Access authentication method, device, equipment and storage medium
Patent Information
- Application Number
- CN202080107382.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-03
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2040-12-03
AI Technical Summary
[0004]如何实现智能设备的跨平台接入认证,相关技术尚未提供较好的解决方案
[0040]待认证设备广播的信标帧中携带第一随机数,第一随机数用于生成配网平台网关和待认证设备之间执行第一接入认证所需的认证端信任中心链接密钥以及设备端信任中心链接密钥,第一随机数是每次进行第一接入认证所动态产生的,保障第一接入认证的安全性。并且,本申请实施例中,配网平台网关通过配网平台云与设备平台云进行交互,获取第一接入认证所需的认证端信任中心链接密钥,再由配网平台网关配网平台网关和待认证设备分别使用认证端信任中心链接密钥以及设备端信任中心链接密钥,进行第一接入认证,从而实现了待认证设备的跨平台接入认证,扩展了待认证设备接入认证的实施场景。
Smart Images

Figure CN116508292B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication, and in particular to an access authentication method, apparatus, device, and storage medium. Background Technology
[0002] Smart devices can access and authenticate across different platforms.
[0003] For example, when networking smart devices, the network is built by platform A gateway, the platform cloud corresponding to platform A gateway is platform A cloud, and the platform cloud corresponding to the manufacturer of the smart devices is platform B cloud.
[0004] There is currently no satisfactory solution for cross-platform access authentication of smart devices. Summary of the Invention
[0005] This application provides an access authentication method, apparatus, device, and storage medium, and offers a cross-platform access authentication implementation scheme for smart devices. The technical solution is as follows:
[0006] According to one aspect of this application, an access authentication method is provided, applied to a device to be authenticated, the method comprising:
[0007] A broadcast beacon frame, the beacon frame carrying a first random number generated by the device to be authenticated;
[0008] Based on the first random number and the permission key, a device-side trust center connection key is generated, wherein the permission key is a key stored in the device to be authenticated and the device platform cloud;
[0009] The device-side trust center link key is used to perform the first access authentication with the distribution network platform gateway.
[0010] According to one aspect of this application, an access authentication method is provided, applied in a distribution network platform gateway, wherein the distribution network platform gateway supports network construction, and the cloud server corresponding to the distribution network platform gateway is a distribution network platform cloud, the method comprising:
[0011] Receive a beacon frame broadcast by the device to be authenticated, the beacon frame carrying a first random number generated by the device to be authenticated;
[0012] Through the distribution network platform cloud, it interacts with the device platform cloud to obtain the authentication end trust center link key. The authentication end trust center link key is a key generated based on the first random number and the permission key. The permission key is a key stored in the device to be authenticated and the device platform cloud.
[0013] The authentication terminal uses the trust center link key to perform the first access authentication with the device to be authenticated.
[0014] According to one aspect of this application, an access authentication method is provided, applied in a device platform cloud, wherein the device platform cloud is a cloud server of the manufacturer to which the device to be authenticated belongs, the method comprising:
[0015] The system interacts with the distribution network platform gateway, enabling the distribution network platform gateway to obtain the authentication end trust center link key. The authentication end trust center link key is a key generated based on a first random number generated by the device to be authenticated. The authentication end trust center link key is used to perform the first access authentication of the device to be authenticated.
[0016] According to one aspect of this application, an access authentication device is provided for use with a device to be authenticated, the device comprising: a beacon frame broadcasting module, a key generation module, and a first authentication module;
[0017] The beacon frame broadcasting module is used to broadcast beacon frames, which carry a first random number generated by the device to be authenticated.
[0018] The key generation module is used to generate a device-side trust center link key based on the first random number and the permission key, wherein the permission key is a key stored in the device to be authenticated and the device platform cloud.
[0019] The first authentication module is used to perform first access authentication with the distribution network platform gateway using the connection key of the device-side trust center.
[0020] According to one aspect of this application, an access authentication device is provided, applied in a distribution network platform gateway, wherein the distribution network platform gateway supports network construction and the cloud server corresponding to the distribution network platform gateway is a distribution network platform cloud, and the device includes: a beacon frame receiving module, a key determination module, and a first authentication module;
[0021] The beacon frame receiving module is used to receive beacon frames broadcast by the device to be authenticated, the beacon frames carrying a first random number generated by the device to be authenticated;
[0022] The key determination module is used to interact with the device platform cloud through the distribution network platform cloud to obtain the authentication end trust center link key. The authentication end trust center link key is a key generated based on the first random number and the permission key. The permission key is a key stored in the device to be authenticated and the device platform cloud.
[0023] The first authentication module is used to perform a first access authentication with the device to be authenticated using the link key of the authentication end trust center.
[0024] According to one aspect of this application, an access authentication device is provided, which is applied in a device platform cloud, wherein the device platform cloud is a cloud server of the manufacturer to which the device to be authenticated belongs, and the device includes: a key determination module;
[0025] The key determination module is used to interact with the distribution network platform gateway, so that the distribution network platform gateway obtains the authentication end trust center link key. The authentication end trust center link key is a key generated based on the first random number generated by the device to be authenticated. The authentication end trust center link key is used to perform the first access authentication of the device to be authenticated.
[0026] According to one aspect of this application, a device to be authenticated is provided, the device to be authenticated comprising: a processor and a transceiver connected to the processor; wherein,
[0027] The transceiver is used to broadcast beacon frames, which carry a first random number generated by the device to be authenticated.
[0028] The processor is configured to generate a device-side trust center link key based on the first random number and the permission key, wherein the permission key is a key stored in the device to be authenticated and the device platform cloud.
[0029] The processor is used to perform the first access authentication with the distribution network platform gateway using the device-side trust center link key.
[0030] According to one aspect of this application, a distribution network platform gateway is provided, which supports the construction of a Zigbee network. The cloud server corresponding to the distribution network platform gateway is a distribution network platform cloud. The distribution network platform gateway includes: a processor and a transceiver connected to the processor; wherein...
[0031] The transceiver is used to receive beacon frames broadcast by the device to be authenticated, the beacon frames carrying a first random number generated by the device to be authenticated;
[0032] The processor is used to interact with the device platform cloud through the distribution network platform cloud to obtain the authentication end trust center link key. The authentication end trust center link key is a key generated based on the first random number and the permission key. The permission key is a key stored in the device to be authenticated and the device platform cloud.
[0033] The processor is used to perform a first access authentication with the device to be authenticated using the link key of the authentication end trust center.
[0034] According to one aspect of this application, a device platform cloud is provided, which is a cloud server of the manufacturer to which the device to be certified belongs. The device platform cloud includes: a processor and a transceiver connected to the processor; wherein,
[0035] The processor is used to interact with the distribution network platform gateway, enabling the distribution network platform gateway to obtain the authentication end trust center link key. The authentication end trust center link key is a key generated based on a first random number generated by the device to be authenticated. The authentication end trust center link key is used to perform the first access authentication of the device to be authenticated.
[0036] According to one aspect of this application, a computer-readable storage medium is provided, wherein a computer program is stored therein, the computer program being loaded and executed by a processor to implement the access authentication method as described above.
[0037] According to one aspect of the embodiments of this application, a chip is provided, the chip including programmable logic circuits and / or program instructions, which, when the chip is run on a network device, is used to implement the access authentication method described above.
[0038] According to one aspect of this application, a computer program product is provided that, when run on a processor of a network device, causes the network device to perform the access authentication method described in the above aspect.
[0039] The technical solutions provided in this application have at least the following beneficial effects:
[0040] The beacon frame broadcast by the device to be authenticated carries a first random number. This first random number is used to generate the authentication trust center link key and the device trust center link key required for the first access authentication between the distribution network platform gateway and the device to be authenticated. The first random number is dynamically generated each time the first access authentication is performed, ensuring the security of the first access authentication. Furthermore, in this embodiment, the distribution network platform gateway interacts with the device platform cloud through the distribution network platform cloud to obtain the authentication trust center link key required for the first access authentication. Then, the distribution network platform gateway and the device to be authenticated use the authentication trust center link key and the device trust center link key respectively to perform the first access authentication, thereby realizing cross-platform access authentication for the device to be authenticated and expanding the implementation scenarios of access authentication for the device to be authenticated. Attached Figure Description
[0041] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0042] Figure 1 This is a block diagram of a cross-platform access authentication system for smart devices provided in an exemplary embodiment of this application;
[0043] Figure 2 This is a flowchart of an access authentication method provided in an exemplary embodiment of this application;
[0044] Figure 3 This is a flowchart of an access authentication method provided in an exemplary embodiment of this application;
[0045] Figure 4 This is a flowchart of an access authentication method provided in an exemplary embodiment of this application;
[0046] Figure 5 This is a flowchart of an access authentication method provided in an exemplary embodiment of this application;
[0047] Figure 6 This is a flowchart of an access authentication method provided in an exemplary embodiment of this application;
[0048] Figure 7 This is a flowchart of an access authentication method provided in an exemplary embodiment of this application;
[0049] Figure 8 This is a structural block diagram of an access authentication method apparatus provided in an exemplary embodiment of this application;
[0050] Figure 9 This is a structural block diagram of an access authentication method apparatus provided in an exemplary embodiment of this application;
[0051] Figure 10 This is a structural block diagram of an access authentication method apparatus provided in an exemplary embodiment of this application;
[0052] Figure 11 This is a schematic diagram of the structure of a computer device provided in an exemplary embodiment of this application. Detailed Implementation
[0053] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0054] First, a brief introduction to the terms used in the embodiments of this application:
[0055] Zigbee technology:
[0056] Zigbee is a low-power local area network (LAN) protocol based on the Institute of Electrical and Electronics Engineers (IEEE) 802.15.4 standard. According to international standards, ZigBee technology is a short-range, low-power wireless communication technology.
[0057] Because ZigBee technology typically has a transmission distance of less than 1 kilometer (i.e., short distance), it is mainly used for Personal Area Networks (PANs).
[0058] Beacon frames:
[0059] According to the IEEE 802.15.4 specification for beacons, two beacon frame formats are defined: a regular beacon frame and an enhanced beacon frame.
[0060] The difference between enhanced beacon frames and regular beacon frames lies in the addition of an Information Elements (IEs) field to the variable data, while the Guaranteed Time Slot (GTS) field and the Pending Address field are omitted.
[0061] Please refer to Table 1 below.
[0062] Table 1: Enhanced Beacon Frames
[0063]
[0064] As shown in Table 1, in the enhanced beacon frame, the information element field is further divided into header information elements (HeaderIEs) and payload information elements (PayloadIEs).
[0065] In the header information unit, when the element ID is 0, it indicates that the content is filled with vendor-defined information. The data length ranges from 0 to 127 bytes, with the first 3 bytes being the vendor's organizationally unique identifier (OUI), and the remaining bytes customizable according to the vendor's requirements. In this embodiment, the header information unit is filled with a first random number, a device identifier, and a vendor identifier.
[0066] Devices that support the Zigbee protocol are called Zigbee devices. Each Zigbee device has a unique installation code. The Zigbee gateway needs to obtain the installation code of the Zigbee device in order to connect the Zigbee device to the Zigbee network created by the Zigbee gateway.
