Authentication method of device, communication system, device, and storage medium

By using gateway devices to authenticate the certificates and identifiers of managed devices, and by employing timing checks and random number authentication, the security risks of terminals diagnosing in-vehicle devices through gateway devices are resolved, thereby improving the security of the access process and the stability of the connection.

CN116545644BActive Publication Date: 2026-02-13CHONGQING CHANGAN AUTOMOBILE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310265183.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-16
Publication Date
2026-02-13
Estimated Expiration
2043-03-16

AI Technical Summary

Technical Problem

There are security risks when the terminal diagnoses the vehicle-mounted equipment through the gateway device. How can we improve the security of the process of the management device accessing the managed device?

Method used

The gateway device authenticates itself by receiving the certificate and identifier from the management device, and opens the port address after successful authentication, thus establishing a connection between the management device and the target device. At the same time, it ensures the security of the connection through timing checks and random number authentication.

Benefits of technology

It improves the security of the process of management devices accessing managed devices, ensures the stability of connection status and device identity verification, and reduces the risk of information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116545644B_ABST
    Figure CN116545644B_ABST
Patent Text Reader

Abstract

The application relates to an authentication method of a device, a communication system, a device and a storage medium, and relates to the technical field of vehicle diagnosis. The method comprises the following steps: a gateway device receives a first request message from a management device, the first request message is used for requesting access to a target device to be managed, and the first request message comprises a first certificate. If the first certificate is the same as a preset certificate, address information of a first port is determined, the first port is a port in the gateway device, the first port is connected with a second port, and the second port is a port of the gateway device connected with the target device to be managed. The gateway device sends the address information of the first port to the management device. The gateway device receives a connection message from the management device, and the connection message is used for indicating that the management device is successfully connected with the first port. Therefore, the security of a process in which the management device accesses the device to be managed can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of vehicle diagnosis, in particular to a device authentication method, a communication system, a device and a storage medium. BACKGROUND

[0002] In recent years, with the increase of automobile functions, more and more vehicle-mounted devices (such as vehicle-mounted audio, vehicle recorders, etc.) are used, and the management requirements of management devices (such as terminals, servers, etc.) on vehicle-mounted devices are also increasing. For example, a terminal diagnoses the state of a vehicle recorder through a gateway device.

[0003] Currently, when the terminal diagnoses the state of the vehicle recorder through the gateway device, the terminal needs to send a request message to the gateway device to diagnose the state of the vehicle recorder. Then, the gateway device responds to the request message from the terminal to open the port of the vehicle recorder for the terminal to access. Then, the terminal accesses the vehicle recorder through the port opened by the gateway device and diagnoses the state of the vehicle recorder. However, in the above technical solution, the process of the terminal diagnosing the state of the vehicle recorder through the gateway device may have security risks. Therefore, how to improve the security of the process of the management device accessing the device to be managed has become a technical problem to be solved. SUMMARY

[0004] The present application provides a device authentication method, a communication system, a device and a storage medium to at least solve the technical problem of low security of the process of the management device accessing the device to be managed in the related art. The technical solution of the present application is as follows:

[0005] According to a first aspect of the present application, a device authentication method is provided, applied to a gateway device, the gateway device storing a preset certificate, the gateway device being connected with a target device to be managed. The device authentication method comprises: the gateway device receives a first request message from a management device, the first request message being used to request to access the target device to be managed, the first request message comprising a first certificate. If the first certificate is the same as the preset certificate, the gateway device determines address information of a first port, the first port being a port in the gateway device, and the first port being connected with a second port, the second port being a port of the gateway device connected with the target device to be managed. The gateway device sends the address information of the first port to the management device. The gateway device receives a connection message from the management device, the connection message being used to indicate that the management device is successfully connected with the first port.

[0006] According to the above technical means, the gateway device can receive a first request message from the management device, the first request message being used to request access to a target to-be-managed device, and the first request message comprising: a first certificate and an identifier of the target to-be-managed device. Then, the gateway device can determine whether the first certificate is the same as a preset certificate. If it is determined that the first certificate is the same as the preset certificate, the gateway device determines address information of a first port, the first port being a port in the gateway device and being connected to a second port, the second port being a port of the gateway device connected to the target to-be-managed device. Then, the gateway device can send the address information of the first port to the management device. In addition, the gateway device can receive a connection message from the management device, the connection message being used to indicate that the management device is successfully connected to the first port. That is, the identity of the management device is authenticated by the gateway device, and the service of the target to-be-managed device accessed by the management device is managed. In this way, the security of the process of the management device accessing the to-be-managed device can be improved.

[0007] In a possible implementation, after the gateway device receives the connection message from the management device, the device authentication method further comprises: the gateway device sends a target instruction to the management device, the target instruction being used to instruct the management device to send a response message at a preset time. If the response message from the management device is not received at the preset time, the gateway device closes the first port.

[0008] According to the above technical means, the gateway device can determine the connection state of the management device and the gateway device by determining whether the management device sends the response message at the preset time, so that the management device and the gateway device maintain a safe connection state. In this way, the security of the connection between the management device and the gateway device can be improved.

[0009] In a possible implementation, the response message comprises a second certificate, and the device authentication method further comprises: if the response message from the management device is received at the preset time, and the second certificate is not the same as the preset certificate, the gateway device closes the first port.

[0010] According to the above technical means, the gateway device can determine the connection state of the management device and the gateway device by determining whether the second certificate is the same as the preset certificate in the case where it is determined that the management device sends the response message at the preset time, so that the management device and the gateway device maintain a safe connection state. In this way, the security of the connection between the management device and the gateway device can be improved.

[0011] In a possible implementation, the gateway device further stores target key information. After the gateway device receives the first request message from the management device, the method further includes: the gateway device sends a second request message to the target device to be managed, the second request message being used to request a target credential, the target credential being used to access the target device to be managed. The gateway device receives a target random number from the target device to be managed. The gateway device generates a target authentication code based on the target key information and the target random number, and sends the target authentication code to the target device to be managed. The method of determining the address information of the first port includes: if the first certificate is the same as the preset certificate and the target credential from the target device to be managed is received, the gateway device determines the address information of the first port.

