Device connection method, apparatus, and storage medium

By storing device information, token information, and terminal device authentication information in the module device, and adopting a trusted module approach, the problem of insufficient security in the connection between low-speed, low-power terminal devices and the device management platform is solved, thereby improving security and user experience.

CN116193439BActive Publication Date: 2026-02-03CHINA UNITED NETWORK COMM GRP CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211685704.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-27
Publication Date
2026-02-03
Estimated Expiration
2042-12-27

AI Technical Summary

Technical Problem

Due to limited system resources, low-speed, low-power terminal devices have low connection security with the device management platform. Existing technologies also involve a lot of identity information and complex operations for terminal devices, resulting in insufficient connection security.

Method used

By enabling information exchange between the module device and the module account on the device management platform, the device information, token information, and authentication information of the terminal device are all stored in the module device. The trusted module provides a trusted storage area and a secure operating environment between the terminal device and the device management platform.

Benefits of technology

It improves the security of the connection between terminal devices and the device management platform, simplifies the steps for terminal devices to access the device management platform, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116193439B_ABST
    Figure CN116193439B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of communication, in particular to a device connection method and device and a storage medium, which can guarantee the security of connection between a terminal and a device management platform. The method comprises the following steps: determining device information and token information of a module device; accessing a module account of the device management platform according to the device information and the token information of the module device; the module account is used for managing the module accessing the device management platform; reporting a terminal device product number to the module account of the device management platform according to the device information of the module device; receiving terminal device authentication information fed back by a terminal account; the terminal account is used for managing a plurality of terminal devices accessing the device management platform; the terminal device authentication information is terminal device authentication information determined by the terminal account and associated with the terminal device product number; and initiating connection authentication to the device management platform according to the terminal device authentication information. The application is used in a device connection process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a device connection method, apparatus, and storage medium. Background Technology

[0002] In related technologies, terminals typically connect to device management platforms via communication modules. During this connection process, the terminal usually establishes a connection with the device management platform using its identity and key information. However, for some low-speed, low-power terminals, limited system resources often result in inadequate security mechanisms, leading to lower security in the connection between the terminal and the device management platform. Therefore, ensuring the security of the connection between the terminal and the device management platform is a pressing issue that needs to be addressed. Summary of the Invention

[0003] This application provides a device connection method, apparatus, and storage medium that can ensure the security of the connection between the terminal and the device management platform.

[0004] To achieve the above objectives, this application adopts the following technical solution:

[0005] In a first aspect, this application provides a device connection method, which includes: determining device information and token information of a module device; accessing a module account of a device management platform based on the device information and token information of the module device; the module account being used to manage modules accessing the device management platform; reporting the terminal device product number to the module account of the device management platform based on the device information of the module device; receiving terminal device authentication information fed back by the terminal account; the terminal account being used to manage multiple terminal devices accessing the device management platform; the terminal device authentication information being terminal device authentication information determined by the terminal account and associated with the terminal device product number; and initiating connection authentication to the device management platform based on the terminal device authentication information.

[0006] In conjunction with the first aspect, in one possible implementation, determining the device information and token information of the module device includes: receiving the terminal device product number sent by the terminal device; detecting whether the module device stores terminal device authentication information based on the terminal device product number; if the module device stores terminal device authentication information, initiating connection authentication to the device management platform based on the terminal device authentication information; if the module device does not store terminal device authentication information, detecting whether the module device stores device information and token information; and if the module device stores device information and token information, determining the device information and token information of the module device.

[0007] In conjunction with the first aspect, in one possible implementation, the method further includes: sending authentication failure information to the terminal device when the module device does not store the module device's device information and token information.

[0008] In conjunction with the first aspect, in one possible implementation, the terminal device authentication information includes: the terminal device product number, the terminal device number associated with the terminal device product number, and the terminal device key.

[0009] In conjunction with the first aspect, in one possible implementation, before determining the device information and token information of the module device, the process includes: detecting whether the module device stores token information; if the module device does not store token information, sending a registration request to the device management platform based on the module device's registration information; the module device's registration information includes at least one of the following: the module device's product number and the module device's product key; receiving token information fed back by the module account of the device management platform; the token information is the token information associated with the registration information fed back by the module account; and establishing a connection with the device management platform based on the module device's product number, the module device's device number, and the token information.