[0067] In related technologies, the installation code of a Zigbee device is obtained by scanning the QR code of the Zigbee device with a mobile phone or by manually entering it on the mobile phone. The mobile phone then sends the installation code to the Zigbee gateway, which requires a lot of human interaction.
[0068] Meanwhile, the aforementioned technologies have not yet achieved cross-platform access authentication for Zigbee devices, and a solution for cross-platform access authentication for Zigbee devices is urgently needed.
[0069] The solution provided in this application will be described below by way of example.
[0070] Figure 1 The diagram illustrates a block diagram of a smart device cross-platform access authentication system provided in an exemplary embodiment of this application. The system may include: a device to be authenticated 12, a distribution network platform gateway 141, a distribution network platform cloud 142, and a device platform cloud 16.
[0071] The device to be authenticated 12 is a device capable of accessing a network. Optionally, the device to be authenticated 12 can be a smart device (such as VR (Virtual Reality) glasses, smart wearable devices, etc.), a terminal device, or other devices with network access capabilities. This application embodiment does not limit this. In one example, when the system is applied to smart home living, the device to be authenticated 12 can be a smart TV, smart speaker, smart air conditioner, smart light, smart doors and windows, smart curtains, smart socket, and other smart home devices. Optionally, there can be one device to be authenticated 12, or there can be multiple devices to be authenticated 12. This application embodiment does not limit this. In practical applications, the number of devices to be authenticated 12 can be determined based on application requirements or the maximum number of devices that the distribution network platform gateway 141 can manage.
[0072] The device 12 to be authenticated is configured to join the network by the distribution network platform gateway 141, and the cloud server corresponding to the distribution network platform gateway 141 is the distribution network platform cloud 142. The distribution network platform gateway 141 and the distribution network platform cloud 142 are connected via wired or wireless network.
[0073] The distribution platform gateway 141 is a device capable of configuring a network. Optionally, the distribution platform gateway 141 can be a server, terminal device, router, mobile phone, tablet computer, wearable device, or other device capable of configuring network access. This application embodiment does not limit this; in practical applications, the implementation form of the distribution platform gateway 141 can be determined based on the application scenario of the system. In one example, when the system is applied to smart home living, considering the characteristics of a small home environment and frequent activities, using a large-space distribution platform gateway 141 would affect normal home life. Therefore, the distribution platform gateway 141 can be implemented as a router, terminal device, mobile phone, tablet computer, wearable device, etc. Optionally, the number of distribution platform gateways 141 can be one or more. This application embodiment does not limit this; typically, for considerations such as saving resources, the number of distribution platform gateways 141 is one.
[0074] The device to be authenticated 12 is developed based on the device platform cloud 16, and the license key Kc of the device to be authenticated 12 is stored in the device platform cloud 16.
[0075] There is a communication link between the distribution network platform cloud 142 and the device platform cloud 16. Optionally, the distribution network platform cloud 142 sends the information required for the access authentication process of the device 12 to be authenticated to the device platform cloud 16; or, it forwards the information required for the access authentication process of the device 12 to the distribution network platform gateway 141.
[0076] Among them, the aforementioned distribution network platform Cloud 142 and equipment platform Cloud 16 are cloud computing resource pools in the field of cloud technology. These resource pools deploy various types of virtual resources for external customers to choose from. The cloud computing resource pool mainly includes: computing devices (virtualized machines containing operating systems), storage devices, and network devices. These can be independent physical servers, server clusters or distributed systems composed of multiple physical servers, or cloud servers providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0077] Optionally, the system may also include a control device 18, with the distribution network platform gateway 141 connected to the control device 18 via a wired or wireless network. The control device 18 is a device operated by a user to control the distribution network platform gateway 141. For example, a user can activate the distribution network platform gateway 141 using an application on the control device 18. The control device 18 can be a terminal device, mobile phone, tablet computer, wearable device, etc.
[0078] In one example, device 12 to be authenticated is a Zigbee device, and the network configuration platform gateway supports configuring a Zigbee network.
[0079] Figure 2 A flowchart illustrating an exemplary embodiment of the access authentication method provided in this application is shown. This method can be applied to, for example... Figure 1 In the cross-platform access authentication system for smart devices shown, the method includes:
[0080] Step 201: The device to be authenticated broadcasts a beacon frame, which carries a first random number generated by the device to be authenticated.
[0081] The device to be authenticated is a device that supports network access. Optionally, the device to be authenticated includes various types of home appliances (such as light bulbs), industrial assets (such as examination equipment in a hospital), etc. For example, the device to be authenticated is a Zigbee device.
[0082] A beacon frame is a command frame in the Medium Access Control (MAC) layer. Beacon frames are primarily used for the joining and rejoining processes of devices seeking authentication. In this embodiment, the device seeking authentication queries available networks by broadcasting beacon frames. Optionally, the device seeking authentication begins broadcasting beacon frames when it enters network configuration mode; alternatively, the device automatically enters network configuration mode upon first activation; or, the device is passively triggered into network configuration mode by user intervention.
[0083] The beacon frame carries a first random number, which is a random number (Nonce) generated by the device to be authenticated. The first random number is used to ensure the security of the first access authentication. Optionally, the length of the first random number is 4 bytes.
[0084] Optionally, the beacon frame may also carry a Device ID, which identifies the type of device to be authenticated and can be 2 bytes long. Optionally, the beacon frame may also carry a Company Identifier (CID), which identifies the manufacturer of the device to be authenticated and can be 3 bytes long. Optionally, the beacon frame may also carry a Device Address Identifier, which identifies the MAC address of the device to be authenticated. The Device Address Identifier uniquely identifies a device to be authenticated and can be a 64-bit address. For example, the Device Address Identifier may be an Extended Unique Identifier (EUI).
[0085] Step 202: The distribution network platform gateway receives the beacon frame.
[0086] A network distribution platform gateway is a device capable of configuring a network. Optionally, the network distribution platform gateway can be a server, terminal device, router, mobile phone, tablet, wearable device, or other device capable of configuring network access. For example, a network distribution platform gateway supports configuring Zigbee networks.
[0087] Since the device to be authenticated broadcasts beacon frames, the distribution network platform gateway can receive these beacon frames. Optionally, the distribution network platform gateway receives the beacon frames broadcast by the device to be authenticated through channel scanning. Optionally, the distribution network platform gateway has already established a network. Optionally, the network established by the distribution network platform gateway is identified using a Personal Area Network (PAN) ID.
[0088] Step 203: The distribution network platform gateway interacts with the device platform cloud through the distribution network platform cloud to obtain the authentication end trust center link key.
[0089] The device platform cloud is the cloud server corresponding to the development of the device to be certified. In other words, the device platform cloud is the cloud server corresponding to the manufacturer of the device to be certified.
[0090] The distribution platform cloud is the cloud server corresponding to the distribution platform gateway.
[0091] Optionally, the interaction between the distribution network platform gateway and the device platform cloud through the distribution network platform cloud refers to: the distribution network platform gateway sending message A to the distribution network platform cloud, and the distribution network platform cloud forwarding message A to the device platform cloud; or, the device platform cloud sending message B to the distribution network platform cloud, and the distribution network platform cloud forwarding message B to the distribution network platform gateway.
[0092] The authentication end TrustCenterLinkKey (TCLK) is a key generated based on a first random number and a permission key. Optionally, the authentication end TrustCenterLinkKey is generated by the distribution network platform gateway or by the device platform cloud. That is, the authentication end TrustCenterLinkKey is a key generated on the distribution network platform gateway side or the device platform cloud side for the first access authentication.
[0093] Step 204: The device to be authenticated generates a device-side trust center link key based on the first random number and the permission key.
[0094] The license key is a key stored in the device to be authenticated and in the device platform cloud. Optionally, the license key is pre-programmed into the secure storage area of the device to be authenticated at the factory. Optionally, the device platform cloud stores a table showing the relationship between the device address identifier of the device to be authenticated and the license key.
[0095] The device to be authenticated generates a device-side trust center connection key based on a self-generated first random number and a stored permission key. The device-side trust center connection key is a key generated by the device to be authenticated for the first access authentication.
[0096] It is understood that the implementation order of steps 203 and 204 is not limited in the embodiments of this application.
[0097] Step 205: The distribution network platform gateway and the device to be authenticated use the authentication end trust center link key and the device end trust center link key respectively to perform the first access authentication.
[0098] After the device to be authenticated generates the device-side trust center link key and the distribution network platform gateway obtains the authentication-side trust center link key, the distribution network platform gateway and the device to be authenticated use the authentication-side trust center link key and the device-side trust center link key, respectively, to perform the first access authentication.
[0099] Optionally, if the device-side trust center connection key generated by the device to be authenticated is the same as the authentication-side trust center connection key obtained by the distribution network platform gateway, the first access authentication is successful. Optionally, after the first access authentication is successful, the device to be authenticated can join the network established by the distribution network platform gateway.
[0100] In summary, the method provided in this embodiment carries a first random number in the beacon frame broadcast by the device to be authenticated. This first random number is used to generate the authentication trust center link key and the device trust center link key required for performing the first access authentication between the distribution network platform gateway and the device to be authenticated. The first random number is dynamically generated each time the first access authentication is performed, ensuring the security of the first access authentication. Furthermore, in this embodiment, the distribution network platform gateway interacts with the device platform cloud through the distribution network platform cloud to obtain the authentication trust center link key required for the first access authentication. Then, the distribution network platform gateway and the device to be authenticated use the authentication trust center link key and the device trust center link key respectively to perform the first access authentication, thereby realizing cross-platform access authentication for the device to be authenticated and expanding the implementation scenarios of access authentication for the device to be authenticated.
[0101] Based on Figure 2 In an optional embodiment, the process of performing the first access authentication on the device to be authenticated side includes: the device to be authenticated obtaining a network key based on the device-side trust center link key, and the network key being used to encrypt data at the network layer after the first access authentication. That is, the device to be authenticated obtains the correct network key by performing the first access procedure, thereby joining the network.
[0102] The following is an exemplary description of the first access authentication process.
[0103] Figure 3 A flowchart illustrating an exemplary embodiment of the access authentication method provided in this application is shown. This method can be applied to, for example... Figure 1 In the cross-platform access authentication system for smart devices shown, the method includes:
[0104] Step 301: The device to be authenticated broadcasts a beacon frame, which carries a first random number, device identifier, manufacturer identifier, and device address identifier.
[0105] Optionally, the beacon frame is an Enhanced Beacon frame. Enhanced Beacon frames are defined in IEEE 802.15.4 and are distinct from regular beacon frames. The specific format of an Enhanced Beacon frame can be found in Table 1 above.
[0106] Optionally, the enhanced beacon frame carries a first random number, a device identifier, a vendor identifier, and a device address identifier. The first random number, device identifier, and vendor identifier are filled in the header information elements (HeaderIEs) of the enhanced beacon frame, while the device address identifier is filled in the beacon payload of the enhanced beacon frame.
[0107] In one possible implementation, step 301 is replaced by the device to be authenticated broadcasting an enhanced beacon frame. In another possible implementation, step 301 is replaced by the device to be authenticated alternately broadcasting enhanced beacon frames and regular beacon frames to achieve compatibility with regular beacon frames.
