Connection method, device and apparatus of internet of things equipment and storage medium
By utilizing the 128-bit structure of IPv6 addresses, IoT devices and optical modems can collaboratively verify each other, thus solving the problem of information leakage when IoT devices connect to the management platform and achieving a secure and efficient connection method.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-21
- Publication Date
- 2026-04-07
AI Technical Summary
IoT devices face information leakage issues when connecting to management platform devices, mainly due to the lack of security protection software for hardware resources, such as VPNs and complex keys, which makes hardware information easy to forge and connections insecure.
The 128-bit structure of the IPv6 address is adopted. The first 60 bits are assigned to the optical modem by the telecommunications operator, the middle 4 bits are the key generated by the optical modem, and the last 64 bits are the identification information of the IoT device. The management platform device verifies the first 60 bits of the target IPv6 address to determine the telecommunications operator, and the optical modem device verifies the key to ensure connection security.
It enables IoT devices to connect to the management platform without authentication while ensuring information security, preventing information leakage, and improving connection security and efficiency.
Smart Images

Figure CN116668160B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a connection method, apparatus, device, and storage medium for Internet of Things (IoT) devices. Background Technology
[0002] Due to limited hardware resources, IoT device manufacturers often do not deploy strong security software, such as VPNs (Virtual Private Networks) or complex key encryption methods, on their IoT devices.
[0003] Currently, a whitelist is typically set up using hardware information between IoT devices and management platform devices. However, since hardware information is easily forged, this can lead to IoT devices connecting to other management platform devices, which in turn can result in information leaks. Summary of the Invention
[0004] This application provides a method, apparatus, device, and storage medium for connecting IoT devices to solve the problem of information leakage when IoT devices connect to management platform devices in the prior art.
[0005] Firstly, this application provides a connection method for an Internet of Things (IoT) device, applicable to IoT devices, the connection method for the IoT device including:
[0006] When connected to an optical modem, obtain the target IPv6 address sent by the optical modem. The first 60 bits of the target IPv6 address are assigned by the telecommunications operator to the optical modem, the last 64 bits of the target IPv6 address are the identification information of the IoT device, and the middle 4 bits of the target IPv6 address are the first key assigned by the optical modem to the IoT device.
[0007] Send a connection request to the management platform device of the IoT device, the connection request carrying the target IPv6 address;
[0008] Once the management platform device verifies that the target IPv6 address has been successfully authenticated, it connects to the management platform device.
[0009] Optionally, the connection request is used to instruct the management platform device to determine the communication operator based on the first 60 bits of the target IPv6 address and send the target IPv6 address to the communication operator. The communication operator is used to determine the optical modem device based on the target IPv6 address and send the target IPv6 address to the optical modem device. The optical modem device is used to verify the target IPv6 address. If the verification is successful, it sends a message to the management platform device that the target IPv6 address has been verified relative to the target IPv6 address.
[0010] Optionally, it also includes: under preset conditions, after restarting the IoT device, performing the step of obtaining the target IPv6 address sent by the optical modem device; the preset conditions include: the management platform device determines that the target IPv6 address fails to be verified relative to the target IPv6 address, the IoT device and the management platform device are not connected for a preset period of time, and the duration from the time of allocating the target IPv6 address to the current time is greater than the effective usage duration of the first key.
[0011] Secondly, this application provides a connection method for an IoT device, applied to an optical modem device. The connection method includes: when the IoT device is connected to the optical modem device, generating a target IPv6 address, wherein the first 60 bits of the target IPv6 address are assigned by the telecommunications operator to the optical modem device, the last 64 bits of the target IPv6 address are the identification information of the IoT device, and the middle 4 bits of the target IPv6 address are the first key assigned by the optical modem device to the IoT device; sending the target IPv6 address to the IoT device; receiving the target IPv6 address sent by the management platform device through the telecommunications operator, wherein the target IPv6 address is carried in the connection request sent by the IoT device to the management platform device; verifying the target IPv6 address based on the target IPv6 address, and if the target IPv6 address is verified successfully, sending a verification success indication to the associated platform device, wherein the verification success indication is used to instruct the management platform device to accept the connection of the IoT device.
[0012] Optionally, verifying the target IPv6 address based on the target IPv6 address includes: if the last 64 bits of the target IPv6 address are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key, then the target IPv6 address is determined to be verified successfully.
[0013] Optionally, the first key corresponds to a verification validity period. If the last 64 bits of the target IPv6 address are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key, the target IPv6 address is determined to be verified successfully. This includes: if the verification validity period has not expired, and the last 64 bits of the target IPv6 address are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key, the target IPv6 address is determined to be verified successfully.