[0010] Secondly, this application provides a device connection apparatus, comprising: a processing unit and a communication unit; the processing unit is configured to determine device information and token information of a module device; the processing unit is further configured to access a module account of a device management platform based on the device information and token information of the module device; the module account is used to manage modules accessing the device management platform; the processing unit is further configured to report the terminal device product number to the module account of the device management platform based on the device information of the module device; the communication unit is configured to receive terminal device authentication information fed back by the terminal account; the terminal account is used to manage multiple terminal devices accessing the device management platform; the terminal device authentication information is terminal device authentication information determined by the terminal account and associated with the terminal device product number; the processing unit is further configured to initiate connection authentication to the device management platform based on the terminal device authentication information.

[0011] In conjunction with the second aspect, in one possible implementation, the communication unit is further configured to receive the terminal device product number sent by the terminal device; the processing unit is specifically configured to detect whether the module device stores terminal device authentication information based on the terminal device product number; if the module device stores terminal device authentication information, initiate connection authentication to the device management platform based on the terminal device authentication information; if the module device does not store terminal device authentication information, detect whether the module device stores device information and token information; if the module device stores device information and token information, determine the device information and token information of the module device.

[0012] In conjunction with the second aspect, in one possible implementation, if the module device does not store the module device's device information and token information, the processing unit is also used to send authentication failure information to the terminal device.

[0013] In conjunction with the second aspect, in one possible implementation, the terminal device authentication information includes: the terminal device product number, the terminal device number associated with the terminal device product number, and the terminal device key.

[0014] In conjunction with the second aspect, in one possible implementation, the processing unit is further configured to detect whether the module device stores token information; if the module device does not store token information, the processing unit is further configured to send a registration request to the device management platform based on the module device's registration information; the module device's registration information includes at least one of the following: the module device's product number and the module device's product key; the communication unit is further configured to receive token information fed back by the module account of the device management platform; the token information is token information associated with the registration information fed back by the module account; the processing unit is further configured to establish a connection with the device management platform based on the module device's product number, the module device's device number, and the token information.

[0015] Thirdly, this application provides a device connection apparatus, which includes: a processor and a communication interface; the communication interface and the processor are coupled, and the processor is used to run computer programs or instructions to implement the device connection method as described in the first aspect and any possible implementation of the first aspect.

[0016] Fourthly, this application provides a computer-readable storage medium storing instructions that, when executed on a terminal, cause the terminal to perform the device connection method as described in the first aspect and any possible implementation thereof.

[0017] In this application, the names of the aforementioned device connection devices do not limit the devices or functional modules themselves. In actual implementation, these devices or functional modules may appear under other names. As long as the functions of each device or functional module are similar to those in this application, they fall within the scope of the claims of this application and their equivalents.

[0018] These or other aspects of this application will become more readily apparent in the following description.

[0019] Based on the above technical solutions, the device connection method provided in this application involves the device connection device first determining the device information and token information of the module device, and then accessing the module account of the device management platform based on the device information and token information. After accessing the module account of the device management platform, the device connection device reports the terminal device product number to the module account of the device management platform using the device information of the module device. The device management platform then feeds back terminal device authentication information associated with the terminal device product number to the device connection device. Finally, the device connection device receives the terminal device authentication information and initiates connection authentication with the device management platform based on the terminal device authentication information. This application provides a module device that uses a trusted module, thereby providing a trusted storage area and a secure operating environment for the connection between the terminal device and the device management platform. This application ensures the security of all information by allowing information exchange between the module device and the module account of the device management platform, storing the device information, token information, and terminal device authentication information of the module device in the module device. Attached Figure Description

[0020] Figure 1 A schematic diagram of a device connection apparatus provided in this application;

[0021] Figure 2 An architecture diagram of a TCP module terminal connection platform provided in this application;

[0022] Figure 3 An architecture diagram of an SDK embedding module connection platform provided in this application;

[0023] Figure 4 A flowchart illustrating a single-device-one-key terminal access method provided in this application;

[0024] Figure 5 A flowchart illustrating a single-type, single-key terminal access method provided in this application;

[0025] Figure 6 A flowchart illustrating another type of single-key terminal access provided in this application;

[0026] Figure 7 A flowchart of a device connection method provided in this application;

[0027] Figure 8 A flowchart of another device connection method provided in this application;

[0028] Figure 9 A flowchart of another device connection method provided in this application;

[0029] Figure 10A schematic diagram of a device connection apparatus provided in this application;

[0030] Figure 11 This is a schematic diagram of a device connection device provided in this application. Detailed Implementation

[0031] The device connection method and apparatus provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0032] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.