[0012] According to the above technical means, the gateway device can generate an authentication code for proving the identity of the device according to the random number from the target device to be managed and the stored key information, and send the authentication code for proving the identity of the device to the target device to be managed. Then, the gateway device can manage the service of the target device to be managed by the management device by determining whether the target credential from the target device to be managed is received. In this way, the security of the process of the management device accessing the device to be managed can be improved.

[0013] According to the second aspect of the present application, a device authentication method is provided, which is applied to a target device to be managed, and the target device to be managed stores target key information. The device authentication method includes: the target device to be managed receives a second request message from a gateway device, the second request message being used to request a target credential, the target credential being used to access the target device to be managed. The target device to be managed generates a target random number in response to the second request message, and sends the target random number to the gateway device. The target device to be managed receives a target authentication code from the gateway device. The target device to be managed determines whether the target authentication code is composed of the target random number according to the target key information. If it is determined that the target authentication code is composed of the target random number, the target device to be managed sends the target credential to the gateway device.

[0014] According to a third aspect provided in the present application, an authentication apparatus of a device is provided, which is applied to a gateway device, the gateway device storing a preset certificate, and the gateway device being connected with a target device to be managed. The authentication apparatus of the device comprises a sending module, a receiving module and a processing module. The receiving module is configured to receive a first request message from a management device, the first request message being used to request access to the target device to be managed, and the first request message comprising a first certificate. The processing module is configured to determine address information of a first port if the first certificate is the same as the preset certificate, the first port being a port in the gateway device, and the first port being connected with a second port, the second port being a port of the gateway device connected with the target device to be managed. The sending module is configured to send the address information of the first port to the management device. The receiving module is further configured to receive a connection message from the management device, the connection message being used to indicate that the management device is successfully connected with the first port.

[0015] In a possible implementation, the sending module is further configured to send a target instruction to the management device, the target instruction being used to instruct to send a response message at a preset time. The processing module is further configured to close the first port if the response message from the management device is not received at the preset time.

[0016] In a possible implementation, the response message comprises a second certificate. The processing module is further configured to close the first port if the response message from the management device is received at the preset time, and the second certificate is not the same as the preset certificate.

[0017] In a possible implementation, the gateway device further stores target key information. The sending module is further configured to send a second request message to the target device to be managed, the second request message being used to request to obtain a target credential, the target credential being used to access the target device to be managed. The receiving module is further configured to receive a target random number from the target device to be managed. The processing module is further configured to generate a target authentication code based on the target key information and the target random number, and send the target authentication code to the target device to be managed. The processing module is specifically configured to determine the address information of the first port if the first certificate is the same as the preset certificate, and the target credential from the target device to be managed is received.

[0018] According to a fourth aspect provided by the present application, an authentication apparatus of a device is provided, and is applied to a target device to be managed, the target device to be managed storing target key information. The authentication apparatus of the device comprises a receiving module, a processing module and a sending module. The receiving module is configured to receive a second request message from a gateway device, the second request message being used to request a target credential, the target credential being used to access the target device to be managed. The processing module is configured to generate a target random number in response to the second request message. The sending module is configured to send the target random number to the gateway device. The receiving module is further configured to receive a target authentication code from the gateway device. The processing module is further configured to determine whether the target authentication code is composed of the target random number according to the target key information. The sending module is further configured to send the target credential to the gateway device if it is determined that the target authentication code is composed of the target random number.

[0019] According to a fifth aspect provided by the present application, an electronic device is provided, comprising a processor, and a memory for storing processor-executable instructions. The processor is configured to execute the instructions to implement the method of the first aspect and any possible implementation thereof.

[0020] According to a sixth aspect provided by the present application, a computer-readable storage medium is provided, and when instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform the method of the first aspect and any possible implementation thereof.

[0021] According to a seventh aspect provided by the present application, a computer program product is provided, and the computer program product comprises computer instructions, and when the computer instructions are run on an electronic device, the electronic device performs the method of the first aspect and any possible implementation thereof.

[0022] Therefore, the above technical features of the present application have the following beneficial effects:

[0023] (1) The gateway device can receive a first request message from the management device, the first request message being used to request access to a target to-be-managed device, the first request message comprising: a first certificate and an identifier of the target to-be-managed device. Then, the gateway device can determine whether the first certificate is the same as a preset certificate. If it is determined that the first certificate is the same as the preset certificate, the gateway device determines address information of a first port, the first port being a port in the gateway device and connected to a second port, the second port being a port of the gateway device connected to the target to-be-managed device. Then, the gateway device can send the address information of the first port to the management device. In addition, the gateway device can receive a connection message from the management device, the connection message being used to indicate that the management device is successfully connected to the first port. That is, the identity of the management device is authenticated by the gateway device, and the service of the target to-be-managed device accessed by the management device is managed. In this way, the security of the process of the management device accessing the to-be-managed device can be improved.

[0024] (2) The gateway device can determine the connection state of the management device and the gateway device by determining whether the management device sends a response message at a preset time, so that the management device and the gateway device maintain a safe connection state. In this way, the security of the connection between the management device and the gateway device can be improved.

[0025] (3) The gateway device can determine the connection state of the management device and the gateway device by determining whether the second certificate is the same as the preset certificate in the case where it is determined that the management device sends a response message at a preset time, so that the management device and the gateway device maintain a safe connection state. In this way, the security of the connection between the management device and the gateway device can be improved.

[0026] (4) The gateway device can generate an authentication code for proving the identity of the device according to a random number from the target to-be-managed device and stored key information, and send the authentication code for proving the identity of the device to the target to-be-managed device. Then, the gateway device can manage the service of the target to-be-managed device accessed by the management device by determining whether a target credential from the target to-be-managed device is received. In this way, the security of the process of the management device accessing the to-be-managed device can be improved.

[0027] It should be noted that the technical effects brought by any one of the implementation manners of the second aspect to the seventh aspect can refer to the technical effects brought by the corresponding implementation manners in the first aspect, which will not be repeated here.

[0028] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF DRAWINGS

[0029] The accompanying drawings, which are incorporated herein and constitute part of this specification, illustrate implementations of the application and, together with the description, further serve to explain the principles of the application and, do not limit the application.