[0108] Step 302: The distribution network platform gateway receives the beacon frame.
[0109] Optionally, the beacon frame is an enhanced beacon frame. The distribution network platform gateway receives the enhanced beacon frame broadcast by the device to be authenticated and obtains the first random number, device identifier, manufacturer identifier and device address identifier from the enhanced signal frame.
[0110] Step 303: The distribution network platform gateway sends a beacon response to the device to be authenticated.
[0111] The beacon response is used to respond to the beacon frame. Optionally, the beacon response carries the PAN ID of the network constructed by the distribution network platform gateway. Optionally, if the distribution network platform gateway agrees to the device to be authenticated joining the network, the distribution network platform gateway sends a beacon response to the device to be authenticated.
[0112] Optionally, the beacon frame carries a device identifier, which identifies the type of device to be authenticated. Before sending the beacon response, the distribution network platform gateway will also perform the following steps: send the device identifier to the control device, which controls the distribution network platform gateway; receive an access request sent by the control device, which triggers the distribution network platform gateway to send a beacon response, which is used to respond to the beacon frame.
[0113] For example, the distribution network platform gateway is a router, and the control terminal is a mobile phone used by the user. After receiving a beacon frame, the distribution network platform gateway sends the device identifier in the beacon frame to the mobile phone. The mobile phone broadcasts the type of the device to be authenticated corresponding to the device identifier. For example, if the type of the device to be authenticated corresponding to the device identifier is a temperature sensor, the user can understand the type of the device to be authenticated by the broadcast and control the mobile phone to send an access request. After receiving the access request, the distribution network platform gateway sends a beacon response to the device to be authenticated according to the instructions in the access request.
[0114] Step 304: The device to be authenticated receives the beacon response.
[0115] Optionally, the device to be authenticated can determine that there is a network that can be joined at the distribution network platform gateway by receiving a beacon response. This network is identified by a PAN ID.
[0116] Step 305: The device to be authenticated sends an association request to the distribution network platform gateway.
[0117] Among them, the association request is used to request access to the network built by the distribution network platform gateway.
[0118] Optionally, after receiving the beacon response, if the device to be authenticated chooses to access the network constructed by the distribution network platform gateway, the device to be authenticated sends an association request to the distribution network platform gateway.
[0119] Step 306: The distribution network platform gateway receives the association request.
[0120] Step 307: The distribution network platform gateway sends an association response to the device to be authenticated.
[0121] The association response is used to respond to association requests. After receiving an association request from the device to be authenticated, the distribution network platform gateway unicasts an association response back to the device.
[0122] Optionally, the associated response may include the network address assigned to the device to be authenticated by the distribution network platform gateway. This network address is a short 16-bit address used to uniquely identify the device to be authenticated within the network constructed by the distribution network platform gateway.
[0123] Step 308: The device to be authenticated receives the associated response.
[0124] Step 309: The distribution network platform gateway interacts with the device platform cloud through the distribution network platform cloud to obtain the authentication end trust center link key.
[0125] For details on how the distribution network platform gateway obtains the connection key from the authentication trust center, please refer to [link / reference needed]. Figure 4 The corresponding implementation examples will not be described in detail here.
[0126] Step 310: The device to be authenticated generates a device-side trust center link key based on the first random number and the permission key.
[0127] In one possible implementation, the device to be authenticated uses the generated device-side installation code as the device-side trust center link key. That is, step 310 includes: the device to be authenticated using a first key generation algorithm to process a first random number and a permission key to generate a device-side installation code, and using the device-side installation code as the device-side trust center link key. Optionally, the first key generation algorithm is a symmetric encryption algorithm, including the Advanced Encryption Standard (AES)-MMO (Matyas-Meyer-Oseas) hash algorithm.
[0128] For example, TCLK = InstallCode = AES-MMO(Kc|R1). Where TCLK is the device-side trust center link key, InstallCode is the device-side installation code, Kc is the license key, and R1 is the first random number.
[0129] In another possible implementation, after generating the device-side installation code, the device to be authenticated further processes the installation code to obtain the device-side trust center link key. That is, step 310 includes: the device to be authenticated using a first key generation algorithm to process a first random number and a license key to generate a device-side installation code; and using a second key generation algorithm to process the installation code to generate the device-side trust center link key. Optionally, the first key generation algorithm and the second key algorithm are symmetric encryption algorithms. The first key generation algorithm includes an AES-MMO hash algorithm; the second key generation algorithm includes an AES-MMO hash algorithm.
[0130] For example, InstallCode = AES-MMO(Kc|R1), TCLK = AES-MMO(Install Code). Where TCLK is the device-side trust center link key, InstallCode is the device-side installation code, Kc is the license key, and R1 is the first random number.
[0131] It is understandable that in the two implementation methods mentioned above, since the first random number is generated each time the device to be authenticated attempts to join the network, the device-side installation code is dynamically generated, and thus the device-side trust center link key determined by the device to be authenticated based on the device-side installation code is also dynamically generated.
[0132] Step 311: The distribution network platform gateway sends encryption key information to the device to be authenticated. The encryption key information is obtained by encrypting the network key based on the link key of the authentication end trust center.
[0133] The network key is a random string generated by the network distribution platform gateway when building the network. Optionally, all devices connected to the network share the same network key.
[0134] After obtaining the authentication trust center link key, the distribution network platform gateway uses the authentication trust center link key to encrypt the network key, obtains the encrypted key information, and sends the encrypted key information to the device to be authenticated, so that the device to be authenticated can obtain the network key from the encrypted key information.
[0135] Step 312: The device to be authenticated receives the encryption key information.
[0136] Step 313: The device to be authenticated uses the device-side trust center link key to process the encryption key information to obtain the network key.
[0137] The network key is used to encrypt data at the network layer. Optionally, after obtaining the network key, the device to be authenticated communicates with the distribution platform gateway based on the network key.
[0138] Since the encryption key information is obtained by the distribution network platform gateway encrypting the network key based on the authentication end trust center link key, if the device-side trust center link key generated on the device to be authenticated is equal to the authentication end trust center link key, the device to be authenticated can use the device-side trust center link key to process the encryption key information and obtain the correct network key.
[0139] Step 314: The device to be certified broadcasts a device declaration message.
[0140] The device declaration broadcast message is used to indicate that the device to be authenticated has been connected to the network constructed by the distribution network platform gateway.
[0141] Step 315: The distribution network platform gateway receives the device declaration message.
[0142] The distribution network platform gateway receives device declaration messages broadcast by the devices to be authenticated.
[0143] In summary, the method provided in this embodiment uses an enhanced beacon frame broadcast by the device to be authenticated. Since the enhanced beacon frame contains fields that can be customized by the manufacturer to which the device to be authenticated belongs, it is convenient to carry a first random number, device identifier, manufacturer identifier, and device address identifier in the enhanced beacon frame, thereby ensuring the subsequent execution of the first access authentication process.
[0144] Meanwhile, the method provided in this embodiment allows the distribution network platform gateway to obtain the authentication terminal installation code from the device cloud platform, eliminating the need for users to manually input or scan it. The user then sends the authentication terminal installation code to the device cloud platform, reducing human interaction and improving the efficiency of access authentication.
[0145] The following is an exemplary description of how the distribution network platform gateway obtains the authentication end trust center link key in step 309.
[0146] Figure 4 A flowchart illustrating an exemplary embodiment of the access authentication method provided in this application is shown. This method can be applied to, for example... Figure 1 In the cross-platform access authentication system for smart devices shown, the method includes:
[0147] Step 3091: The distribution network platform gateway sends an installation code request to the device platform cloud through the distribution network platform cloud.
[0148] The installation code request carries a device address identifier and a first random number. The first random number is used by the device platform cloud to generate the authentication installation code, and the device address identifier is used to identify the MAC address of the device to be authenticated.
[0149] Optionally, the installation code request also carries a manufacturer identifier. The distribution network platform gateway sends the installation code request to the distribution network platform cloud. The distribution network platform cloud identifies the device platform cloud based on the manufacturer identifier and forwards the installation code request to the device platform cloud.
[0150] Step 3092: The device platform cloud receives the installation code request.
[0151] The source address of the installation code request is the distribution platform gateway, and the installation code request carries the device address identifier corresponding to the device to be authenticated and the first random number.
[0152] Optionally, the device platform cloud receives an installation code request from the distribution network platform cloud with the source address being the distribution network platform gateway.
[0153] Step 3093: The device platform cloud generates an authentication terminal installation code based on the first random number.
[0154] Optionally, step 3093 includes: the device platform cloud determining the license key corresponding to the device to be authenticated based on the device address identifier; and using a first key generation algorithm to process the first random number and the license key to generate an authentication terminal installation code.
[0155] Optionally, the device platform cloud stores a relationship table between device address identifiers and license keys. The device platform cloud searches the relationship table based on the device address identifier to determine the license key corresponding to the device to be authenticated. Optionally, the first key generation algorithm is a symmetric encryption algorithm, including the AES-MMO hash algorithm.
[0156] For example, InstallCode' = AES-MMO(Kc|R1). Where InstallCode' is the authentication installation code, Kc is the license key, and R1 is the first random number.
[0157] Step 3094: The device platform cloud sends an installation code response, and the destination address of the installation code response is the distribution network platform gateway.
[0158] The installation code response carries the authentication end installation code, which is used by the distribution network platform gateway to determine the authentication end trust center link key.
[0159] Optionally, the device platform cloud sends an installation code response to the distribution network platform cloud, and the distribution network platform cloud forwards the installation code response to the distribution network platform gateway.
[0160] Step 3095: The distribution network platform gateway receives the installation code response.
[0161] Optionally, the distribution network platform gateway receives the installation code response with the source address being the device platform cloud via the distribution network platform cloud.
[0162] Step 3096: Based on the installation code response, the distribution network platform gateway determines the authentication end trust center link key.
[0163] The installation code response carries the authentication end installation code, which is used by the distribution network platform gateway to determine the authentication end trust center link key.
[0164] In one possible implementation, the distribution network platform gateway uses the obtained authentication terminal installation code as the device-side trust center link key.
[0165] In another possible implementation, after obtaining the authentication terminal installation code, the distribution network platform gateway further processes the authentication terminal installation code to obtain the authentication terminal trust center link key. Step 3096 includes: the distribution network platform gateway uses a second key generation algorithm to process the authentication terminal installation code to generate the authentication terminal trust center link key. Optionally, the second key generation algorithm is a symmetric encryption algorithm, including the AES-MMO hash algorithm.
[0166] For example, TCLK' = AES-MMO(Install Code'). Where TCLK' is the authentication trust center link key, and InstallCode' is the authentication installation code.
[0167] In summary, the method provided in this embodiment uses a device-side installation code and an authentication-side installation code, which are generated by the device to be authenticated and the distribution network platform gateway based on a first random number. Since the first random number is generated each time the device to be authenticated attempts to join the network, the device-side installation code is dynamically generated. Consequently, the device-side trust center link key determined by the device to be authenticated based on the device-side installation code is also dynamically generated, thus avoiding the risk of device-side installation code leakage caused by the device-side installation code being fixed.