[0033] The terms "first" and "second," etc., used in the specification and drawings of this application are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.

[0034] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.

[0035] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0036] Figure 1 This is a schematic diagram of the structure of a device connection device provided in an embodiment of this application, as shown below. Figure 1 As shown, the device connection device 100 includes at least one processor 101, a communication line 102, and at least one communication interface 104, and may also include a memory 103. The processor 101, memory 103, and communication interface 104 can be connected to each other via the communication line 102.

[0037] The processor 101 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs).

[0038] Communication line 102 may include a path for transmitting information between the aforementioned components.

[0039] The communication interface 104 is used to communicate with other devices or communication networks. It can use any transceiver-like device, such as Ethernet, radio access network (RAN), wireless local area network (WLAN), etc.

[0040] The memory 103 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of including or storing desired program code having the form of instructions or data structures and accessible by a computer, but not limited thereto.

[0041] In one possible design, the memory 103 can exist independently of the processor 101, meaning the memory 103 can be an external memory of the processor 101. In this case, the memory 103 can be connected to the processor 101 via the communication line 102 to store execution instructions or application code, and its execution is controlled by the processor 101 to implement the network quality determination method provided in the following embodiments of this application. In another possible design, the memory 103 can also be integrated with the processor 101, meaning the memory 103 can be an internal memory of the processor 101. For example, the memory 103 can be a cache, which can be used to temporarily store some data and instruction information.

[0042] As one possible implementation, processor 101 may include one or more CPUs, for example Figure 1 CPU0 and CPU1 in the example. As another possible implementation, the device connectivity may include multiple processors, such as... Figure 1 The processors 101 and 107 are included. Alternatively, the device connection apparatus may also include an output device 105 and an input device 106.

[0043] Through the above description of the implementation methods, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the network node can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, modules, and network nodes described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0044] The connectivity of IoT terminal devices in related technologies involves complex and diverse scenarios, and the configuration and communication methods of terminal devices vary depending on the specific needs of each scenario. Currently, a large number of IoT terminals use microcontrollers (MCUs) with real-time operating systems for control operations, such as home appliances, automation equipment, practical control devices, and data acquisition devices; they also use AT commands to connect the MCU and the communication module.

[0045] Currently, terminal devices typically connect to the device management platform via communication modules. For example... Figure 2 The diagram shows the architecture of a TCP module terminal connection platform. The communication module can be a Transmission Control Protocol (TCP) module; for example... Figure 3The diagram shows the architecture of the SDK implantation module connecting the platform. The communication module can also be a software development kit (SDK) module. The SDK module includes integrated common IoT protocols such as MQTT, COAP, and LWM2M.

[0046] Regardless of whether a TCP module or an SDK module is used, the product and terminal device need to be registered on the device management platform, and the product type and device type of the terminal device need to be preset in advance. Then, the product identity information (Product Key, Product Secret; PK, PS) and device identity information (Device Key, Device Secret; DK, DS) on the device management platform are imported into the terminal device. The terminal device stores the above information and sends a connection request to the device management platform according to the product identity information and device identity information. The device management platform authenticates the product identity information and device identity information. If the authentication is successful, the connection is established.

[0047] In existing technologies, there are three ways to connect terminal devices and device management platforms:

[0048] 1. For example Figure 4 The diagram shows a flowchart for one-device-one-secret terminal access. For the one-device-one-secret access method, the connection process includes the following steps:

[0049] S401, The device management platform creates terminal products under the terminal account.

[0050] S402. The device management platform adds terminal devices under the corresponding terminal products.

[0051] S403. Each terminal device burns its own device identity information (Product Key, Device Key, Device Secret), which can also be understood as importing the terminal device's device identity information.