[0014] Optionally, it also includes: determining that the target IPv6 address verification failed if the verification validity period expires, or if the last 64 bits of the target IPv6 address are not the identification information of the IoT device or the middle 4 bits of the target IPv6 address are not the first key;
[0015] Send a verification failure indication to the management platform device. The verification failure indication is used to instruct the management platform device to reject the connection of the IoT device.
[0016] Thirdly, this application provides a connection device for an Internet of Things (IoT) device, which is applied to an IoT device. The connection device for the IoT device includes:
[0017] The acquisition module is used to acquire the target IPv6 address sent by the optical modem when connected to the optical modem. The first 60 bits of the target IPv6 address are assigned by the telecommunications operator to the optical modem, the last 64 bits of the target IPv6 address are the identification information of the IoT device, and the middle 4 bits of the target IPv6 address are the first key assigned by the optical modem to the IoT device.
[0018] The sending module is used to send connection requests to the management platform device of IoT devices. The connection requests carry the target IPv6 address.
[0019] The connection module is used to connect to the management platform device after the management platform device has verified that the target IPv6 address has been successfully authenticated.
[0020] Optionally, the connection request is used to instruct the management platform device to determine the communication operator based on the first 60 bits of the target IPv6 address and send the target IPv6 address to the communication operator. The communication operator is used to determine the optical modem device based on the target IPv6 address and send the target IPv6 address to the optical modem device. The optical modem device is used to verify the target IPv6 address. If the verification is successful, it sends a message to the management platform device that the target IPv6 address has been verified relative to the target IPv6 address.
[0021] Optionally, the execution module is used to perform the step of obtaining the target IPv6 address sent by the optical modem device after restarting the IoT device under preset conditions; the preset conditions include: the management platform device determines that the target IPv6 address verification fails relative to the target IPv6 address, the IoT device and the management platform device are not connected for a preset period of time, and the duration from the time of allocating the target IPv6 address to the current time is greater than the effective usage duration of the first key.
[0022] Fourthly, this application provides a connection device for an Internet of Things (IoT) device, applied to an optical modem device. The connection device for the IoT device includes:
[0023] The generation module is used to generate a target IPv6 address when an IoT device is connected to an optical modem. The first 60 bits of the target IPv6 address are assigned by the telecommunications operator to the optical modem, the last 64 bits of the target IPv6 address are the identification information of the IoT device, and the middle 4 bits of the target IPv6 address are the first key assigned by the optical modem to the IoT device.
[0024] The sending module is used to send the target IPv6 address to IoT devices;
[0025] The receiving module is used to receive the target IPv6 address sent by the management platform device through the communication operator. The target IPv6 address is carried in the connection request sent by the IoT device to the management platform device.
[0026] The verification module is used to verify the target IPv6 address based on the target IPv6 address, and if the target IPv6 address is successfully verified, it sends a verification success indication to the associated platform device. The verification success indication is used to instruct the management platform device to accept the connection of the IoT device.
[0027] Optionally, the verification module is specifically used to: determine that the target IPv6 address verification is successful if the last 64 bits of the target IPv6 address are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key.
[0028] Optionally, the first key corresponds to a verification validity period. When the verification module determines that the target IPv6 address verification is successful if the last 64 bits of the target IPv6 address are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key, it is specifically used to: determine that the target IPv6 address verification is successful if the last 64 bits of the target IPv6 address are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key, provided that the verification validity period has not expired.
[0029] Optionally, the verification module is also used to: determine that the verification of the target IPv6 address has failed if the verification validity period expires, or if the last 64 bits of the target IPv6 address are not the identification information of the IoT device or the middle 4 bits of the target IPv6 address are not the first key; and send a verification failure indication to the management platform device, the verification failure indication being used to instruct the management platform device to reject the connection of the IoT device.
[0030] Fifthly, this application provides an electronic device, comprising:
[0031] At least one processor; and
[0032] A memory that is communicatively connected to at least one processor; wherein,
[0033] The memory stores instructions executable by at least one processor, which enable the electronic device to perform the connection method of the Internet of Things device according to any one of the first or second aspects of this application.
[0034] Sixthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the connection method of an Internet of Things device according to any one of the first or second aspects of this application.
[0035] In a seventh aspect, this application provides a computer program product, including a computer program that, when executed by a processor, implements the connection method of an Internet of Things device according to any one of the first or second aspects of this application.