[0030] Figure 1 is a schematic diagram of a communication system according to an example embodiment;

[0031] Figure 2 is a flowchart of a method of authenticating a device according to an example embodiment;

[0032] Figure 3 is a flowchart of a method of authenticating a device according to an example embodiment;

[0033] Figure 4 is a flowchart of a method of authenticating a device according to an example embodiment;

[0034] Figure 5 is a flowchart of a method of authenticating a device according to an example embodiment;

[0035] Figure 6 is a flowchart of a method of authenticating a device according to an example embodiment;

[0036] Figure 7 is a flowchart of a method of authenticating a device according to an example embodiment;

[0037] Figure 8 is a flowchart of a method of authenticating a device according to an example embodiment;

[0038] Figure 9 is a block diagram of an authentication apparatus of a device according to an example embodiment;

[0039] Figure 10 is a block diagram of an authentication apparatus of a device according to an example embodiment;

[0040] Figure 11 is a block diagram of an electronic device according to an example embodiment. DETAILED DESCRIPTION

[0041] Other advantages and effects of the present application will be easily understood by those skilled in the art from the above description of the embodiments of the present application. The present application can also be implemented or applied in other different embodiments, and the details in the specification can be modified or changed based on different views and applications without departing from the spirit of the present application. It should be understood that the preferred embodiments are only for illustrating the present application, but not for limiting the protection scope of the present application.

[0042] It should be noted that the diagrams provided in the following embodiments only schematically illustrate the basic concept of the present application, and only the components related to the present application are shown in the diagrams, but not drawn according to the number, shape and size of the components in actual implementation. The shapes, number and proportions of the components in actual implementation can be arbitrarily changed, and the layout pattern of the components can be more complex.

[0043] Before the authentication method of the device provided by the embodiments of the present application is described in detail, the implementation environment and application scenario of the embodiments of the present application are introduced.

[0044] Firstly, the application scenario of the embodiments of the present application is introduced.

[0045] The authentication method of the device of the embodiments of the present application is applied to the diagnosis scenario of the vehicle-mounted device. In the related technology, when the terminal diagnoses the state of the vehicle event data recorder through the gateway device, the terminal needs to send a request message for diagnosing the state of the vehicle event data recorder to the gateway device. Then, the gateway device opens the port for accessing the vehicle event data recorder to the terminal in response to the request message from the terminal. Then, the terminal accesses the vehicle event data recorder through the port opened by the gateway device, and diagnoses the state of the vehicle event data recorder.

[0046] In summary, in the current technical solution, the process of diagnosing the state of the vehicle event data recorder by the terminal through the gateway device may have security risks. Therefore, how to improve the security of the process of the management device accessing the vehicle-mounted device has become a technical problem to be solved.

[0047] In order to solve the above problems, the embodiments of the present application provide an authentication method of a device. The gateway device can receive a request message for accessing the to-be-managed device from the management device, and the request message includes the device certificate of the management device. Then, the gateway device can perform identity authentication on the management device by determining whether the device certificate of the management device is a certificate issued by the gateway device. If the gateway device determines that the device certificate of the management device is a certificate issued by the gateway device, the gateway device opens the port for accessing the to-be-managed device to the management device. That is, the identity authentication of the management device by the gateway device manages the access service of the management device to the to-be-managed device. In this way, the security of the process of the management device accessing the to-be-managed device can be improved.

[0048] The implementation environment of the embodiments of the present application is introduced as follows.

[0049] As shown in Figure 1 A communication system provided by the embodiments of the present application includes a management device (such as terminal 101), a gateway device 102, and at least one target device to be managed (such as vehicle-mounted device 103 and vehicle-mounted device 104). The gateway device 102 can perform wired / wireless communication with the terminal 101, the vehicle-mounted device 103, and the vehicle-mounted device 104, respectively.

[0050] Specifically, the terminal 101 can receive an operation instruction of a user and send a request message for accessing the vehicle-mounted device 103 to the gateway device 102. The gateway device 102 can receive the request message for accessing the vehicle-mounted device 103 from the terminal 101 and perform identity authentication on the terminal 101. If the identity authentication on the terminal 101 succeeds, the gateway device 102 sends a port address for accessing the vehicle-mounted device 103 in the gateway device 102 to the terminal 101. Moreover, the gateway device 102 can send a request message for obtaining a credential for accessing the vehicle-mounted device 103 to the vehicle-mounted device 103. Then, the vehicle-mounted device 103 can perform identity authentication on the gateway device 102. If the identity authentication on the gateway device 102 succeeds, the vehicle-mounted device 103 sends the credential for accessing the vehicle-mounted device 103 to the gateway device 102. Then, the terminal 101 can access the vehicle-mounted device 103 through the gateway device 102 with the credential for accessing the vehicle-mounted device 103 according to the port address for accessing the vehicle-mounted device 103 in the gateway device 102.

[0051] Similarly, the terminal 101 can also receive an operation instruction of a user and send a request message for accessing the vehicle-mounted device 104 to the gateway device 102. The gateway device 102 can receive the request message for accessing the vehicle-mounted device 104 from the terminal 101 and perform identity authentication on the terminal 101. If the identity authentication on the terminal 101 succeeds, the gateway device 102 sends a port address for accessing the vehicle-mounted device 104 in the gateway device 102 to the terminal 101. Moreover, the gateway device 102 can send a request message for obtaining a credential for accessing the vehicle-mounted device 104 to the vehicle-mounted device 104. Then, the vehicle-mounted device 104 can perform identity authentication on the gateway device 102. If the identity authentication on the gateway device 102 succeeds, the vehicle-mounted device 104 sends the credential for accessing the vehicle-mounted device 104 to the gateway device 102. Then, the terminal 101 can access the vehicle-mounted device 104 through the gateway device 102 with the credential for accessing the vehicle-mounted device 104 according to the port address for accessing the vehicle-mounted device 104 in the gateway device 102.

[0052] It should be noted that in the embodiments of the present application, the terminal (such as the terminal 101) can be a mobile phone, a tablet computer, a desktop computer, a laptop computer, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, etc. with a transceiving function, and the present application does not specially limit the specific form of the terminal. The terminal can perform human-computer interaction with a user through one or more of a keyboard, a touchpad, a touch screen, a remote controller, voice interaction, a handwriting device, etc.

[0053] The gateway device (such as the gateway device 102) can be an inter-network connector, or can also be a negotiation converter. Alternatively, the gateway device can also be a network switch. Alternatively, the gateway device can also be a router. The embodiments of the present application do not limit the specific implementation mode of the gateway device.