[0052] S404. The terminal device sends a connection request to the device management platform using its device identity information.

[0053] S405 The device management platform sends the authentication result back to the terminal device to complete the connection.

[0054] 2. For example Figure 5 The diagram shows a flowchart for accessing a Type-1, Type-2, Type-3 terminal. For the Type-1, Type-2, Type-3 pre-registered access method, the connection process includes the following steps:

[0055] S501, the device management platform creates terminal products under the terminal account.

[0056] S502, The device management platform adds terminal devices under the corresponding terminal products.

[0057] S503. Each terminal device burns its own device identity information (Product Key, Product Secret), which can also be understood as importing the device identity information of the terminal device.

[0058] S504. The terminal checks whether it has stored its own device secret (DS).

[0059] S505. If the terminal's device key is not stored, the terminal initiates a dynamic registration request to the device management platform based on the device identity information (Product Key, Product Secret).

[0060] S506. After the registration request is successful, the device management platform will send the device secret (DS) back to the terminal device.

[0061] S507. The terminal device stores the device key.

[0062] S508. The terminal device sends a connection request to the device management platform using its device identity information and device key information.

[0063] S509: The device management platform sends the authentication result back to the terminal device, completing the connection.

[0064] 3. For example Figure 6 The diagram shows a flowchart for another type of one-key terminal access method. For the one-key, pre-registration-free access method, the connection process includes the following steps:

[0065] S601, The device management platform creates terminal products under the terminal account.

[0066] S602. Each terminal device burns its own device identity information (Product Key, Product Secret), which can also be understood as importing the device identity information of the terminal device.

[0067] S603. The terminal detects whether it has stored its own token information.

[0068] S604. If the terminal's token information is not stored, the terminal initiates a dynamic registration request to the terminal account of the device management platform based on the device identity information (Product Key, Product Secret).

[0069] S605, the terminal account of the device management platform automatically adds terminal devices.

[0070] S606. After the registration request is successful, the device management platform sends token information to the terminal device.

[0071] S607. The terminal device stores the token information.

[0072] S608. The terminal device sends a connection request to the device management platform using its device identity information and token information.

[0073] S609: The device management platform sends the authentication result back to the terminal device, completing the connection.

[0074] All three connection methods have the following drawbacks: During the connection process, the terminal usually establishes a connection with the device management platform through the device's identity information and key information. However, for some low-speed and low-power terminals, due to limited system resources, the terminal's security mechanism is often not perfect, resulting in low security of the connection between the terminal and the device management platform.

[0075] In addition, the terminal devices contain a lot of identity information, and the operation on the terminal device side is too complicated.

[0076] To address the problems in the prior art, embodiments of this application provide a method such as... Figure 7 The device connection method shown in this application includes: first, the device connection device determines the device information and token information of the module device; then, based on the device information and token information, it accesses the module account of the device management platform; after accessing the module account, the device connection device reports the terminal device product number to the module account of the device management platform using the device information of the module device; then, the device management platform feeds back terminal device authentication information associated with the terminal device product number to the device connection device; finally, the device connection device receives the terminal device authentication information and initiates connection authentication with the device management platform based on the terminal device authentication information. This device connection method proposes a module device that, through information exchange between the module device and the module account of the device management platform, stores the device information, token information, and terminal device authentication information of the module device in the module device, ensuring the security of all information.

[0077] like Figure 7 The diagram shown is a flowchart of a device connection method provided in an embodiment of this application. The device connection method provided in this application can be applied to, for example... Figure 1 In the device connection device shown, the device connection method provided in this application embodiment can be implemented through the following steps.

[0078] Step 701: The device connection device determines the device information and token information of the module device.

[0079] In one possible implementation, the device connection device can be understood as a module device on the terminal device; the device information of the module device includes at least one of the following: the product number of the module device and the device number of the module device.

[0080] Optionally, the product number of the module device can be represented by the Module Product Key or M-PK; the device number of the module device can be represented by the Module Device Key or M-DK; and the token information of the module device can be represented by the Moduletoken.

[0081] It is understandable that the product number of a module device refers to the product number of a certain type of module device; the device number of a module device refers to the number of a specific module device within that type of module device.

[0082] Step 702: The device connection device connects to the module account of the device management platform based on the device information and token information of the module device.