[0168] Optional, based on Figure 2 In an optional embodiment, after the first access authentication, the device to be authenticated will perform a second access authentication based on a second random number generated by the device platform cloud.
[0169] The second access authentication process will be described below as an example.
[0170] Figure 5 A flowchart illustrating an exemplary embodiment of the access authentication method provided in this application is shown. This method can be applied to, for example... Figure 1 In the cross-platform access authentication system for smart devices shown, the method includes:
[0171] Step 501: The distribution network platform gateway sends a random number write request to the custom cluster of the device to be authenticated. The random number write request carries a second random number.
[0172] The second random number is generated by the device platform cloud. Optionally, the distribution network platform gateway obtains the second random number from the installation code response with the source address being the device platform cloud.
[0173] A custom cluster is a cluster defined by the manufacturer of the device to be authenticated. The cluster of the device to be authenticated supports access by the distribution network platform gateway, with access types including write, write-after-return, read, etc. Optionally, step 501 includes: the distribution network platform gateway obtaining the access type of the custom cluster; in response to the custom cluster's access type being write-after-return, sending a random number write request to the custom cluster. When the custom cluster's access type is write-after-return, it facilitates the distribution network platform gateway receiving the returned device authentication key from the device to be authenticated after sending the random number write request.
[0174] Step 502: The device to be authenticated receives a random number write request.
[0175] The random number write request carries a second random number.
[0176] Step 503: The device to be authenticated generates a device-side authentication key based on the second random number.
[0177] Among them, the device-side authentication key is used for the second access authentication of the device to be authenticated.
[0178] Optionally, step 503 includes: the device to be authenticated uses a third key generation algorithm to process the second random number and the permission key to generate a device-side authentication key. Optionally, the third key generation algorithm is a symmetric encryption algorithm, including the AES-MMO hash algorithm.
[0179] For example, Auth = AES-MMO(Kc|R2). Where Auth is the device authentication key, Kc is the permission key, and R2 is the second random number.
[0180] Optionally, after generating the device-side authentication key, the device to be authenticated stores the device-side authentication key in an attribute of a custom cluster. The custom cluster includes at least one attribute, which is a data entity reflecting the state or nature of the device to be authenticated. In this embodiment, the attribute is used to store the device-side authentication key corresponding to the device to be authenticated. Optionally, the access type of the custom cluster is write-back.
[0181] Step 504: The device to be authenticated sends its device authentication key to the distribution network platform gateway.
[0182] After generating and storing the device-side authentication key, the device to be authenticated sends the device-side authentication key to the distribution network platform gateway.
[0183] Step 505: The distribution network platform gateway receives the device's authentication key.
[0184] Step 506: The distribution network platform gateway sends an authentication device request to the device platform cloud through the distribution network platform cloud. The authentication device request carries the device address identifier and the device authentication key.
[0185] The Authentication Device Request is used to request the device platform cloud to perform a second access authentication.
[0186] Optionally, the authentication device request also carries a manufacturer identifier. The distribution network platform gateway sends the authentication device request to the distribution network platform cloud. The distribution network platform cloud identifies the device platform cloud based on the manufacturer identifier and forwards the authentication device request to the device platform cloud.
[0187] Step 507: The device platform cloud receives the authentication device request.
[0188] The source address of the authentication device request is the distribution network platform gateway. The authentication device request carries a device address identifier and a device-side authentication key, which is a key generated by the device to be authenticated based on a second random number. Optionally, the device platform cloud receives the authentication device request with the distribution network platform gateway as the source address from the distribution network platform cloud.
[0189] Step 508: The device platform cloud performs a second access authentication on the device-side authentication key based on the second random number.
[0190] The second random number is a random number generated by the device platform cloud. Optionally, the length of the second random number is 4 bytes.
[0191] Optionally, step 508 includes: the device platform cloud determining the license key corresponding to the device to be authenticated based on the device address identifier; using a third key generation algorithm to process the second random number and the license key to generate a cloud authentication key; and verifying the cloud authentication key and the device authentication key to determine the authentication result.
[0192] Optionally, the device platform cloud stores a relationship table between device address identifiers and license keys. The device platform cloud searches the relationship table based on the device address identifier to determine the license key corresponding to the device to be authenticated. Optionally, the third key generation algorithm is a symmetric encryption algorithm, including the AES-MMO hash algorithm.
[0193] For example, Auth' = AES-MMO(Kc|R2). Where Auth' is the cloud authentication key, Kc is the permission key, and R2 is the second random number.
[0194] For example, if the cloud authentication key is equal to the device authentication key, the authentication result is successful; if the cloud authentication key is not equal to the device authentication key, the authentication result is unsuccessful.
[0195] Step 509: The device platform cloud sends the authentication result, and the destination address of the authentication result is the distribution network platform gateway.
[0196] Optionally, the device platform cloud sends the authentication result to the distribution network platform cloud, and the distribution network platform cloud forwards the authentication result to the distribution network platform gateway.
[0197] Step 510: The distribution network platform gateway receives the authentication result.
[0198] Optionally, the distribution network platform gateway receives the authentication result from the device platform cloud via the distribution network platform cloud.
[0199] Optionally, after receiving the authentication result, the distribution network platform gateway may also perform any of the following steps: In response to a successful authentication result, update the authentication end trust center link key; in response to a failed authentication result, add the device to be authenticated to the device blacklist, which records devices that failed to distribute the network. Optionally, the devices to be authenticated in the device blacklist may be removed from the network constructed by the distribution network platform gateway.
[0200] It is understandable that, since the authentication end's trust center link key is verified to be equal to the device's trust center link key during the first access authentication process, and the device to be authenticated has joined the network built by the distribution network platform gateway, the distribution network platform gateway updating the authentication end's trust center link key after successful authentication means that the distribution network platform gateway and the device to be authenticated update the trust center link keys on both sides simultaneously.
[0201] In summary, the method provided in this embodiment generates a cloud authentication key and a device authentication key using a second random number generated by the device platform cloud after the first access verification. The cloud authentication key and the device authentication key are then used to perform a second access verification on the device to be authenticated. Compared with only performing the first access verification, the second access verification achieves bidirectional verification, further improving the reliability of access verification.
[0202] The solution presented in this application will be described below with reference to the following embodiments. In this embodiment, the device to be authenticated is a Zigbee device, and the distribution network platform gateway is configured with a Zigbee network.
[0203] In the following embodiments, CID represents the manufacturer identifier, R1 represents the first random number, Device ID represents the device identifier, EUI represents the device address identifier, R2 represents the second random number, Kc represents the license key, Install Code represents the device-side installation code, Install Code' represents the authentication-side installation code, TCLK represents the device-side trust center link key, TCLK' represents the authentication-side trust center link key, Network Key represents the network key, Auth represents the device-side authentication key, and Auth' represents the cloud authentication key for illustrative purposes.
[0204] Figure 6 A flowchart illustrating an exemplary embodiment of the access authentication method provided in this application is shown. This method can be applied to, for example... Figure 1 In the cross-platform access authentication system for smart devices shown, the method includes:
[0205] Step 61: The distribution network platform gateway builds a Zigbee network.
[0206] The distribution network platform gateway is a device capable of configuring a Zigbee network.
[0207] Step 62: The user activates the network configuration platform gateway via APP or voice.
[0208] Step 63: The distribution network platform gateway grants access.
[0209] Optionally, the distribution network platform may grant access by broadcasting a Permit Join message.
[0210] Step 64: The distribution network platform gateway performs a channel scan.
[0211] Step 65: The Zigbee device uses the enhanced beacon frame format to fill the header information unit with CID|R1|DeviceID and the beacon payload with EUI.
[0212] Optionally, the element ID of the enhanced beacon frame is 0x00. Optionally, the CID is 3 bytes, R1 is 4 bytes, and DeviceID is 2 bytes.
[0213] Step 66: The distribution network platform gateway broadcasts an enhanced beacon frame, carrying the data CID|R1|Device ID|EUI.
[0214] Optionally, either of the following two broadcast methods can be used: broadcast only enhanced beacon frames; or, alternately broadcast enhanced beacon frames and regular beacon frames, compatible with regular beacon frames.
[0215] Step 67: The distribution network platform gateway returns the Device ID.
[0216] Optionally, DeviceID is a 16-bit identifier used to identify the device type.
[0217] Step 68: The user side broadcasts the device type.
[0218] Optionally, the user side can determine the device type of the Zigbee device based on the Device ID and broadcast it.
[0219] Step 69, the user enters: Connect device.
[0220] After obtaining the device type of the Zigbee device, the user sends an access request to the distribution network platform gateway.
[0221] Step 610: The distribution network platform gateway sends a beacon response to the Zigbee device.
[0222] The beacon response is used to respond to the enhanced beacon frame broadcast by the Zigbee device.
[0223] Step 611: The Zigbee device sends an association request to the distribution network platform gateway.
[0224] The association request is used to request access to the Zigbee network built by the distribution network platform gateway.
[0225] Step 612: The distribution network platform gateway sends an association response to the Zigbee device.
[0226] The association response is used to respond to an association request. Optionally, the association response may include the network address assigned to the Zigbee device by the distribution platform gateway.
[0227] Step 613: The distribution network platform gateway sends an installation code request, carrying the data CID|R1|EUI.
[0228] Step 613.1: The distribution network platform cloud queries the device platform cloud based on the CID.
[0229] The distribution network platform cloud can determine through the CID that the Zigbee device does not belong to the distribution network platform cloud, and obtain the corresponding manufacturer's cloud platform information based on the CID.
[0230] Step 613.2: The distribution network platform cloud sends an installation code request to the device platform cloud, carrying the data R1|EUI.
[0231] Step 613.3: The device platform cloud finds device Kc based on EUI, generates Install Code' = AES-MMO(Kc|R1), and generates a random number R2.
[0232] Optionally, the device platform cloud stores a mapping table between EUI and Kc.
[0233] Step 613.4: The device platform returns an installation code response to the distribution network platform cloud, carrying the data Install Code' and R2.
[0234] Step 614: The distribution network platform cloud returns an installation code response to the distribution network platform gateway, carrying the data Install Code' and R2.
[0235] Step 615: The distribution network platform gateway generates TCLK' = AES-MMO (Install Code').
[0236] After obtaining the Install Code, the distribution network platform gateway generates the TCLK based on the Install Code.
[0237] Optionally, the distribution network platform gateway establishes and stores a mapping table between EUI and TCLK'.
[0238] Step 616: The Zigbee device generates Install Code = AES-MMO(Kc|R1) and TCLK = AES-MMO(Install Code).
[0239] Kc can only be stored in Zigbee devices and device platform clouds.
[0240] Step 617: The distribution network platform gateway and Zigbee device establish a network layer security channel through TCLK to transmit the Network Key.
[0241] The distribution network platform gateway encrypts the NetworkKey using TCLK and sends the encrypted data to the Zigbee device.
[0242] Step 618: The Zigbee device obtains the Network Key.
[0243] If the InstallCode of the Zigbee device does not match the InstallCode of the device platform cloud, it cannot access the Zigbee network established by the distribution network platform gateway; only when the InstallCode of the Zigbee device matches the InstallCode of the device platform cloud can the Zigbee device obtain the correct NetworkKey.