[0054] The vehicle-mounted device (such as the vehicle-mounted device 103, the vehicle-mounted device 104) can be a car audio. Alternatively, the vehicle-mounted device can be a car data recorder. Alternatively, the vehicle-mounted device can be a car charger. The embodiments of the present application do not limit the vehicle-mounted device.

[0055] For ease of understanding, the authentication method of the device provided by the present application is specifically introduced below in combination with the accompanying drawings.

[0056] Figure 2 is a flowchart of an authentication method of a device according to an exemplary embodiment, as shown in Figure 2 The authentication method of the device includes the following steps: S201-S209.

[0057] S201, the management device sends a first request message to the gateway device.

[0058] The first request message is used to request access to a target to-be-managed device.

[0059] In a possible implementation, the management device can receive an operation instruction input by a user to access a target to-be-managed device, and based on the operation instruction input by the user to access the target to-be-managed device, the management device sends a first request message to the gateway device.

[0060] In a possible implementation, the management device stores a first certificate, and the first certificate is used to authenticate the identity of the management device. In response to receiving the operation instruction input by the user to access the target to-be-managed device, the management device can generate a first request message according to the first certificate and the identifier of the target to-be-managed device, and send the first request message to the gateway device. The first request message can include the first certificate and the identifier of the target to-be-managed device.

[0061] S202, the gateway device receives the first request message from the management device.

[0062] S203. The gateway device determines whether the first certificate is the same as the preset certificate.

[0063] In one possible implementation, the gateway device stores a preset certificate, which is a certificate that allows connections to the gateway device. The gateway device can determine whether the first certificate is the same as the preset certificate based on the preset certificate.

[0064] In one possible design, the gateway device stores an authentication root certificate, and a default certificate is a device certificate issued by the gateway device based on the authentication root certificate. The gateway device can determine whether the first certificate is a device certificate issued by the gateway device based on the authentication root certificate, and thus determine whether the first certificate is the same as the default certificate.

[0065] In other words, the gateway device can determine whether the management device is a device that is allowed to connect to the gateway device by checking whether the first certificate is the same as the preset certificate, thereby authenticating the identity of the management device.

[0066] In some embodiments, if the gateway device determines that the first certificate is different from the preset certificate, the gateway device sends a first prompt message to the management device. The first prompt message is used to indicate that the identity authentication failed.

[0067] In other embodiments, if the gateway device determines that the first certificate is the same as the preset certificate, the gateway device executes S204.

[0068] S204. The gateway device determines the second port based on the identifier of the target device to be managed.

[0069] The gateway device is connected to the target device to be managed, and the second port is the port through which the gateway device connects to the target device to be managed.

[0070] In one possible implementation, the gateway device is connected to multiple preset managed devices. The gateway device can determine the target managed device from the multiple preset managed devices based on the identifier of the target managed device, and determine the second port based on the connection relationship between the gateway device and the target managed device.

[0071] S205. The gateway device determines the address information of the first port based on the second port.

[0072] The first port is a port in the gateway device, and the first port is connected to the second port.

[0073] In one possible implementation, the gateway device includes multiple unused ports. The gateway device may select one of the multiple unused ports as the first port to connect to the second port, and determine the address information of the first port.

[0074] That is, the first port is a port opened by the gateway device for accessing the target device to be managed, and the gateway device can provide a service for accessing the target device to be managed through the first port.

[0075] S206, the gateway device sends address information of the first port to the management device.

[0076] Correspondingly, the management device can receive the address information of the first port from the gateway device, and perform S207.

[0077] S207, the management device connects the first port according to the address information of the first port.

[0078] In some embodiments, after the management device establishes a connection relationship with the first port, the management device can perform S208.

[0079] S208, the management device sends a connection message to the gateway device.

[0080] The connection message is used to indicate that the management device is successfully connected with the first port.

[0081] S209, the gateway device receives the connection message from the management device.

[0082] The above-mentioned embodiments provide at least the following beneficial effects: the management device can send a first request message to the gateway device, the first request message is used to request to access the target device to be managed, and the first request message includes: a first certificate and an identifier of the target device to be managed. The gateway device can receive the first request message from the management device, and determine whether the first certificate is the same as a preset certificate. If the gateway device determines that the first certificate is the same as the preset certificate, the gateway device determines a second port according to the identifier of the target device to be managed, and determines address information of the first port according to the second port, the second port is a port of the gateway device connecting the target device to be managed, the first port is a port in the gateway device, and the first port is connected with the second port. Then, the gateway device can send the address information of the first port to the management device. The management device can receive the address information of the first port from the gateway device, and connect the first port according to the address information of the first port. Then, the management device can send a connection message to the gateway device, the connection message is used to indicate that the management device is successfully connected with the first port. And, the gateway device can receive the connection message from the management device. That is, the identity authentication of the gateway device to the management device is used to manage the service of the management device accessing the target device to be managed. In this way, the security of the process of the management device accessing the device to be managed can be improved.

[0083] In some embodiments, in order to detect the connection state of the management device and the gateway device, such as Figure 3As shown, after the gateway device receives the connection message from the management device (i.e., S209), the authentication method of the device provided by the embodiments of the present application further includes the following steps: S301-S305.

[0084] S301, the gateway device sends a target instruction to the management device.

[0085] The target instruction is used to instruct sending a response message at a preset time.

[0086] Correspondingly, the management device can receive the target instruction from the gateway device, and in response to the target instruction, perform S302.

[0087] S302, the management device sends a response message to the gateway device.

[0088] Correspondingly, the gateway device can receive the response message from the gateway device, and perform S303.

[0089] S303, the gateway device determines whether the response message from the management device is received at the preset time.

[0090] In one possible implementation, the gateway device can determine the time of receiving the response message from the management device, and determine whether the response message from the management device is received at the preset time according to the preset time.

[0091] In some embodiments, the response message can include a second certificate. If the gateway device determines that the response message from the management device is received at the preset time, the gateway device performs S304.

[0092] S304, the gateway device determines whether the second certificate is the same as a preset certificate.

[0093] In some embodiments, if the gateway device determines that the second certificate is the same as the preset certificate, the gateway device maintains the connection relationship with the management device.

[0094] In other embodiments, if the gateway device determines that the second certificate is not the same as the preset certificate, the gateway device performs S305.

[0095] S305, the gateway device closes the first port.

[0096] That is, the gateway device cancels the access to the service of the target device to be managed by closing the first port.