[0083] The module account is used to manage the modules accessing the device management platform.

[0084] As one possible implementation, the above step 702 can be implemented as follows: the device connection device sends the device information and token information of the module device to the module account of the device management platform. The module account of the device management platform receives the device information and token information of the module device and compares it with the device information and token information of the module device stored in its own database to determine whether they are consistent. If they are consistent, the module account of the device management platform sends the access success information back to the device connection device.

[0085] Step 703: The device connection device reports the terminal device product number to the module account of the device management platform based on the device information of the module device.

[0086] In one possible implementation, the device connection device reports the terminal device product number to the module account of the device management platform, and then the module account of the device management platform sends it to the terminal account of the device management platform. After receiving the terminal device product number, the terminal account of the device management platform automatically creates a terminal device number and a terminal device key associated with the terminal device product number, and adds the terminal device number and the terminal device key under the product of the terminal device product number. Finally, the terminal account of the device management platform feeds back the terminal device product number, the terminal device key and the terminal device key to the device connection device.

[0087] In one example, the device connection device publishes a message via Message Queuing Telemetry Transport (MQTT) with the topic "$sys / M-PK / M-DK / module / autoregist" and the payload being...

[0088]

[0089] "This allows the module device's terminal device product number to be reported to the module account on the device management platform using the module device's device information."

[0090] Optionally, the terminal device product number can be represented by Product Key or PK; the terminal device number can be represented by Device Key or DK; and the terminal device secret can be represented by Device Secret or DS.

[0091] Step 704: The device connection device receives the terminal device authentication information fed back by the terminal account.

[0092] The terminal account is used to manage multiple terminal devices accessing the device management platform; the terminal device authentication information is the terminal device authentication information associated with the terminal device product number determined by the terminal account.

[0093] In one possible implementation, the terminal device authentication information includes: the terminal device product number, the terminal device number associated with the terminal device product number, and the terminal device key.

[0094] Referring to the example in step 703 above, after receiving the terminal device product number, the terminal device number associated with the terminal device product number, and the terminal device key, the device connection device performs a storage operation.

[0095] Step 705: The device connection device initiates connection authentication to the device management platform based on the terminal device authentication information.

[0096] As one possible implementation, the device connection device sends the terminal device authentication information to the terminal account of the device management platform. After the terminal account of the device management platform is connected and authenticated, it sends the authentication result back to the device connection device.

[0097] The above solution will bring at least the following beneficial effects:

[0098] Based on the above technical solutions, the device connection method provided in this application involves the device connection device first determining the device information and token information of the module device, and then accessing the module account of the device management platform based on the device information and token information. After accessing the module account of the device management platform, the device connection device reports the terminal device product number to the module account of the device management platform using the device information of the module device. The device management platform then feeds back terminal device authentication information associated with the terminal device product number to the device connection device. Finally, the device connection device receives the terminal device authentication information and initiates connection authentication with the device management platform based on the terminal device authentication information. This application provides a module device that uses a trusted module, thereby providing a trusted storage area and a secure operating environment for the connection between the terminal device and the device management platform. This application ensures the security of all information by allowing information exchange between the module device and the module account of the device management platform, storing the device information, token information, and terminal device authentication information of the module device in the module device.

[0099] Furthermore, compared to traditional terminal device access to device management platforms, the terminal device in this application only needs to provide its product number to connect to the device management platform. Upon receiving the product number from the module device's channel, the device management platform will automatically configure the associated terminal device number and key, and add the terminal device itself. This simplifies the process of connecting the terminal device to the device management platform, enabling rapid connection and improving the user experience.

[0100] In one possible implementation, combining Figure 7 ,like Figure 8 As shown, in step 701 above, the device connection device determines the device information and token information of the module device. This can be achieved through the following steps 801-806, which are explained in detail below:

[0101] Step 801: The device connection device receives the terminal device product number sent by the terminal device.

[0102] In one possible implementation, the terminal device imports its own terminal device product number into the module device, which can be understood as the terminal device initiating a connection request through the terminal device product number.

[0103] Step 802: The device connection device checks whether the module device stores terminal device authentication information based on the terminal device product number.