[0036] This application provides a connection method, apparatus, device, and storage medium for IoT devices. The connection method is applied to IoT devices and includes: when connecting to an optical modem (ONT), obtaining a target IPv6 address sent by the ONT, wherein the first 60 bits of the target IPv6 address are assigned by the telecommunications operator to the ONT, the last 64 bits of the target IPv6 address are the IoT device's identification information, and the middle 4 bits of the target IPv6 address are a first key assigned by the ONT to the IoT device; sending a connection request to the IoT device's management platform device, the connection request carrying the target IPv6 address; and connecting to the management platform device if the management platform device verifies the target IPv6 address. This application enables the IoT device to securely connect to the management platform device, preventing information leakage. Attached Figure Description
[0037] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some of those in this application. For those skilled in the art, other drawings can be obtained from these drawings without any creative effort.
[0038] Figure 1 A schematic diagram illustrating a scenario for the connection method of the IoT device provided in this application;
[0039] Figure 2 A flowchart illustrating the steps of a connection method for an Internet of Things (IoT) device provided in this application;
[0040] Figure 3 A schematic diagram illustrating a connection method for an Internet of Things (IoT) device provided in this application;
[0041] Figure 4 A flowchart illustrating the steps of another IoT device connection method provided in this application;
[0042] Figure 5 A structural block diagram of a connection device for an Internet of Things (IoT) device provided in this application.
[0043] Figure 6 A structural block diagram of a connection device for another Internet of Things (IoT) device provided in this application;
[0044] Figure 7 A schematic diagram of the hardware structure of the electronic device provided in this application.
[0045] The foregoing figures have clearly illustrated the present application, and a more detailed description follows. These figures and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of the application to those skilled in the art through reference. Detailed Implementation
[0046] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, what is described is only a part of this application, not all of it. Based on this application, all other methods that a person skilled in the art can obtain without inventive effort are within the scope of protection of this application.
[0047] The terms "first," "second," "third," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that, for example, the application described herein can be implemented in orders other than those illustrated or described herein.
[0048] Furthermore, the terms “comprising” and “having”, and any variations thereof, are intended to cover non-exclusive inclusion, such that a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such process, method, product, or apparatus.
[0049] Currently, various telecommunications operators have launched IPv6 (Internet Protocol Version 6) network upgrades for fixed-line broadband. As of now, almost all home users can obtain IPv6 addresses, extending from traditional routers and mobile phones to smart home devices. An IPv6 address represents a 128-bit IPv6 address. With the rapid increase in the number of smart home devices, they have gained popularity among many home users. However, these smart devices (some IoT devices) have relatively weak capabilities, and the initial network connection process is complex. Furthermore, the issue of identity security authentication for these smart devices has become a major concern for users.
[0050] Based on the above problems, related technologies typically use hardware information (such as MAC addresses) between IoT device terminals and management platform devices to create whitelists. This approach has the following issues: First, if there are a large number of internet devices, the efficiency and accuracy of connecting these devices to the management platform cannot be guaranteed. Second, MAC addresses can be forged, making them insecure. Third, when forging servers or management platform devices, IoT devices cannot effectively identify the risks, which is why attacks on IoT devices frequently lead to information leaks.
[0051] To address the aforementioned issues, the IoT device connection method provided in this application fully leverages the scalability advantage of 128-bit IPv6 addresses, enabling IoT devices to connect to management platform devices without authentication while ensuring the information security of IoT devices provided by the management platform devices.
[0052] Before introducing the connection method for IoT devices provided in this application, we will first briefly introduce the application scenarios of the connection method for IoT devices.
[0053] For example, Figure 1 This is a schematic diagram illustrating a scenario of the connection method for IoT devices provided in an embodiment of this application, such as... Figure 1 As shown, this scenario includes an IoT device 11 and a management platform device 12 that manages the IoT device 11. After establishing a connection between the IoT device 11 and the management platform device 12, the IoT device 11 can establish a connection with the management platform device 12. For example, if the IoT device 11 is a camera and the management platform device 12 is a mobile terminal, the mobile terminal can control the camera's rotation, on / off state, etc., and the camera can transmit the captured video to the mobile terminal. As another example, if the IoT device 11 is a robotic vacuum cleaner and the management platform device 12 is a mobile terminal, the mobile terminal can control the robotic vacuum cleaner's on / off state and cleaning mode, etc., and the robotic vacuum cleaner can transmit its location information to the mobile terminal.
[0054] The following is combined Figure 1 Application scenarios, refer to Figure 2 This application describes a connection method for an Internet of Things (IoT) device according to exemplary embodiments. It should be noted that the above application scenarios are shown only to facilitate understanding of the spirit and principles of this application, and the embodiments of this application are not limited in any way. Rather, the embodiments of this application can be applied to any applicable scenario.