[0244] Step 619: The distribution network platform gateway and Zigbee devices broadcast device declarations.
[0245] Device announcements are broadcast to indicate that a Zigbee device is connected to the Zigbee network built by the distribution network platform gateway.
[0246] Step 620: The distribution network platform gateway sends a random number write request, carrying data R2.
[0247] Optionally, the distribution network platform gateway obtains the access type of the custom cluster of the Zigbee device; in response to the access type of the custom cluster being Write-After-Return (W*R), it sends a random number write request to the custom cluster.
[0248] Step 621: The Zigbee device generates Auth = AES-MMO(Kc|R2) and stores the Auth in the attributes of the custom cluster.
[0249] Step 622: The Zigbee device returns the Auth to the distribution platform gateway.
[0250] Step 623: The distribution network platform gateway sends an authentication device request to the distribution network platform cloud, carrying the data CID|Auth|EUI.
[0251] Step 623.1: The distribution network platform cloud queries the device platform cloud based on the CID.
[0252] The distribution network platform cloud can determine through the CID that the Zigbee device does not belong to the distribution network platform cloud, and obtain the corresponding manufacturer's cloud platform information based on the CID.
[0253] Step 623.2: The distribution network platform cloud sends an authentication device request to the device platform cloud, carrying the data Auth|EUI.
[0254] Step 623.3: The device platform cloud finds device Kc based on EUI, generates device Auth' = AES-MMO(Kc|R2), and verifies Auth' against Auth.
[0255] Optionally, the device platform cloud stores a mapping table between EUI and Kc. If Auth' = Auth, authentication is successful; otherwise, it fails.
[0256] Step 623.4: The device platform cloud returns the authentication result to the distribution network platform cloud.
[0257] Step 624: The distribution network platform cloud returns the authentication result to the distribution network platform gateway.
[0258] Step 625: If the network distribution platform gateway fails authentication, add the device to the blacklist.
[0259] The device blacklist is used to record devices that fail to configure the network. Optionally, Zigbee devices in the device blacklist are removed from the Zigbee network constructed by the network configuration platform gateway.
[0260] If the network distribution platform gateway successfully authenticates, proceed with the next steps.
[0261] Step 626: The distribution network platform gateway and Zigbee device update TCLK and establish a normal connection.
[0262] Optionally, the updated TCLK is used to encrypt data transmission in the Application Support Sublayer (APS).
[0263] Figure 6 In one embodiment, the authentication trust center link key is generated on the distribution network platform gateway side. In another possible implementation, the authentication trust center link key is generated on the device platform cloud side.
[0264] Figure 7 A flowchart illustrating an exemplary embodiment of the access authentication method provided in this application is shown. This method can be applied to, for example... Figure 1 The illustrated smart device cross-platform access authentication system is shown. Figure 6 Based on this, the following steps of the method have been adjusted:
[0265] Step 713.3: The device platform cloud finds device Kc based on EUI, generates TCLK' = AES-MMO(Kc|R1), and generates a random number R2.
[0266] InstallCode' is implicitly represented by the combination of Kc|R1, TCLK' = InstallCode' = AES-MMO(Kc|R1).
[0267] Optionally, the device platform cloud stores a mapping table between EUI and Kc.
[0268] Step 713.4: The device platform returns an installation code response to the distribution network platform cloud, carrying data TCLK' and R2.
[0269] Step 714: The cloud distribution platform returns an installation code response to the distribution platform gateway, carrying data TCLK' and R2.
[0270] Step 715: The distribution network platform gateway establishes a mapping table between EUI and TCLK'.
[0271] Step 716, the Zigbee device generates TCLK = AES-MMO(Kc|R1).
[0272] Kc can only be stored in Zigbee devices and device platform clouds.
[0273] Understandable Figure 7 Other steps are described in the above embodiments and will not be repeated here.
[0274] In summary, the method provided in this embodiment generates the authentication end trust center link key and the device end trust center link key directly based on the first random number and the permission key, without requiring further processing of the authentication end installation code or the device end installation code, thus improving the efficiency of access authentication for Zigbee devices.
[0275] It should be noted that the above method embodiments can be implemented individually or in combination, and this application does not impose any restrictions on this.
[0276] Figure 8 The diagram shows a structural block diagram of an access authentication device provided in an exemplary embodiment of this application. The device can be implemented as a device to be authenticated, or as part of a device to be authenticated. The device includes: a beacon frame broadcast module 801, a key generation module 802, and a first authentication module 803.
[0277] The beacon frame broadcasting module 801 is used to broadcast beacon frames, the beacon frames carrying a first random number generated by the device to be authenticated;
[0278] The key generation module 802 is used to generate a device-side trust center link key based on the first random number and the permission key, wherein the permission key is a key stored in the device to be authenticated and the device platform cloud.
[0279] The first authentication module 803 is used to perform first access authentication with the distribution network platform gateway using the link key of the device-side trust center.
[0280] In an optional embodiment, the first authentication module 803 is used to obtain a network key based on the device-side trust center link key, and the network key is used to encrypt data at the network layer after the first access authentication.
[0281] In an optional embodiment, the first authentication module 803 is configured to receive encryption key information sent by the distribution network platform gateway, wherein the encryption key information is encrypted by the distribution network platform gateway according to the authentication end trust center link key, and the authentication end trust center link key is generated by the distribution network platform gateway or the device platform cloud; and the encryption key information is processed using the device end trust center link key to obtain the network key.
[0282] In an optional embodiment, the apparatus further includes: a device declaration broadcast module; the device declaration broadcast module is used to broadcast a device declaration message, the device declaration message being used to indicate that the device to be authenticated has been connected to the network constructed by the distribution network platform gateway.
[0283] In an optional embodiment, the key generation module 802 is configured to use a first key generation algorithm to process the first random number and the license key to generate a device-side installation code, and use the device-side installation code as the device-side trust center link key; or, the key generation module 802 is configured to use the first key generation algorithm to process the first random number and the license key to generate the device-side installation code; and use a second key generation algorithm to process the device-side installation code to generate the device-side trust center link key.
[0284] In an optional embodiment, the first key generation algorithm includes: the AES-MMO hash algorithm; the second key generation algorithm includes: the AES-MMO hash algorithm.
[0285] In an optional embodiment, the beacon frame is an enhanced beacon frame, and the first random number is filled into the header information unit field of the enhanced beacon frame.
[0286] In an optional embodiment, the beacon frame broadcasting module 801 is used to broadcast the enhanced beacon frame; or, the beacon frame broadcasting module 801 is used to alternately broadcast the enhanced beacon frame and the regular beacon frame.
[0287] In an optional embodiment, the beacon frame also carries a device identifier, which identifies the type of the device to be authenticated.
[0288] In an optional embodiment, the beacon frame also carries a vendor identifier, which identifies the vendor to which the device to be authenticated belongs.
[0289] In an optional embodiment, the beacon frame also carries a device address identifier, which is used to identify the MAC address of the device to be authenticated.
[0290] In an optional embodiment, the apparatus further includes: a beacon response receiving module and an association module; the beacon response receiving module is configured to receive a beacon response sent by the distribution network platform gateway, the beacon response being used to respond to the beacon frame; the association module is configured to send an association request to the distribution network platform gateway, the association request being used to request access to the network constructed by the distribution network platform gateway; and receive an association response sent by the distribution network platform gateway, the association response being used to respond to the association request.
[0291] In an optional embodiment, the device further includes: a second authentication module; the second authentication module is configured to generate a device-side authentication key based on a second random number generated by the device platform cloud, the device-side authentication key being used for the second access authentication of the device to be authenticated; and to send the device-side authentication key to the distribution network platform gateway.
[0292] In an optional embodiment, the second authentication module is configured to use a third key generation algorithm to process the second random number and the permission key to generate the device-side authentication key.
[0293] In an optional embodiment, the third key generation algorithm includes the AES-MMO hash algorithm.
[0294] In an optional embodiment, the apparatus further includes: a request receiving module; the request receiving module is configured to receive a random number write request sent by the distribution network platform gateway to a custom cluster of the device to be authenticated, the random number write request carrying the second random number.
[0295] In an optional embodiment, the apparatus further includes a key storage module; the key storage module is used to store the device-side authentication key in the attributes of the custom cluster.
[0296] In an optional embodiment, the access type of the custom cluster is write-back.
[0297] Figure 9 The diagram shows a structural block diagram of an access authentication device provided in an exemplary embodiment of this application. The device can be implemented as a distribution network platform gateway, or as part of a distribution network platform gateway. The device includes: a beacon frame receiving module 901, a key determination module 902, and a first authentication module 903.
[0298] The beacon frame receiving module 901 is used to receive a beacon frame broadcast by the device to be authenticated, the beacon frame carrying a first random number generated by the device to be authenticated;
[0299] The key determination module 902 is used to interact with the device platform cloud through the distribution network platform cloud to obtain the authentication end trust center link key. The authentication end trust center link key is a key generated based on the first random number and the permission key. The permission key is a key stored in the device to be authenticated and the device platform cloud.
[0300] The first authentication module 903 is used to perform a first access authentication with the device to be authenticated using the link key of the authentication end trust center.
[0301] In an optional embodiment, the first authentication module 903 is used to send encryption key information to the device to be authenticated. The encryption key information is obtained by encrypting the network key according to the authentication end trust center link key. The network key is used to encrypt data at the network layer after the first access authentication.
[0302] In an optional embodiment, the apparatus further includes: a device declaration receiving module; the device declaration receiving module is configured to receive a device declaration message sent by the device to be authenticated, the device declaration message indicating that the device to be authenticated has been connected to the network constructed by the distribution network platform gateway.
[0303] In an optional embodiment, the beacon frame further carries a device address identifier of the device to be authenticated, the device address identifier being used to identify the MAC address of the device to be authenticated; the key determination module 902 is used to send an installation code request to the device platform cloud through the distribution network platform cloud, the installation code request carrying the device address identifier and the first random number, the first random number being used by the device platform cloud to generate an authentication terminal installation code; receive an installation code response with the device platform cloud as the source address through the distribution network platform cloud; and determine the authentication terminal trust center link key based on the installation code response.
[0304] In an optional embodiment, the installation code response carries the authentication terminal installation code; the key determination module 902 is used to use the authentication terminal installation code as the authentication terminal trust center link key; or, the key determination module 902 is used to process the authentication terminal installation code using a second key generation algorithm to generate the authentication terminal trust center link key.
[0305] In an optional embodiment, the second key generation algorithm includes the AES-MMO hash algorithm.
[0306] In an optional embodiment, the installation code response also carries a second random number generated by the device platform cloud.
[0307] In an optional embodiment, the apparatus further includes: an authentication request module; the authentication module is configured to send a random number write request to a custom cluster of the device to be authenticated, the random number write request carrying a second random number, the second random number being obtained by the distribution network platform gateway from the installation code response with the source address being the device platform cloud; receive a device-side authentication key sent by the device to be authenticated, the device-side authentication key being used for a second access authentication of the device to be authenticated; and send an authentication device request to the device platform cloud through the distribution network platform cloud, the authentication device request carrying a device address identifier and the device-side authentication key, the device address identifier being used to identify the MAC address of the device to be authenticated.