[0104] As one possible implementation, step 802 above can be implemented as follows: the device connection device detects whether it stores terminal device authentication information associated with the terminal device product number.

[0105] Step 803: If the module device stores the terminal device authentication information, the device connection device initiates connection authentication to the device management platform based on the terminal device authentication information.

[0106] Step 804: If the module device does not store terminal device authentication information, the device connection device detects whether the module device stores device information and token information.

[0107] In one possible implementation, if the device connection device detects that it does not store terminal device authentication information associated with the terminal device product number, the device connection device will continue to detect whether it stores the module device's device information and token information.

[0108] Step 805: If the module device stores the module device's device information and token information, the device connection device determines the module device's device information and token information.

[0109] Step 806: If the module device does not store the module device information and token information, the device connection device sends an authentication failure message to the terminal device.

[0110] In one possible implementation, if the module device does not store the module device information and token information, the device connection device sends feedback to the terminal device that there is no module authentication information.

[0111] The above details the specific steps by which the device connection device determines the device information and token information of the module device.

[0112] In one possible implementation, combining Figure 7 ,like Figure 9 As shown, before the device connection device determines the device information and token information of the module device, step 701 above specifically includes the following steps 901-904, which are described in detail below:

[0113] Step 901: The device connection device detects whether the module device stores token information.

[0114] As one possible implementation, before the device connection device detects the module device, the device management platform pre-creates the module product under the module account and determines the module device's product number and product key. When the module device leaves the factory, the device management platform's SDK module, along with the module device's product number and product key, are built into the module device, ensuring that the module device's product number and product key are stored in a trusted area and are not lost upon power failure.

[0115] After the module product is created in the module account on the device management platform, the terminal device is powered on, and the module is initialized. At this time, the implementation process of step 901 above can be: the device connection device detects whether the module device stores its own token information.

[0116] Optionally, the product key for the module device can be represented by a Module Product Secret or an M-PS.

[0117] Step 902: If the module device does not store token information, the device connection device sends a registration request to the device management platform based on the registration information of the module device.

[0118] The registration information for the module device includes at least one of the following: the module device's product number and the module device's product key.

[0119] In one possible implementation, step 902 can be implemented as follows: if no token information is stored in the module device, the device connection device sends an activation registration request to the module account of the device management platform through the module device's product number and product key. The module account of the device management platform compares the module device's product number and product key with its own pre-registered module device's product number and product key. If the comparison matches, the activation registration request is successful.

[0120] Step 903: The device connection device receives the token information fed back by the module account of the device management platform.

[0121] Among them, the token information is the token information associated with the registration information returned by the module account.

[0122] In one possible implementation, after the activation registration request is approved, the module account of the device management platform sends the token information of the module device to the device connection device. The device connection device receives the token information of the module device and stores it in the module device to ensure that it is not lost when power is off.

[0123] Step 904: The device connection device establishes a connection with the device management platform based on the product number of the module device, the device number of the module device, and the token information.

[0124] As one possible implementation, step 904 above can be implemented as follows: The device connection device sends the product number, device information, and token information of the module device to the module account of the device management platform. The module account of the device management platform receives the product number, device information, and token information of the module device and compares them with its own stored information to determine whether they match. If they match, the module account of the device management platform automatically adds the module device and sends the connection result back to the device connection device. Then, the module device disconnects from the module account of the device management platform, and finally the self-registration of the module device is completed.

[0125] Optionally, the device number of the module device can be the International Mobile Equipment Identity (IMEI) of the module device.

[0126] This application embodiment can divide the device connection device into functional modules or functional units according to the above method examples. For example, each function can be divided into a separate functional module or functional unit, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or in software functional modules or functional units. The module or unit division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.

[0127] like Figure 10 The diagram shown is a structural schematic of a device connection apparatus provided in an embodiment of this application. The apparatus includes a processing unit 1001 and a communication unit 1002.

[0128] Processing unit 1001 is used to determine the device information and token information of the module device; processing unit 1001 is also used to access the module account of the device management platform based on the device information and token information of the module device; the module account is used to manage the modules accessing the device management platform; processing unit 1001 is also used to report the terminal device product number to the module account of the device management platform based on the device information of the module device; communication unit 1002 is used to receive terminal device authentication information fed back by the terminal account; the terminal account is used to manage multiple terminal devices accessing the device management platform; the terminal device authentication information is the terminal device authentication information determined by the terminal account and associated with the terminal device product number; processing unit 1001 is also used to initiate connection authentication to the device management platform based on the terminal device authentication information.

