keys according to the security code.
[0150] In one embodiment, the information receiving module 310 is specifically configured to:
[0151] Encrypt the security encoding according to each key algorithm to generate security keys corresponding one by one to each of the key algorithms;
[0152] Among them, the target key algorithm in each of the key algorithms is used to encrypt the security encoding in the terminal device to generate the first key.
[0153] In one embodiment, the information receiving module 310 is specifically configured to:
[0154] Determine the target key algorithm from each key algorithm according to the algorithm encoding received from the terminal device;
[0155] Encrypt the security encoding according to the target key algorithm to generate the security key;
[0156] Among them, the target key algorithm is the key algorithm for encrypting the security encoding in the terminal device to generate the first key.
[0157] In one embodiment, the access authentication module 320 is further configured to:
[0158] Determine that the authentication result includes that the time interval between the timestamp in the encrypted information and the current time point is within a preset time interval, and the authentication information in the encrypted information is paired with any preset identifier in the gateway device, and feedback a first prompt message of successful authentication to the terminal device.
[0159] In one embodiment, the access authentication module 320 is further configured to:
[0160] Determine that the time interval between the timestamp in the encrypted information and the current time point in the authentication result is outside the preset time interval, and feedback a second prompt message of authentication timeout to the terminal device, so that the terminal device regenerates the encrypted information according to the first key for verification.
[0161] Figure 8 Illustrates a schematic diagram of the physical structure of a terminal device, as Figure 8 shown, the electronic device may include: a processor 810, a communication interface 820, a memory 830, and a communication bus 840. Among them, the processor 810, the communication interface 820, and the memory 830 complete mutual communication through the communication bus 840. The processor 810 can call the computer program in the memory 830 to execute the access authentication method of the Internet of Things, for example, including:
[0162] Encrypt the authentication information of the terminal device according to the obtained first key to generate encrypted information;
[0163] Send the encrypted information to the gateway device of the Internet of Things, so that the gateway device verifies the encrypted information according to the second key that is the same as the first key in at least one security key, and obtains the access authentication result of the Internet of Things;
[0164] Wherein, the authentication information is used for access authentication of the Internet of Things.
[0165] Figure 9 Illustrates a schematic diagram of the physical structure of a gateway device, as Figure 9 shown. The electronic device may include: a processor 910, a communication interface 920, a memory 930, and a communication bus 940. Among them, the processor 910, the communication interface 920, and the memory 930 communicate with each other through the communication bus 940. The processor 910 can call the computer program in the memory 930 to execute the access authentication method of the Internet of Things, for example, including:
[0166] Receive the encrypted information sent by the terminal device and generated according to the first key of the terminal device;
[0167] Verify the encrypted information according to the second key that is the same as the first key in at least one security key, and obtain the access authentication result of the Internet of Things;
[0168] Wherein, the encrypted information is generated by encrypting the authentication information of the terminal device with the first key;
[0169] The authentication information is used for access authentication of the Internet of Things.
[0170] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solution essentially or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0171] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than limiting them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. An access authentication method for the Internet of Things, characterized in that, Applied to a terminal device, including: Encrypt the authentication information of the terminal device according to the obtained first key to generate encrypted information; Send the encrypted information to a gateway device of the Internet of Things, so that the gateway device verifies the encrypted information according to a second key that is the same as the first key in at least one security key, and obtains the access authentication result of the Internet of Things; Wherein, the authentication information is used for access authentication of the Internet of Things; The first key is generated in the following manner: Encrypt the obtained security code according to a target key algorithm in each key algorithm to generate the first key; The security key is generated in the following manner: Send the algorithm code corresponding to the target key algorithm to the gateway device, so that the gateway device determines the target key algorithm from each key algorithm according to the algorithm code; send the security code to the gateway device, so that the gateway device encrypts the security code according to the target key algorithm to generate the security key.
2. The access authentication method for the Internet of Things according to claim 1, characterized in that, It further includes: Generate the security code according to at least one of the product serial number of the terminal device, the physical address of the terminal device, and the current timestamp.
3. The access authentication method for the Internet of Things according to claim 1, characterized in that, It further includes: Determine that a first prompt message is obtained from the gateway device and access the Internet of Things; Wherein, the first prompt message is generated by the gateway device when the time interval between the timestamp in the encrypted information and the current time point in the authentication result is within a preset time interval, and the authentication information in the encrypted information is paired with any preset identifier in the gateway device.