[0308] In an optional embodiment, the authentication request module is configured to obtain the access type of the custom cluster; in response to the access type of the custom cluster being write-back, the module sends the random number write request to the custom cluster.
[0309] In an optional embodiment, the apparatus further includes: an authentication result processing module; the authentication result processing module is configured to receive an authentication result from the device platform cloud via the distribution network platform cloud; update the authentication end trust center link key in response to the authentication result being successful; and add the device to be authenticated to a device blacklist in response to the authentication result being unsuccessful, the device blacklist being used to record devices that failed to distribute the network.
[0310] In an optional embodiment, the apparatus further includes: a beacon response sending module and an association module; the beacon response sending module is configured to send a beacon response to the device to be authenticated, the beacon response being used to respond to the beacon frame; the association module is configured to receive an association request sent by the device to be authenticated, the association request being used to request access to the network constructed by the distribution network platform gateway; and to send an association response to the device to be authenticated, the association response being used to respond to the association request.
[0311] In an optional embodiment, the beacon frame further carries a device identifier, which is used to identify the type of the device to be authenticated. The apparatus further includes: an access request receiving module; the access request receiving module is used to send the device identifier to a control device, which is used to control the distribution network platform gateway; and to receive an access request sent by the control device, which is used to trigger the distribution network platform gateway to send a beacon response, which is used to respond to the beacon frame.
[0312] In an optional embodiment, the beacon frame is an enhanced beacon frame, and the first random number is filled into the header information unit field of the enhanced beacon frame.
[0313] Figure 10 The diagram shows a structural block diagram of an access authentication device provided in an exemplary embodiment of this application. The device can be implemented as a device platform cloud, or as part of a device platform cloud. The device includes: a key determination module 1001.
[0314] The key determination module 1001 is used to interact with the distribution network platform gateway, so that the distribution network platform gateway obtains the authentication end trust center link key. The authentication end trust center link key is a key generated based on the first random number generated by the device to be authenticated. The authentication end trust center link key is used to perform the first access authentication of the device to be authenticated.
[0315] In an optional embodiment, the key determination module 1001 is configured to receive an installation code request, the source address of which is the distribution network platform gateway, the installation code request carrying a device address identifier corresponding to the device to be authenticated and the first random number, the device address identifier being used to identify the MAC address of the device to be authenticated; generate an authentication terminal installation code based on the first random number; and send an installation code response, the destination address of which is the distribution network platform gateway, the installation code response carrying the authentication terminal installation code, the authentication terminal installation code being used by the distribution network platform gateway to determine the authentication terminal trust center link key.
[0316] In an optional embodiment, the key determination module 1001 is used to determine the license key corresponding to the device to be authenticated based on the device address identifier; and to process the first random number and the license key using a first key generation algorithm to generate the authentication terminal installation code.
[0317] In an optional embodiment, the first key generation algorithm includes: the AES-MMO hash algorithm.
[0318] In an optional embodiment, the installation code response also carries a second random number generated by the device platform cloud.
[0319] In an optional embodiment, the apparatus further includes: a second authentication module; the second authentication module is configured to receive an authentication device request, wherein the source address of the authentication device request is the distribution platform gateway, the authentication device request carries a device address identifier and a device-side authentication key, the device-side authentication key is a key generated by the device to be authenticated based on a second random number, the second random number being generated by the device platform cloud; and to perform a second access authentication on the device-side authentication key according to the second random number, wherein the device address identifier is used to identify the MAC address of the device to be authenticated.
[0320] In an optional embodiment, the second authentication module is configured to determine the license key corresponding to the device to be authenticated based on the device address identifier; process the second random number and the license key using a third key generation algorithm to generate a cloud authentication key; and verify the cloud authentication key and the device-side authentication key to determine the authentication result.
[0321] In an optional embodiment, the third key generation algorithm includes the AES-MMO hash algorithm.
[0322] In an optional embodiment, the apparatus further includes: an authentication result sending module; the authentication result sending module is used to send the authentication result, the destination address of which is the distribution network platform gateway.
[0323] It should be noted that the above embodiments only illustrate the division of the above functional modules when implementing the device. In actual applications, the above functions can be assigned to different functional modules according to actual needs, that is, the content structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0324] Regarding the apparatus in the above embodiments, the specific manner in which each module performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.
[0325] Figure 11 The diagram illustrates the structure of a computer device (such as a device to be authenticated, a distribution network platform gateway, or a device platform cloud) provided in an exemplary embodiment of this application. The computer device includes: a processor 101, a receiver 102, a transmitter 103, a memory 104, and a bus 105.
[0326] The processor 101 includes one or more processing cores. The processor 101 executes various functional applications and information processing by running software programs and modules.
[0327] The receiver 102 and the transmitter 103 can be implemented as a communication component, which can be a communication chip.
[0328] The memory 104 is connected to the processor 101 via the bus 105.
[0329] The memory 104 can be used to store at least one instruction, and the processor 101 can execute the at least one instruction to implement the various steps in the above method embodiments.
[0330] Furthermore, the memory 104 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, including but not limited to: magnetic disks or optical disks, electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), static random access memory (SRAM), read-only memory (ROM), magnetic storage, flash memory, and programmable read-only memory (PROM).
[0331] In an exemplary embodiment, the computer device includes a processor, a memory, and a transceiver (the transceiver may include a receiver and a transmitter, the receiver being used to receive information and the transmitter being used to send information).
[0332] In one possible implementation, when the computer device is implemented as a device to be authenticated,
[0333] The transceiver is used to broadcast beacon frames, which carry a first random number generated by the device to be authenticated.
[0334] The processor is configured to generate a device-side trust center link key based on the first random number and the permission key, wherein the permission key is a key stored in the device to be authenticated and the device platform cloud.
[0335] The processor is used to perform the first access authentication with the distribution network platform gateway using the device-side trust center link key.
[0336] When the computer device is implemented as a device to be authenticated, the processor and transceiver in the computer device involved in the embodiments of this application can perform the above-described functions. Figures 2 to 5 The steps performed by the device to be certified in any of the methods shown will not be described here.
[0337] In one possible implementation, when the computer device is implemented as a distribution network platform gateway,
[0338] The transceiver is used to receive beacon frames broadcast by the device to be authenticated, the beacon frames carrying a first random number generated by the device to be authenticated;
[0339] The processor is used to interact with the device platform cloud through the distribution network platform cloud to obtain the authentication end trust center link key. The authentication end trust center link key is a key generated based on the first random number and the permission key. The permission key is a key stored in the device to be authenticated and the device platform cloud.
[0340] The processor is used to perform a first access authentication with the device to be authenticated using the link key of the authentication end trust center.
[0341] When the computer device is implemented as a distribution network platform gateway, the processor and transceiver in the computer device involved in the embodiments of this application can perform the above-mentioned functions. Figures 2 to 5 The steps performed by the distribution network platform gateway in any of the methods shown will not be described again here.
[0342] In one possible implementation, when the computer device is implemented as a device platform cloud,
[0343] The processor is used to interact with the distribution network platform gateway, enabling the distribution network platform gateway to obtain the authentication end trust center link key. The authentication end trust center link key is a key generated based on a first random number generated by the device to be authenticated. The authentication end trust center link key is used to perform the first access authentication of the device to be authenticated.
[0344] When the computer device is implemented as a device platform cloud, the processor and transceiver in the computer device involved in the embodiments of this application can perform the above-mentioned functions. Figures 2 to 5 The steps performed by the device platform cloud in any of the methods shown will not be described in detail here.
[0345] In an exemplary embodiment, a computer-readable storage medium is also provided, wherein a computer program is stored therein, the computer program being loaded and executed by a processor to implement the access authentication method executed by a computer device provided in the above-described method embodiments.
[0346] In an exemplary embodiment, a computer program product is also provided, which, when run on the processor of a computer device, causes a network device to perform the access authentication method described above.
[0347] In an exemplary embodiment, a chip is also provided, the chip including programmable logic circuitry and / or program instructions, which, when the chip is run on a computer device, are used to implement the access authentication method described above.
[0348] The above description is merely an optional embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. An access authentication method, characterized in that, Applied to a device to be authenticated, the method includes: A broadcast beacon frame, the beacon frame carrying a first random number generated by the device to be authenticated; Based on the first random number and the permission key, a device-side trust center connection key is generated, wherein the permission key is a key stored in the device to be authenticated and the device platform cloud; Using the device-side trust center link key, a first access authentication is performed with the distribution network platform gateway. This includes receiving encryption key information sent by the distribution network platform gateway, which is encrypted by the gateway based on the authentication end trust center link key. The authentication end trust center link key is generated by the distribution network platform gateway or the device platform cloud. The device-side trust center link key is then used to process the encryption key information to obtain a network key, which is used to encrypt data at the network layer after the first access authentication. The device platform cloud is the cloud server corresponding to the manufacturer to which the device to be certified belongs, and the device to be certified is configured to enter the network by the distribution network platform gateway.
2. The method according to claim 1, characterized in that, The method further includes: A broadcast device declaration message is used to indicate that the device to be authenticated has been connected to the network constructed by the distribution network platform gateway.
3. The method according to claim 1 or 2, characterized in that, The step of generating a device-side trust center link key based on the first random number and the permission key includes: The first key generation algorithm is used to process the first random number and the license key to generate a device-side installation code, which is then used as the device-side trust center link key. or, A first key generation algorithm is used to process the first random number and the license key to generate a device-side installation code; a second key generation algorithm is used to process the device-side installation code to generate the device-side trust center link key.
4. The method according to claim 3, characterized in that, The first key generation algorithm includes: Advanced Encryption Standard (AES)-MMO hash algorithm; The second key generation algorithm includes the AES-MMO hash algorithm.
5. The method according to claim 1 or 2, characterized in that, The beacon frame is an enhanced beacon frame, and the first random number is filled into the header information unit field of the enhanced beacon frame.
6. The method according to claim 5, characterized in that, The broadcast beacon frame includes: Broadcast the enhanced beacon frame; or, The enhanced beacon frames and regular beacon frames are broadcast alternately.
7. The method according to claim 1 or 2, characterized in that, The beacon frame also carries a device identifier, which is used to identify the type of the device to be authenticated.
8. The method according to claim 1 or 2, characterized in that, The beacon frame also carries a manufacturer identifier, which is used to identify the manufacturer to which the device to be authenticated belongs.
9. The method according to claim 1 or 2, characterized in that, The beacon frame also carries a device address identifier, which is used to identify the Media Access Control (MAC) address of the device to be authenticated.
10. The method according to claim 1 or 2, characterized in that, The method further includes: Receive a beacon response sent by the distribution network platform gateway, the beacon response being used to respond to the beacon frame; Send an association request to the distribution network platform gateway, the association request being used to request access to the network constructed by the distribution network platform gateway; Receive the association response sent by the distribution network platform gateway, the association response being used to respond to the association request.
11. The method according to claim 1 or 2, characterized in that, The method further includes: A device authentication key is generated based on a second random number generated by the device platform cloud. The device authentication key is used for the second access authentication of the device to be authenticated. Send the device-side authentication key to the distribution network platform gateway.