[0129] Optionally, the communication unit 1002 is further configured to receive the terminal device product number sent by the terminal device; the processing unit 1001 is specifically configured to detect whether the module device stores terminal device authentication information based on the terminal device product number; if the module device stores terminal device authentication information, initiate connection authentication to the device management platform based on the terminal device authentication information; if the module device does not store terminal device authentication information, detect whether the module device stores device information and token information; if the module device stores device information and token information, determine the device information and token information of the module device.

[0130] Optionally, if the module device does not store the module device information and token information, the processing unit 1001 is also used to send authentication failure information to the terminal device.

[0131] Optionally, the terminal device authentication information includes: the terminal device product number and the terminal device number associated with the terminal device product number, and the terminal device key.

[0132] Optionally, the processing unit 1001 is further configured to detect whether the module device stores token information; if the module device does not store token information, the processing unit 1001 is further configured to send a registration request to the device management platform based on the registration information of the module device; the registration information of the module device includes at least one of the following: the product number of the module device and the product key of the module device; the communication unit 1002 is further configured to receive token information fed back by the module account of the device management platform; the token information is the token information associated with the registration information fed back by the module account; the processing unit 1001 is further configured to establish a connection with the device management platform based on the product number of the module device, the device number of the module device, and the token information.

[0133] When implemented in hardware, the communication unit 1002 in this embodiment can be integrated onto the communication interface, and the processing unit 1001 can be integrated onto the processor. Specific implementation methods are as follows: Figure 11 As shown.

[0134] Figure 11A schematic diagram of another possible structure of the device connection device involved in the above embodiments is shown. The device connection device includes a processor 1102 and a communication interface 1103. The processor 1102 is used to control and manage the operation of the device connection device, for example, executing the steps performed by the processing unit 1001, and / or performing other processes of the technology described herein. The communication interface 1103 is used to support communication between the device connection device and other network entities, for example, executing the steps performed by the communication unit 1002. The device connection device may also include a memory 1101 and a bus 1104, the memory 1101 being used to store the program code and data of the device connection device.

[0135] The memory 1101 may be a memory in a device connection device, and the memory may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as read-only memory, flash memory, hard disk or solid-state drive; the memory may also include a combination of the above types of memory.

[0136] The processor 1102 described above can implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor can be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor can also be a combination that implements computing functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.

[0137] Bus 1104 can be an Extended Industry Standard Architecture (EISA) bus, etc. Bus 1104 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 11 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0138] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0139] This application provides a computer program product containing instructions that, when run on a computer, cause the computer to execute the device connection method described in the above method embodiments.

[0140] This application also provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the device connection method in the method flow shown in the above method embodiments.

[0141] The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: electrical connections having one or more wires; portable computer disks; hard disks; random access memory (RAM); read-only memory (ROM); erasable programmable read-only memory (EPROM); registers; hard disks; optical fibers; portable compact disc read-only memory (CD-ROM); optical storage devices; magnetic storage devices; or any suitable combination thereof; or any other form of computer-readable storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may reside in an application-specific integrated circuit (ASIC). In the embodiments of this application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0142] Since the device connection device, computer-readable storage medium, and computer program product in the embodiments of the present invention can be applied to the above method, the technical effects obtained can also be referred to the above method embodiments. The embodiments of the present invention will not be repeated here.

[0143] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0144] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0145] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0146] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A device connection method, characterized in that, The method includes: The device information and token information of the module device are determined. The module device is a trusted module and serves as a connection between the terminal device and the device management platform. The module device is used to provide a trusted storage area and a secure operating environment. The information stored in the trusted storage area is not lost when power is lost. The module account accesses the device management platform based on the device information and token information of the module device; the module account is used to manage the modules accessing the device management platform. The terminal device product number provided by the terminal device is reported to the module account of the device management platform based on the device information of the module device; the terminal device only provides the terminal device product number; The system receives terminal device authentication information from a terminal account; the terminal account is used to manage multiple terminal devices accessing the device management platform; the terminal device authentication information is the terminal device authentication information determined by the terminal account and associated with the terminal device product number; the terminal device authentication information includes: the terminal device product number, and the terminal device number and terminal device key associated with the terminal device product number. The terminal device initiates connection authentication to the device management platform based on the terminal device product number, the terminal device number associated with the terminal device product number, and the terminal device key.