[0097] In some embodiments, if the gateway device determines that the response message from the management device is not received at the preset time, the gateway device performs S305.

[0098] It can be understood that the gateway device can determine the connection state of the management device and the gateway device by determining whether the management device sends a response message at a preset time and determining whether the second certificate is the same as the preset certificate, so that the management device and the gateway device maintain a secure connection state. In this way, the security of the connection between the management device and the gateway device can be improved.

[0099] In some embodiments, in order to authenticate the device identity of the gateway device, as shown in FIG. 4, after the gateway device determines the second port according to the identifier of the target device to be managed (i.e., S204), the device authentication method provided by the embodiments of the present application further includes the following steps: S401-S411. Figure 4

[0100] S401, the gateway device sends a second request message to the target device to be managed.

[0101] The second request message is used to request to obtain a target credential, and the target credential is used to access the target device to be managed.

[0102] S402, the target device to be managed receives the second request message from the gateway device.

[0103] In some embodiments, the target device to be managed performs S403 in response to the second request message.

[0104] S403, the target device to be managed generates a target random number.

[0105] In a possible implementation, the target device to be managed is deployed with a random number generator. The target device to be managed can generate the target random number through the random number generator.

[0106] S404, the target device to be managed sends the target random number to the gateway device.

[0107] S405, the gateway device receives the target random number from the target device to be managed.

[0108] S406, the gateway device generates a target authentication code based on the target key information and the target random number.

[0109] In a possible implementation, the gateway device also stores the target key information. The gateway device can generate the target authentication code based on the target key information and the target random number.

[0110] It should be noted that for the process of the gateway device generating the target authentication code based on the target key information and the target random number, reference can be made to the introduction of generating a message authentication code (message authentication code, MAC) in conventional technology, which will not be described here.

[0111] ​S407, the gateway device sends the target authentication code to the target to-be-managed device.

[0112] S408, the target to-be-managed device receives the target authentication code from the gateway device.

[0113] S409, the target to-be-managed device determines whether the target authentication code is composed of the target random number according to the target key information.

[0114] In a possible implementation, the target to-be-managed device stores the target key information. The target to-be-managed device can verify the target authentication code according to the target key information, and determine whether the target authentication code is composed of the target random number.

[0115] In some embodiments, if the target to-be-managed device determines that the target authentication code is not composed of the target random number, the target to-be-managed device sends a second prompt message to the gateway device, where the second prompt message is used to prompt that the access credential acquisition fails.

[0116] In other embodiments, if the target to-be-managed device determines that the target authentication code is composed of the target random number, the target to-be-managed device performs S410.

[0117] S410, the target to-be-managed device sends the target credential to the gateway device.

[0118] S411, the gateway device determines whether the target credential from the target to-be-managed device is received.

[0119] In some embodiments, if the gateway device determines that the target credential from the target to-be-managed device is received, the gateway device performs S205.

[0120] In other embodiments, if the gateway device determines that the target credential from the target to-be-managed device is not received (or the second prompt message from the target to-be-managed device is received), the gateway device does not perform S205, and sends a third prompt message to the management device, where the third prompt message is used to prompt that the first request message response fails.

[0121] It can be understood that the target to-be-managed device can perform identity authentication on the gateway device by sending the target random number to the gateway device, and verifying whether the target authentication code from the gateway device is composed of the target random number. In this way, the security of the target to-be-managed device can be improved. Moreover, the gateway device can manage the management device to access the service of the target to-be-managed device by determining whether the target credential from the target to-be-managed device is received. In this way, the security of the process that the management device accesses the to-be-managed device can be improved.

[0122] In some embodiments, the first request message can further include target information, the target information being information that the management device needs to access in the target to-be-managed device. After the gateway device receives the first request message from the management device, the gateway device can generate a second request message based on the target information, and send the second request message to the target to-be-managed device, the second request message can include the target information. The target to-be-managed device can receive the second request message from the gateway device, and determine a target access level according to the target information. Then, the target to-be-managed device can determine whether the target access level is greater than a preset level, and if the target to-be-managed device determines that the target access level is greater than the preset level, the target to-be-managed device can perform 0x27 diagnostic instruction authentication of UDS (Unified Diagnostic Services) with the gateway device.

[0123] It should be noted that the process of performing 0x27 diagnostic instruction authentication of UDS by the target to-be-managed device and the gateway device can be described with reference to S401-S411 described above, and will not be described here.

[0124] It can be understood that the target to-be-managed device can determine the security level of access according to the information that needs to be accessed, and determine whether to perform security authentication on the gateway device according to the security level of access. In this way, the risk of leakage of information of the to-be-managed device can be reduced, and the security of the to-be-managed device can be improved.

[0125] Embodiments of the present application provide a device authentication method, as shown in the method, the device authentication method can include S501-S505. Figure 5

[0126] S501, the gateway device receives a first request message from the management device.

[0127] It should be noted that the process of receiving the first request message from the management device by the gateway device can be described with reference to S201-S202 described above, and will not be described here.

[0128] S502, the gateway device determines whether the first certificate is the same as the preset certificate.

[0129] It should be noted that the process of determining whether the first certificate is the same as the preset certificate by the gateway device can be described with reference to S203 described above, and will not be described here.

[0130] In some embodiments, if the gateway device determines that the first certificate is the same as the preset certificate, the gateway device performs S503.

[0131] S503, the gateway device determines the address information of the first port.

[0132] ​It should be noted that the introduction of the process that the gateway device determines the address information of the first port can refer to the description in S204-S205 described above, and details are not described herein.

[0133] S504, the gateway device sends the address information of the first port to the management device.

[0134] S505, the gateway device receives the connection message from the management device.

[0135] It should be noted that the introduction of the process that the gateway device receives the connection message from the management device can refer to the description in S207-S209 described above, and details are not described herein.

[0136] In some embodiments, after the gateway device receives the connection message from the management device, the gateway device can also send a target instruction to the management device, and determine whether a response message from the management device is received at a preset time. If the gateway device determines that the response message from the management device is not received at the preset time, the gateway device closes the first port.

[0137] It should be noted that the introduction of the process that the gateway device sends a target instruction to the management device and determines whether a response message from the management device is received at a preset time can refer to the description in S301-S303 described above, and details are not described herein.