12. The method according to claim 11, characterized in that, The second random number generated based on the device platform cloud to generate the device-side authentication key includes: The third key generation algorithm is used to process the second random number and the permission key to generate the device authentication key.
13. The method according to claim 12, characterized in that, The third key generation algorithm includes the AES-MMO hash algorithm.
14. The method according to claim 11, characterized in that, The method further includes: The system receives a random number write request sent by the distribution network platform gateway to the custom cluster of the device to be authenticated, the random number write request carrying the second random number.
15. The method according to claim 14, characterized in that, The method further includes: The device-side authentication key is stored in the attributes of the custom cluster.
16. The method according to claim 14, characterized in that, The access type for the custom cluster is write-back.
17. An access authentication method, characterized in that, Applied in a distribution network platform gateway, the distribution network platform gateway supports network construction, and the cloud server corresponding to the distribution network platform gateway is a distribution network platform cloud. The method includes: Receive a beacon frame broadcast by the device to be authenticated, the beacon frame carrying a first random number generated by the device to be authenticated; Through the distribution network platform cloud, it interacts with the device platform cloud to obtain the authentication end trust center link key. The authentication end trust center link key is a key generated based on the first random number and the permission key. The permission key is a key stored in the device to be authenticated and the device platform cloud. Using the authentication end trust center link key, a first access authentication is performed with the device to be authenticated, wherein encrypted key information is sent to the device to be authenticated. The encrypted key information is obtained by encrypting the network key according to the authentication end trust center link key. The network key is used to encrypt data at the network layer after the first access authentication. The device platform cloud is the cloud server corresponding to the manufacturer to which the device to be certified belongs, and the device to be certified is configured to enter the network by the distribution network platform gateway.
18. The method according to claim 17, characterized in that, The method further includes: The system receives a device declaration message sent by the device to be authenticated, which indicates that the device to be authenticated has been connected to the network constructed by the distribution network platform gateway.
19. The method according to claim 17 or 18, characterized in that, The beacon frame also carries a device address identifier of the device to be authenticated, which is used to identify the Media Access Control (MAC) address of the device to be authenticated. The step of interacting with the device platform cloud through the distribution network platform cloud to obtain the authentication end trust center link key includes: The installation code request is sent to the device platform cloud through the distribution network platform cloud. The installation code request carries the device address identifier and the first random number. The first random number is used by the device platform cloud to generate the authentication terminal installation code. The system receives an installation code response with the source address of the device platform cloud via the distribution network platform cloud. Based on the installation code response, the authentication end trust center link key is determined.
20. The method according to claim 19, characterized in that, The installation code response carries the authentication terminal installation code; The step of determining the authentication end trust center link key based on the installation code response includes: Use the authentication terminal installation code as the authentication terminal trust center link key; or, The second key generation algorithm is used to process the authentication terminal installation code to generate the authentication terminal trust center link key.
21. The method according to claim 20, characterized in that, The second key generation algorithm includes: Advanced Encryption Standard (AES)-MMO hash algorithm.
22. The method according to claim 19, characterized in that, The installation code response also carries a second random number generated by the device platform cloud.
23. The method according to claim 17 or 18, characterized in that, The method further includes: Send a random number write request to the custom cluster of the device to be authenticated. The random number write request carries a second random number, which is obtained by the distribution network platform gateway from the installation code response with the source address of the device platform cloud. Receive the device authentication key sent by the device to be authenticated, the device authentication key being used for the second access authentication of the device to be authenticated; The network distribution platform cloud sends an authentication device request to the device platform cloud. The authentication device request carries a device address identifier and the device authentication key. The device address identifier is used to identify the MAC address of the device to be authenticated.
24. The method according to claim 23, characterized in that, Sending a random number write request to the custom cluster of the device to be authenticated includes: Obtain the access type of the custom cluster; In response to the custom cluster's access type being write-back, a random number write request is sent to the custom cluster.
25. The method according to claim 23, characterized in that, The method further includes: The authentication result with the source address of the device platform cloud is received through the distribution network platform cloud; In response to the authentication result being successful, the authentication end trust center link key is updated; In response to the authentication result being authentication failure, the device to be authenticated is added to the device blacklist, which is used to record devices that fail to configure the network.
26. The method according to claim 17 or 18, characterized in that, The method further includes: Send a beacon response to the device to be authenticated, the beacon response being used in response to the beacon frame; Receive the association request sent by the device to be authenticated, the association request being used to request access to the network constructed by the distribution network platform gateway; Send an association response to the device to be authenticated, the association response being used to respond to the association request.
27. The method according to claim 17 or 18, characterized in that, The beacon frame also carries a device identifier, which identifies the type of the device to be authenticated, and the method further includes: Send the device identifier to the control device, which is used to control the distribution network platform gateway; The system receives an access request sent by the control device. The access request is used to trigger the distribution network platform gateway to send a beacon response. The beacon response is used to respond to the beacon frame.
28. The method according to claim 17 or 18, characterized in that, The beacon frame is an enhanced beacon frame, and the first random number is filled into the header information unit field of the enhanced beacon frame.
29. An access authentication method, characterized in that, Applied to a device platform cloud, where the device platform cloud is the cloud server of the manufacturer to which the device to be certified belongs, the method includes: The system interacts with the distribution network platform gateway, enabling the gateway to obtain the authentication end trust center link key. This key is generated based on a first random number generated by the device to be authenticated. The authentication end trust center link key is used for the first access authentication of the device to be authenticated. Specifically, the system receives an installation code request, the source address of which is the distribution network platform gateway. The installation code request carries a device address identifier corresponding to the device to be authenticated and the first random number. The device address identifier identifies the Media Access Control (MAC) address of the device to be authenticated. Based on the first random number, an authentication end installation code is generated. An installation code response is sent, the destination address of which is the distribution network platform gateway. The installation code response carries the authentication end installation code, which is used by the distribution network platform gateway to determine the authentication end trust center link key. The device to be authenticated is configured to join the network by the distribution network platform gateway.
30. The method according to claim 29, characterized in that, The step of generating the authentication terminal installation code based on the first random number includes: Based on the device address identifier, determine the license key corresponding to the device to be authenticated; The first key generation algorithm is used to process the first random number and the permission key to generate the authentication terminal installation code.
31. The method according to claim 30, characterized in that, The first key generation algorithm includes: Advanced Encryption Standard (AES-MMO) hash algorithm.
32. The method according to claim 29, characterized in that, The installation code response also carries a second random number generated by the device platform cloud.
33. The method according to any one of claims 29 to 32, characterized in that, The method further includes: The system receives an authentication device request. The source address of the authentication device request is the distribution platform gateway. The authentication device request carries a device address identifier and a device authentication key. The device authentication key is a key generated by the device to be authenticated based on a second random number. The second random number is generated by the device platform cloud. The device address identifier is used to identify the MAC address of the device to be authenticated. The device-side authentication key is used for second access authentication based on the second random number.
34. The method according to claim 33, characterized in that, The step of performing second access authentication on the device-side authentication key based on the second random number includes: Based on the device address identifier, determine the license key corresponding to the device to be authenticated; A third key generation algorithm is used to process the second random number and the permission key to generate a cloud authentication key; The cloud authentication key and the device authentication key are verified to determine the authentication result.
35. The method according to claim 34, characterized in that, The third key generation algorithm includes the AES-MMO hash algorithm.
36. The method according to claim 34, characterized in that, The method further includes: The authentication result is sent, and the destination address of the authentication result is the distribution network platform gateway.
37. An access authentication device, characterized in that, Applied to devices to be authenticated, the device includes: a beacon frame broadcasting module, a key generation module, and a first authentication module; The beacon frame broadcasting module is used to broadcast beacon frames, which carry a first random number generated by the device to be authenticated. The key generation module is used to generate a device-side trust center link key based on the first random number and the permission key, wherein the permission key is a key stored in the device to be authenticated and the device platform cloud. The first authentication module is used to perform a first access authentication with the distribution network platform gateway using the device-side trust center link key. Specifically, it receives encryption key information sent by the distribution network platform gateway, which is encrypted by the distribution network platform gateway based on the authentication-side trust center link key. The authentication-side trust center link key is generated by the distribution network platform gateway or the device platform cloud. The module then processes the encryption key information using the device-side trust center link key to obtain a network key, which is used to encrypt data at the network layer after the first access authentication. The device platform cloud is the cloud server corresponding to the manufacturer to which the device to be certified belongs, and the device to be certified is configured to enter the network by the distribution network platform gateway.
38. The apparatus according to claim 37, characterized in that, The device further includes: a device declaration broadcast module; The device declaration broadcast module is used to broadcast a device declaration message, which indicates that the device to be authenticated has been connected to the network constructed by the distribution network platform gateway.
39. The apparatus according to claim 37 or 38, characterized in that, The key generation module is used to process the first random number and the license key using a first key generation algorithm to generate a device-side installation code, and use the device-side installation code as the device-side trust center link key. or, The key generation module is used to process the first random number and the license key using a first key generation algorithm to generate a device-side installation code; and to process the device-side installation code using a second key generation algorithm to generate the device-side trust center link key.
40. The apparatus according to claim 39, characterized in that, The first key generation algorithm includes: Advanced Encryption Standard (AES)-MMO hash algorithm; The second key generation algorithm includes the AES-MMO hash algorithm.
41. The apparatus according to claim 37 or 38, characterized in that, The beacon frame is an enhanced beacon frame, and the first random number is filled into the header information unit field of the enhanced beacon frame.
42. The apparatus according to claim 41, characterized in that, The beacon frame broadcasting module is used to broadcast the enhanced beacon frame; or, The beacon frame broadcasting module is used to alternately broadcast the enhanced beacon frames and the regular beacon frames.
43. The apparatus according to claim 37 or 38, characterized in that, The beacon frame also carries a device identifier, which is used to identify the type of the device to be authenticated.
44. The apparatus according to claim 37 or 38, characterized in that, The beacon frame also carries a manufacturer identifier, which is used to identify the manufacturer to which the device to be authenticated belongs.
45. The apparatus according to claim 37 or 38, characterized in that, The beacon frame also carries a device address identifier, which is used to identify the Media Access Control (MAC) address of the device to be authenticated.
46. The apparatus according to claim 37 or 38, characterized in that, The device further includes: a beacon response receiving module and an association module; The beacon response receiving module is used to receive the beacon response sent by the distribution network platform gateway, and the beacon response is used to respond to the beacon frame; The association module is used to send an association request to the distribution network platform gateway, the association request being used to request access to the network constructed by the distribution network platform gateway; and to receive an association response sent by the distribution network platform gateway, the association response being used to respond to the association request.
47. The apparatus according to claim 37 or 38, characterized in that, The device further includes: a second authentication module; the second authentication module is used for, A device authentication key is generated based on a second random number generated by the device platform cloud. The device authentication key is used for the second access authentication of the device to be authenticated. Send the device-side authentication key to the distribution network platform gateway.
48. The apparatus according to claim 47, characterized in that, The second authentication module is used to process the second random number and the permission key using a third key generation algorithm to generate the device-side authentication key.