2. The method according to claim 1, characterized in that, The determination of the module device's device information and token information includes: Receive the terminal device product number sent by the terminal device; Based on the terminal device product number, detect whether the module device stores the terminal device authentication information; If the module device stores the terminal device authentication information, it initiates connection authentication to the device management platform based on the terminal device authentication information. If the module device does not store the terminal device authentication information, detect whether the module device stores the device information and token information of the module device; If the module device stores the device information and token information of the module device, then the device information and token information of the module device are determined.

3. The method according to claim 2, characterized in that, The method further includes: If the module device does not store the device information and token information of the module device, an authentication failure message is sent to the terminal device.

4. The method according to any one of claims 1-3, characterized in that, Before determining the device information and token information of the module device, the following is included: Detect whether the module device stores the token information; If the module device does not store the token information, a registration request is sent to the device management platform based on the module device's registration information; the module device's registration information includes at least one of the following: the module device's product number and the module device's product key; The device management platform receives the token information fed back by the module account; the token information is the token information associated with the registration information fed back by the module account. A connection is established with the device management platform based on the product number of the module device, the device number of the module device, and the token information.

5. A device connection apparatus, characterized in that, The device includes: a processing unit and a communication unit; The processing unit is used to determine the device information and token information of the module device. The module device is a trusted module and serves as a connection between the terminal device and the device management platform. The module device provides a trusted storage area and a secure operating environment. The information stored in the trusted storage area is not lost when power is lost. The processing unit is further configured to access the module account of the device management platform based on the device information and token information of the module device; the module account is used to manage the modules accessing the device management platform; The processing unit is further configured to report the terminal device product number provided by the terminal device to the module account of the device management platform based on the device information of the module device; the terminal device only provides the terminal device product number; The communication unit is used to receive terminal device authentication information fed back by the terminal account; the terminal account is used to manage multiple terminal devices accessing the device management platform; the terminal device authentication information is the terminal device authentication information determined by the terminal account and associated with the terminal device product number; the terminal device authentication information includes: the terminal device product number, and the terminal device number associated with the terminal device product number and the terminal device key; The processing unit is further configured to initiate connection authentication to the device management platform based on the terminal device product number, the terminal device number associated with the terminal device product number, and the terminal device key.

6. The apparatus according to claim 5, characterized in that, The communication unit is also used to receive data from the terminal device. The product number of the terminal device being sent; The processing unit is specifically used to: detect whether the module device stores the terminal device product number. The terminal device authentication information; If the module device stores the terminal device authentication information, it initiates connection authentication to the device management platform based on the terminal device authentication information. If the module device does not store the terminal device authentication information, detect whether the module device stores the device information and token information of the module device; If the module device stores the device information and token information of the module device, then the device information and token information of the module device are determined.

7. The apparatus according to claim 6, characterized in that, If the module device does not store the device information and token information of the module device, the processing unit is also used to send authentication failure information to the terminal device.

8. The apparatus according to any one of claims 5-7, characterized in that, The processing unit is also used to detect whether the module device stores the token information; If the module device does not store the token information, the processing unit is further configured to send a registration request to the device management platform based on the registration information of the module device; the registration information of the module device includes at least one of the following: the product number of the module device and the product key of the module device; The communication unit is also configured to receive the token information fed back by the module account of the device management platform; the token information is the token information associated with the registration information fed back by the module account. The processing unit is also configured to establish a connection with the device management platform based on the product number of the module device, the device number of the module device, and the token information.

9. A device connection apparatus, characterized in that, include: A processor and a communication interface; the communication interface is coupled to the processor, the processor being configured to run computer programs or instructions to implement the device connection method as described in any one of claims 1-4.

10. A computer-readable storage medium storing instructions, characterized in that, When the computer executes the instruction, the computer performs the device connection method as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Terminal registration method and device

    CN111669817A

  • KR20210154394A