[0138] In other embodiments, if the gateway device determines that the response message from the management device is received at the preset time, the gateway device can determine whether the second certificate is the same as the preset certificate. If the gateway device determines that the second certificate is not the same as the preset certificate, the gateway device closes the first port.

[0139] It should be noted that the introduction of the process that the gateway device determines whether the second certificate is the same as the preset certificate can refer to the description in S305 described above, and details are not described herein.

[0140] In some embodiments, after the gateway device receives the first request message from the management device, the gateway device can send a second request message to the target to-be-managed device, and receive a target random number from the target to-be-managed device. Then, the gateway device can generate a target authentication code based on the target key information and the target random number, and send the target authentication code to the target to-be-managed device. Then, the gateway device can determine whether the first certificate is the same as the preset certificate, and determine whether a target credential from the target to-be-managed device is received. If the gateway device determines that the first certificate is the same as the preset certificate, and the target credential from the target to-be-managed device is received, the address information of the first port is determined.

[0141] It should be noted that the introduction of the process that the gateway device sends a second request message to the target to-be-managed device, and receives a target random number from the target to-be-managed device, and the process that the gateway device generates a target authentication code based on the target key information and the target random number, and sends the target authentication code to the target to-be-managed device, and the process that the gateway device determines whether the first certificate is same as the preset certificate, and determines whether the target credential from the target to-be-managed device is received, can refer to the description of S203-S401, S405-S407 and S411, and details are not described herein.

[0142] The flowchart of the device authentication method provided by the embodiment of the present application is introduced below in combination with specific examples. As shown in Figure 6 The device authentication method provided by the embodiment of the present application includes the following steps: S601-S602.

[0143] S601, the diagnostic proxy gateway (i.e., the gateway device) performs security authentication on the diagnostic device (i.e., the management device).

[0144] In a possible implementation, when the diagnostic device is connected to the automobile diagnostic interface (i.e., the gateway device receives the first request message from the management device), the diagnostic proxy gateway performs security authentication on the diagnostic device by using a security authentication method based on an asymmetric encryption algorithm (i.e., the gateway device determines whether the first certificate is same as the preset certificate).

[0145] S602, the diagnostic proxy gateway performs 0x27 security authentication of the diagnostic protocol on the diagnosed controller (i.e., the target to-be-managed device).

[0146] In a possible implementation, when the diagnostic device accesses a service that needs to be authenticated (i.e., the target to-be-managed device determines that the target access level is greater than the preset level), the diagnostic proxy gateway sends a 0x27 diagnostic instruction authentication of the diagnostic protocol to the diagnosed controller. The diagnostic proxy gateway sends the 0x27 diagnostic instruction authentication of the diagnostic protocol to the diagnosed controller by using a security authentication based on a symmetric encryption algorithm (i.e., S401-S411).

[0147] In some embodiments, as shown in Figure 7 The method for the diagnostic proxy gateway to perform security authentication on the diagnostic device includes the following steps: S701-S703.

[0148] S701, the diagnostic device sends a preset certificate to the diagnostic proxy gateway.

[0149] In a possible implementation, the diagnostic device is preset with a certificate of the diagnostic device (i.e., the management device stores the first certificate), and the diagnostic device can send the preset certificate to the diagnostic proxy gateway (i.e., the management device sends the first request message to the gateway device).

[0150] S702. The diagnostic agent gateway verifies the validity of the diagnostic device's device certificate.

[0151] In one possible implementation, the diagnostic proxy gateway has a pre-installed diagnostic authentication root certificate (i.e., the gateway device stores the authentication root certificate). After the diagnostic device connects to the diagnostic proxy gateway, it uses the standard Transport Layer Security (TLS) protocol. The diagnostic proxy gateway uses the diagnostic authentication root certificate to verify whether the device certificate of the diagnostic device is valid, that is, it uses the diagnostic authentication root certificate to verify the signature of the device certificate (i.e., the gateway device determines whether the first certificate is the same as the preset certificate).

[0152] In some embodiments, if the diagnostic agent gateway authenticates the device certificate of the diagnostic device, the diagnostic agent gateway will check the diagnostic service port and function (i.e., the gateway device determines the address information of the first port).

[0153] S703, The diagnostic agent gateway determines whether the diagnostic device maintains a secure authentication status.

[0154] In one possible implementation, after the diagnostic agent gateway successfully authenticates the diagnostic device, the diagnostic device must periodically send heartbeat data packets in the secure authentication connection channel (i.e., the gateway device determines whether it receives a response message from the management device at a preset time) to maintain a secure connection. The sending period can be set to 30 seconds. If the diagnostic agent gateway detects a connection failure or fails to detect heartbeat data packets for more than three periods, it disconnects the secure connection and shuts down the diagnostic service port and functions (i.e., the gateway device closes the first port).

[0155] In some embodiments, the diagnostic agent gateway and the controller being diagnosed are each pre-configured with a symmetric key for authentication (i.e., the gateway device stores the target key information, and the target device to be managed stores the target key information).

[0156] It should be noted that the pre-setting process can be carried out on the vehicle production line or on the controller production line.

[0157] In some embodiments, such as Figure 8 As shown, the method for the diagnostic agent gateway to perform 0x27 security authentication of the diagnostic protocol to the controller being diagnosed includes the following steps: S801-S803.

[0158] S801, the diagnostic agent gateway requests a random number from the controller being diagnosed (i.e., the gateway device sends a second request message to the target device to be managed), and the controller being diagnosed generates a random number and returns it to the diagnostic agent gateway (i.e., the target device to be managed sends a target random number to the gateway device).

[0159] S802, the diagnostic proxy gateway uses the authentication key to calculate the random number to obtain a message authentication code (i.e., the gateway device generates a target authentication code based on target key information and a target random number), and sends to the diagnosed controller (i.e., the gateway device sends the target authentication code to the target to-be-managed device).

[0160] S803, the diagnosed controller verifies the message authentication code sent by the diagnostic proxy gateway (i.e., the target to-be-managed device determines whether the target authentication code is composed of the target random number according to the target key information).

[0161] In some embodiments, if the diagnosed controller verifies the message authentication code sent by the diagnostic proxy gateway correctly, it returns a security authentication success (i.e., the target to-be-managed device sends the target credential to the gateway device); otherwise, it returns a security authentication failure (i.e., the target to-be-managed device sends a second prompt message to the gateway device).