49. The apparatus according to claim 48, characterized in that, The third key generation algorithm includes the AES-MMO hash algorithm.
50. The apparatus according to claim 47, characterized in that, The device further includes: a request receiving module; The request receiving module is used to receive a random number write request sent by the distribution network platform gateway to the custom cluster of the device to be authenticated, wherein the random number write request carries the second random number.
51. The apparatus according to claim 50, characterized in that, The device further includes: a key storage module; The key storage module is used to store the device-side authentication key in the attributes of the custom cluster.
52. The apparatus according to claim 50, characterized in that, The access type for the custom cluster is write-back.
53. An access authentication device, characterized in that, The device is used in a distribution network platform gateway, which supports network construction. The cloud server corresponding to the distribution network platform gateway is the distribution network platform cloud. The device includes: a beacon frame receiving module, a key determination module, and a first authentication module. The beacon frame receiving module is used to receive beacon frames broadcast by the device to be authenticated, the beacon frames carrying a first random number generated by the device to be authenticated; The key determination module is used to interact with the device platform cloud through the distribution network platform cloud to obtain the authentication end trust center link key. The authentication end trust center link key is a key generated based on the first random number and the permission key. The permission key is a key stored in the device to be authenticated and the device platform cloud. The first authentication module is used to perform a first access authentication with the device to be authenticated using the authentication end trust center link key, wherein the module sends encryption key information to the device to be authenticated. The encryption key information is obtained by encrypting a network key based on the authentication end trust center link key. The network key is used to encrypt data at the network layer after the first access authentication. The device platform cloud is the cloud server corresponding to the manufacturer to which the device to be certified belongs, and the device to be certified is configured to enter the network by the distribution network platform gateway.
54. The apparatus according to claim 53, characterized in that, The device further includes: a device declaration receiving module; The device declaration receiving module is used to receive a device declaration message sent by the device to be authenticated, the device declaration message indicating that the device to be authenticated has been connected to the network constructed by the distribution network platform gateway.
55. The apparatus according to claim 53 or 54, characterized in that, The beacon frame also carries a device address identifier of the device to be authenticated, which identifies the Media Access Control (MAC) address of the device to be authenticated; the key determination module is used to... The installation code request is sent to the device platform cloud through the distribution network platform cloud. The installation code request carries the device address identifier and the first random number. The first random number is used by the device platform cloud to generate the authentication terminal installation code. The system receives an installation code response with the source address of the device platform cloud via the distribution network platform cloud. Based on the installation code response, the authentication end trust center link key is determined.
56. The apparatus according to claim 55, characterized in that, The installation code response carries the authentication terminal installation code; The key determination module is used to use the authentication terminal installation code as the authentication terminal trust center link key; or, The key determination module is used to process the authentication terminal installation code using a second key generation algorithm to generate the authentication terminal trust center link key.
57. The apparatus according to claim 56, characterized in that, The second key generation algorithm includes: Advanced Encryption Standard (AES)-MMO hash algorithm.
58. The apparatus according to claim 55, characterized in that, The installation code response also carries a second random number generated by the device platform cloud.
59. The apparatus according to claim 53 or 54, characterized in that, The apparatus further includes: an authentication request module; the authentication request module is used to, Send a random number write request to the custom cluster of the device to be authenticated. The random number write request carries a second random number, which is obtained by the distribution network platform gateway from the installation code response with the source address of the device platform cloud. Receive the device authentication key sent by the device to be authenticated, the device authentication key being used for the second access authentication of the device to be authenticated; The network distribution platform cloud sends an authentication device request to the device platform cloud. The authentication device request carries a device address identifier and the device authentication key. The device address identifier is used to identify the MAC address of the device to be authenticated.
60. The apparatus according to claim 59, characterized in that, The authentication request module is used to obtain the access type of the custom cluster; in response to the access type of the custom cluster being write-back, it sends the random number write request to the custom cluster.
61. The apparatus according to claim 59, characterized in that, The device further includes: an authentication result processing module; the authentication result processing module is used for, The authentication result with the source address of the device platform cloud is received through the distribution network platform cloud; In response to the authentication result being successful, the authentication end trust center link key is updated; In response to the authentication result being authentication failure, the device to be authenticated is added to the device blacklist, which is used to record devices that fail to configure the network.
62. The apparatus according to claim 53 or 54, characterized in that, The device further includes: a beacon response transmission module and an association module; The beacon response sending module is used to send a beacon response to the device to be authenticated, and the beacon response is used to respond to the beacon frame; The association module is used to receive an association request sent by the device to be authenticated, the association request being used to request access to the network constructed by the distribution network platform gateway; and to send an association response to the device to be authenticated, the association response being used to respond to the association request.
63. The apparatus according to claim 53 or 54, characterized in that, The beacon frame also carries a device identifier, which identifies the type of the device to be authenticated. The apparatus further includes an access request receiving module; the access request receiving module is used for... Send the device identifier to the control device, which is used to control the distribution network platform gateway; The system receives an access request sent by the control device. The access request is used to trigger the distribution network platform gateway to send a beacon response. The beacon response is used to respond to the beacon frame.
64. The apparatus according to claim 53 or 54, characterized in that, The beacon frame is an enhanced beacon frame, and the first random number is filled into the header information unit field of the enhanced beacon frame.
65. An access authentication device, characterized in that, The device is used in a device platform cloud, which is the cloud server of the manufacturer to which the device to be authenticated belongs. The device includes: a key determination module. The key determination module is used to interact with the distribution network platform gateway, enabling the distribution network platform gateway to obtain the authentication end trust center link key. The authentication end trust center link key is a key generated based on a first random number generated by the device to be authenticated. The authentication end trust center link key is used for the first access authentication of the device to be authenticated. Specifically, it receives an installation code request, the source address of which is the distribution network platform gateway. The installation code request carries a device address identifier corresponding to the device to be authenticated and the first random number. The device address identifier is used to identify the Media Access Control (MAC) address of the device to be authenticated. Based on the first random number, it generates an authentication end installation code. It then sends an installation code response, the destination address of which is the distribution network platform gateway. The installation code response carries the authentication end installation code, which is used by the distribution network platform gateway to determine the authentication end trust center link key. The device to be authenticated is configured to join the network by the distribution network platform gateway.
66. The apparatus according to claim 65, characterized in that, The key determination module is used for, Based on the device address identifier, determine the license key corresponding to the device to be authenticated; The first key generation algorithm is used to process the first random number and the permission key to generate the authentication terminal installation code.
67. The apparatus according to claim 66, characterized in that, The first key generation algorithm includes: Advanced Encryption Standard (AES-MMO) hash algorithm.
68. The apparatus according to claim 65, characterized in that, The installation code response also carries a second random number generated by the device platform cloud.
69. The apparatus according to any one of claims 65 to 68, characterized in that, The device further includes: a second authentication module; the second authentication module is used for, The system receives an authentication device request. The source address of the authentication device request is the distribution platform gateway. The authentication device request carries a device address identifier and a device authentication key. The device authentication key is a key generated by the device to be authenticated based on a second random number. The second random number is generated by the device platform cloud. The device address identifier is used to identify the MAC address of the device to be authenticated. The device-side authentication key is used for second access authentication based on the second random number.
70. The apparatus according to claim 69, characterized in that, The second authentication module is used for, Based on the device address identifier, determine the license key corresponding to the device to be authenticated; A third key generation algorithm is used to process the second random number and the permission key to generate a cloud authentication key; The cloud authentication key and the device authentication key are verified to determine the authentication result.
71. The apparatus according to claim 70, characterized in that, The third key generation algorithm includes the AES-MMO hash algorithm.
72. The apparatus according to claim 70, characterized in that, The device further includes: an authentication result sending module; The authentication result sending module is used to send the authentication result, and the destination address of the authentication result is the distribution network platform gateway.
73. A device to be certified, characterized in that, The device to be authenticated includes: a processor and a transceiver connected to the processor; wherein, The transceiver is used to broadcast beacon frames, which carry a first random number generated by the device to be authenticated. The processor is configured to generate a device-side trust center link key based on the first random number and the permission key, wherein the permission key is a key stored in the device to be authenticated and the device platform cloud. The processor is configured to perform a first access authentication with the distribution network platform gateway using the device-side trust center link key, wherein it receives encryption key information sent by the distribution network platform gateway, the encryption key information being encrypted by the distribution network platform gateway according to the authentication end trust center link key, the authentication end trust center link key being generated by the distribution network platform gateway or the device platform cloud; and processes the encryption key information using the device-side trust center link key to obtain a network key, the network key being used to encrypt data at the network layer after the first access authentication; The device platform cloud is the cloud server corresponding to the manufacturer to which the device to be certified belongs, and the device to be certified is configured to enter the network by the distribution network platform gateway.
74. A distribution network platform gateway, characterized in that, The distribution network platform gateway supports network construction, and the cloud server corresponding to the distribution network platform gateway is the distribution network platform cloud. The distribution network platform gateway includes: a processor and a transceiver connected to the processor; wherein... The transceiver is used to receive beacon frames broadcast by the device to be authenticated, the beacon frames carrying a first random number generated by the device to be authenticated; The processor is used to interact with the device platform cloud through the distribution network platform cloud to obtain the authentication end trust center link key. The authentication end trust center link key is a key generated based on the first random number and the permission key. The permission key is a key stored in the device to be authenticated and the device platform cloud. The processor is configured to use the authentication end trust center link key to perform a first access authentication with the device to be authenticated, wherein it sends encryption key information to the device to be authenticated. The encryption key information is information obtained by encrypting a network key based on the authentication end trust center link key. The network key is used to encrypt data at the network layer after the first access authentication. The device platform cloud is the cloud server corresponding to the manufacturer to which the device to be certified belongs, and the device to be certified is configured to enter the network by the distribution network platform gateway.
75. A device platform cloud, characterized in that, The device platform cloud is the cloud server of the manufacturer to which the device to be certified belongs. The device platform cloud includes: a processor and a transceiver connected to the processor; wherein, The processor is configured to interact with the distribution network platform gateway, enabling the distribution network platform gateway to obtain the authentication end trust center link key. The authentication end trust center link key is a key generated based on a first random number generated by the device to be authenticated. The authentication end trust center link key is used for the first access authentication of the device to be authenticated. The processor includes receiving an installation code request, the source address of which is the distribution network platform gateway. The installation code request carries a device address identifier corresponding to the device to be authenticated and the first random number. The device address identifier is used to identify the Media Access Control (MAC) address of the device to be authenticated. Based on the first random number, an authentication end installation code is generated. An installation code response is sent, the destination address of which is the distribution network platform gateway. The installation code response carries the authentication end installation code, which is used by the distribution network platform gateway to determine the authentication end trust center link key. The device to be authenticated is configured to join the network by the distribution network platform gateway.
76. A computer-readable storage medium, characterized in that, The readable storage medium stores a computer program, which is loaded and executed by a processor to implement the access authentication method as described in any one of claims 1 to 36.
Citation Information
Patent Citations
Wireless local area network authentication method and wireless local area network connection method
CN111866881A
Method and apparatus for authenticatiing a network device
US20120124373A1