4. The access authentication method for the Internet of Things according to claim 1 or 3, characterized in that It further includes: Determine that a second prompt message is obtained from the gateway device, regenerate the encrypted information according to the first key, and resend the encrypted information to the gateway device for verification; Wherein, the second prompt message is generated by the gateway device when the time interval between the timestamp in the encrypted information and the current time point in the authentication result is outside the preset time interval.
5. An access authentication method for the Internet of Things, characterized in that, Applied to a gateway device, including: Receive the encrypted information generated according to the first key of the terminal device sent by the terminal device; Verify the encrypted information according to a second key that is the same as the first key in at least one security key, and obtain the access authentication result of the Internet of Things; Wherein, the encrypted information is generated by encrypting the authentication information of the terminal device with the first key; The authentication information is used for access authentication of the Internet of Things; The security key is generated in the following manner: Receive the security code for generating the first key sent by the terminal device; determine the target key algorithm from each key algorithm according to the algorithm code received from the terminal device; encrypt the security code according to the target key algorithm to generate the security key; wherein, the target key algorithm is the key algorithm in the terminal device that encrypts the security code to generate the first key.
6. The access authentication method for the Internet of Things according to claim 5, characterized in that, It further includes: Determine that the authentication result includes that the time interval between the timestamp in the encrypted information and the current time point is within a preset time interval, and the authentication information in the encrypted information is paired with any preset identifier in the gateway device, and feedback a first prompt message of successful authentication to the terminal device.
7. The access authentication method for the Internet of Things according to claim 5, characterized in that, It further includes: Determine that the authentication result includes that the time interval between the timestamp in the encrypted information and the current time point is outside the preset time interval, and feedback a second prompt message of authentication timeout to the terminal device, so that the terminal device regenerates the encrypted information according to the first key for verification.
8. An access authentication device for the Internet of Things, characterized in that, Applied to a terminal device, it includes: An information encryption module, configured to encrypt the authentication information of the terminal device according to the obtained first key to generate encrypted information; An information verification module, configured to send the encrypted information to a gateway device of the Internet of Things, so that the gateway device verifies the encrypted information according to a second key identical to the first key in at least one security key, and obtains an access authentication result of the Internet of Things; Wherein, the authentication information is used for access authentication of the Internet of Things; The first key is generated in the following manner: Encrypt the obtained security code according to a target key algorithm in each key algorithm to generate the first key; The security key is generated in the following manner: Send the algorithm code corresponding to the target key algorithm to the gateway device, so that the gateway device determines the target key algorithm from each key algorithm according to the algorithm code; send the security code to the gateway device, so that the gateway device encrypts the security code according to the target key algorithm to generate the security key; or, send the security code to the gateway device, so that the gateway device encrypts the security code according to each key algorithm to generate security keys corresponding to each key algorithm one by one.
9. An access authentication device for the Internet of Things, characterized in that, Applied to a gateway device, it includes: An information receiving module, configured to receive the encrypted information sent by the terminal device and generated according to the first key of the terminal device; An access authentication module, configured to verify the encrypted information according to a second key identical to the first key in at least one security key, and obtain an access authentication result of the Internet of Things; Wherein, the encrypted information is generated by encrypting the authentication information of the terminal device with the first key; The authentication information is used for access authentication of the Internet of Things; The security key is generated in the following manner: Receive the security code sent by the terminal device for generating the first key; determine the target key algorithm from each key algorithm according to the algorithm code received from the terminal device; encrypt the security code according to the target key algorithm to generate the security key; wherein, the target key algorithm is the key algorithm in the terminal device for encrypting the security code to generate the first key; or, Encrypt the security code according to each key algorithm to generate a security key corresponding to each key algorithm one by one; wherein, the target key algorithm in each key algorithm is used to encrypt the security code in the terminal device to generate the first key.
10. A terminal device, comprising a processor and a memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the access authentication method for the Internet of Things according to any one of claims 1 to 4.
11. A gateway device, comprising a processor and a memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the access authentication method for the Internet of Things according to any one of claims 5 to 7.
Citation Information
Patent Citations
An electric power Internet of Things terminal identity authentication method based on a block chain
CN109787987A