[0162] The above mainly introduces the scheme provided by the embodiments of the application from the method aspect. In order to implement the above functions, the authentication device of the equipment or the electronic device contains the hardware structure and / or software module for executing the corresponding functions. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of the examples described in the embodiments disclosed in the present application, the application can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is driven by hardware or computer software, it depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the application.

[0163] The embodiments of the application can divide the authentication device of the equipment or the electronic device into functional modules according to the above method, for example, the authentication device of the equipment or the electronic device can include functional modules corresponding to each function division, or two or more functions can be integrated into one processing module. The integrated module can be realized in the form of hardware or software functional module. It should be noted that the division of modules in the embodiments of the application is illustrative, and is only a logical function division. Actual implementation can have another division method.

[0164] Figure 9 is a block diagram of an authentication device of an equipment according to an example embodiment. Referring to Figure 9 The authentication device of the equipment is applied to a gateway device, the gateway device stores a preset certificate, the gateway device is connected with a target to-be-managed device, and the authentication device of the equipment includes a sending module 901, a receiving module 902, and a processing module 903.

[0165] The receiving module 902 is configured to receive a first request message from the management device, the first request message being used to request access to the target device to be managed, and the first request message comprising a first certificate. The processing module 903 is configured to determine address information of a first port if the first certificate is identical to a preset certificate, the first port being a port in the gateway device, and the first port being connected to a second port, the second port being a port of the gateway device connected to the target device to be managed. The sending module 901 is configured to send the address information of the first port to the management device. The receiving module 902 is further configured to receive a connection message from the management device, the connection message being used to indicate that the management device is successfully connected to the first port.

[0166] In a possible implementation, the sending module 901 is further configured to send a target instruction to the management device, the target instruction being used to instruct the management device to send a response message at a preset time. The processing module 903 is further configured to close the first port if the response message from the management device is not received at the preset time.

[0167] In a possible implementation, the response message comprises a second certificate. The processing module 903 is further configured to close the first port if the response message from the management device is received at the preset time, and the second certificate is not identical to the preset certificate.

[0168] In a possible implementation, the gateway device further stores target key information. The sending module 901 is further configured to send a second request message to the target device to be managed, the second request message being used to request the target device to be managed to provide a target credential, the target credential being used to access the target device to be managed. The receiving module 902 is further configured to receive a target random number from the target device to be managed. The processing module 903 is further configured to generate a target authentication code based on the target key information and the target random number, and send the target authentication code to the target device to be managed. The processing module 903 is specifically configured to determine the address information of the first port if the first certificate is identical to the preset certificate, and the target credential from the target device to be managed is received.

[0169] Figure 10 is a block diagram of another authentication apparatus of a device according to an example embodiment. Refer to Figure 10 The authentication apparatus of the device is applied to a target device to be managed, and the target device to be managed stores target key information. The authentication apparatus of the device comprises a receiving module 1001, a processing module 1002, and a sending module 1003.

[0170] The receiving module 1001 is configured to receive a second request message from the gateway device, the second request message being used to request a target credential for accessing a target device to be managed. The processing module 1002 is configured to generate a target random number in response to the second request message. The sending module 1003 is configured to send the target random number to the gateway device. The receiving module 1001 is further configured to receive a target authentication code from the gateway device. The processing module 1002 is further configured to determine whether the target authentication code is composed of the target random number according to target key information. The sending module 1003 is further configured to send the target credential to the gateway device if it is determined that the target authentication code is composed of the target random number.

[0171] As to the apparatus in the above-mentioned embodiments, the specific manners in which various units perform operations have been described in detail in the embodiments of the method, and thus will not be described here in detail.

[0172] Figure 11 is a block diagram of an electronic device according to an exemplary embodiment. As shown in Figure 11 , the electronic device 1100 includes but is not limited to a processor 1101 and a memory 1102.

[0173] The memory 1102 described above is configured to store executable instructions of the processor 1101 described above. It can be understood that the processor 1101 is configured to execute the instructions to implement the authentication method of the device in the above-mentioned embodiments.

[0174] It should be noted that those skilled in the art can understand Figure 11 that the electronic device structure shown in the above-mentioned embodiments does not constitute a limitation on the electronic device, and the electronic device can include more or fewer components than Figure 11 those shown in the above-mentioned embodiments, or combine certain components, or arrange different components.

[0175] The processor 1101 is the control center of the electronic device, connects all parts of the electronic device through various interfaces and lines, and performs various functions of the electronic device and processes data by running or executing software programs and / or modules stored in the memory 1102 and calling data stored in the memory 1102, thereby overall monitoring the electronic device. The processor 1101 can include one or more processing units. Optionally, the processor 1101 can integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, user interface and application programs, and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor can also not be integrated into the processor 1101.

[0176] The memory 1102 can be used to store software programs and various data. The memory 1102 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, application programs (such as a processing unit) required by at least one function module, and the like. In addition, the memory 1102 can include a high-speed random access memory, and can also include a non-volatile memory, for example, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state memory device.

[0177] In an example embodiment, a computer readable storage medium including instructions, for example, the memory 1102 including instructions, is also provided, and the instructions can be executed by the processor 1101 of the electronic device 1100 to implement the authentication method of the device in the above embodiment.

[0178] In actual implementation, Figure 9 The functions of the sending module 901, the receiving module 902, and the processing module 903 in the device in the above embodiment can be implemented by Figure 10 The functions of the receiving module 1001, the processing module 1002, and the sending module 1003 in the device in the above embodiment can be implemented by Figure 11 The processor 1101 in the device in the above embodiment can call the computer program stored in the memory 1102 to implement the authentication method of the device in the above embodiment. The specific execution process can refer to the description of the authentication method of the device in the above embodiment, and will not be described here.

[0179] Alternatively, the computer readable storage medium can be a non-transitory computer readable storage medium, for example, a Read-Only Memory (ROM), a Random Access Memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0180] In an example embodiment, the embodiments of the present application also provide a vehicle, which includes Figure 11 The vehicle can be used to execute the authentication method of the device in the above embodiment.

[0181] In an example embodiment, the embodiments of the present application also provide a computer program product including one or more instructions, which can be executed by a processor of an electronic device to complete the authentication method of the device in the above embodiment.

[0182] It should be noted that the instructions in the above computer readable storage medium or the one or more instructions in the computer program product are executed by the processor of the electronic device to implement each process of the above authentication method of the device, and can achieve the same technical effect as the above authentication method of the device. To avoid repetition, it will not be described here.

[0183] Through the description of the above embodiments, those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above division of functional modules is taken as an example, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0184] In several embodiments provided in the present application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are only illustrative, for example, the division of modules or units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0185] The units described as separate components can or can not be physically separate, and the components shown as units can be one physical unit or multiple physical units, that is, can be located in one place or can be distributed to multiple different places. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0186] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present alone, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0187] If the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application essentially or the parts that make contributions to the prior art or all or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing an apparatus (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the method of the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a ROM, a RAM, a magnetic disk or an optical disk, and various storage medium that can store program codes.

[0188] The above merely provides the specific implementation of the present application, but the protection scope of the present application is not limited to this. Any change or replacement within the technical scope disclosed by the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. An authentication method of a device, characterized by, The method comprises: The gateway device receives a first request message from a management device, the gateway device stores preset certificate and target key information, the gateway device is connected with a target device to be managed, the target device to be managed stores target key information, the gateway device is a diagnostic agent gateway, the target device to be managed is a diagnosed controller, the first request message is used for requesting to access the target device to be managed, the first request message comprises: first certificate and target information, the target information is information in the target device to be managed which needs to be accessed by the management device, the target information is used for determining a security level of access by the management device, and the management device is a diagnostic device; The gateway device generates a second request message based on the target information, and sends the second request message to the target device to be managed, the second request message is used for requesting to obtain target credentials, the target credentials are used for accessing the target device to be managed, and the second request message comprises the target information; The target device to be managed receives the second request message from the gateway device, the second request message is used for requesting to obtain target credentials, the target credentials are used for accessing the target device to be managed, and the second request message comprises target information, the target information is information in the target device to be managed which needs to be accessed by the management device, the gateway device is a diagnostic agent gateway, and the management device is a diagnostic device; The target device to be managed determines a target access level based on the target information; The target device to be managed determines whether the target access level is greater than a preset level; If the target access level is greater than the preset level, the target device to be managed generates a target random number in response to the second request message, and sends the target random number to the gateway device; The gateway device receives the target random number from the target device to be managed; The gateway device generates a target authentication code based on the target key information and the target random number, and sends the target authentication code to the target device to be managed; The target device to be managed receives the target authentication code from the gateway device; The target device to be managed determines whether the target authentication code is composed of the target random number according to the target key information; If the target device to be managed determines that the target authentication code is composed of the target random number, the target device to be managed sends the target credentials to the gateway device; If the first certificate is the same as the preset certificate, and the gateway device receives the target credentials from the target device to be managed, address information of a first port is determined, the first port is a port in the gateway device, and the first port is connected with a second port, the second port is a port of the gateway device connected with the target device to be managed; The gateway device sends the address information of the first port to the management device; The gateway device receives a connection message from the management device, the connection message is used for indicating that the management device is successfully connected with the first port.

2. The method of claim 1, wherein, After the gateway device receives the connection message from the management device, the method further comprises: The gateway device sends a target instruction to the management device, the target instruction being used to instruct sending a response message at a preset time; If the gateway device does not receive the response message from the management device at the preset time, the first port is closed.

3. The method of claim 2, wherein, The response message comprises a second certificate, and the method further comprises: If the gateway device receives the response message from the management device at the preset time, and the second certificate is different from the preset certificate, the first port is closed.

4. A communication system, characterized by The communication system comprises a gateway device, a management device and a target device to be managed, the gateway device is connected with the target device to be managed, the target device to be managed stores target key information, the gateway device is a diagnostic agent gateway, and the target device to be managed is a diagnosed controller. The gateway device is used to receive a first request message from the management device, the gateway device stores preset certificate and target key information, the first request message is used to request access to the target device to be managed, the first request message comprises a first certificate and target information, the target information is information in the target device to be managed which needs to be accessed by the management device, the target information is used to determine a security level of access by the management device, and the management device is a diagnostic device. The gateway device is further used to generate a second request message based on the target information, and send the second request message to the target device to be managed, the second request message is used to request target credentials, the target credentials are used to access the target device to be managed, and the second request message comprises the target information. The target device to be managed is used to receive the second request message from the gateway device, the second request message is used to request target credentials, the target credentials are used to access the target device to be managed, and the second request message comprises target information, the target information being information in the target device to be managed which needs to be accessed by the management device, the gateway device being a diagnostic agent gateway, and the management device being a diagnostic device. The target device to be managed is further used to determine a target access level based on the target information. The target device to be managed is further used to determine whether the target access level is greater than a preset level. The target device to be managed is further used to, if the target access level is greater than the preset level, generate a target random number in response to the second request message, and send the target random number to the gateway device. The gateway device is further used to receive the target random number from the target device to be managed. The gateway device is further used to generate a target authentication code based on the target key information and the target random number, and send the target authentication code to the target device to be managed. The target device to be managed is further used to receive the target authentication code from the gateway device. The target device to be managed is further used to determine whether the target authentication code is composed of the target random number according to the target key information. The target device to be managed is further used to determine whether the target authentication code is composed of the target random number according to the target key information. The target device to be managed is further configured to send the target credential to the gateway device if it is determined that the target authentication code is composed of the target random number array; The gateway device is further configured to determine address information of a first port if the first certificate is the same as the preset certificate and the target credential from the target device to be managed is received, the first port being a port in the gateway device, and the first port being connected with a second port, the second port being a port of the gateway device connected with the target device to be managed; The gateway device is further configured to send the address information of the first port to the management device; The gateway device is further configured to receive a connection message from the management device, the connection message being used to indicate that the management device is successfully connected with the first port.

5. An electronic device, comprising: Comprise: a processor; a memory for storing instructions executable by the processor; wherein the processor is configured to execute the instructions to implement the method of any one of claims 1 to 3.

6. A computer-readable storage medium, characterized in that, When the computer-executable instructions stored in the computer-readable storage medium are executed by the processor of the electronic device, the electronic device can perform the method of any one of claims 1 to 3.

7. A vehicle characterized by comprising: Comprise: a processor; a memory for storing instructions executable by the processor; wherein the processor is configured to execute the instructions to implement the method of any one of claims 1 to 3.

Citation Information

Patent Citations

  • Systems and methods for network management

    CN111628960A

  • Communication method, device and equipment, and storage medium

    CN111865922A