[0055] Figure 2A flowchart illustrating a connection method for an Internet of Things (IoT) device provided in this application embodiment. This connection method for IoT devices, applied to IoT devices, specifically includes the following steps:
[0056] S201, when connected to an optical modem, obtain the target IPv6 address sent by the optical modem.
[0057] The first 60 bits of the target IPv6 address are assigned by the telecommunications operator to the optical modem, the last 64 bits of the target IPv6 address are the identification information of the IoT device, and the middle 4 bits of the target IPv6 address are the first key assigned by the optical modem to the IoT device.
[0058] In this embodiment of the application, the optical modem equipment deployed by the telecommunications operator can support IPv6 address generation rules.
[0059] Reference Figure 3 The S301 in the process requests an IPv6 address for the optical modem. This means that the optical modem first requests the first 64 bits of its WAN port's IPv6 address from the BNG (gateway) device of the telecommunications operator. In other words, the first 64 bits of the optical modem's IPv6 address are allocated by the telecommunications operator, and the last 64 bits are the MAC address of the optical modem.
[0060] Furthermore, referring to Figure 3 The S302 connection refers to the optical modem device, which is the specific WiFi SSID (wireless network name) that the IoT device uses to connect to the optical modem device provided by the telecommunications operator. The SSID includes SSID1 and SSID2. SSID1 is used for mobile terminals to access the internet, while the optical modem device provides SSID2 for IoT devices to connect to.
[0061] Furthermore, IoT devices can connect to the optical modem device's SSID2 without authentication. Further, refer to... Figure 3 In section S303, the target IPv6 address is assigned. This means that after an IoT device connects to the optical modem, the modem can assign a target IPv6 address to the IoT device. The first 60 bits of this target IPv6 address can be the first 60 bits of the modem's IPv6 address, the middle 4 bits are the first key generated by the modem, which can be a real-time key (i.e., a time-limited key), and the last 64 bits are the physical identification information of the IoT device.
[0062] When an IoT device is connected to an optical modem, the optical modem can obtain the physical identification information of the IoT device.
[0063] S202, Send a connection request to the management platform device of the IoT device.
[0064] The connection request carries the target IPv6 address.
[0065] Reference Figure 3 S304 in the context of connection requests. In this process, after receiving the target IPv6 address assigned by the optical modem, the IoT device can send the target IPv6 address to the management platform device.
[0066] The connection request is used to instruct the management platform device to determine the communication operator based on the first 60 bits of the target IPv6 address and send the target IPv6 address to the communication operator. The communication operator uses the target IPv6 address to determine the optical modem device and sends the target IPv6 address to the optical modem device. The optical modem device uses the target IPv6 address to verify the target IPv6 address. If the verification is successful, it sends the target IPv6 address to the management platform device to verify that the target IPv6 address has been verified.
[0067] Furthermore, the target IPv6 address takes the form shown in Table 1, which illustrates the composition of the target IPv6 address.
[0068] Table 1
[0069]
[0070] Reference Figure 3 The steps are S305 to S308. Specifically: S305, send the target IPv6 address; S306, send the target IPv6 address; S307, verify the target IPv6 address; S308, send a verification success or failure message. Since IPv6 addresses do not undergo any transformation in the network, the management platform device obtains the target IPv6 address simultaneously when it receives a connection request from an IoT device. The management platform device identifies the first 60 bits of the target IPv6 address to determine which telecommunications operator it originates from, and then sends the target IPv6 address to that operator. The telecommunications operator can identify the optical modem device based on the first 60 bits of the target IPv6 address and then send the target IPv6 address to the optical modem device. The optical modem device compares the received target IPv6 address with the previously generated target IPv6 address. If the verification is successful, the optical modem device sends a verification success message to the management platform device and changes the connection status of the IoT device to secure. If the verification fails, the optical modem will send a verification failure message to the management platform and change the connection status of the IoT device to insecure.
[0071] In this embodiment of the application, if the target IPv6 address is maliciously modified in any of the stages S304 to S307, the verification of the target IPv6 address will fail, thereby ensuring the security of the IoT device connection management platform device.
[0072] S203: Connect to the management platform device if the target IPv6 address is verified successfully.
[0073] Among them, reference Figure 3 S309, Connection Response. If the management platform device determines that the target IPv6 address has been successfully verified, the connection response agrees to the IoT device connecting to the management platform device. If the management platform device determines that the target IPv6 address has not been successfully verified, the connection response disagrees with the IoT device connecting to the management platform device.
[0074] Furthermore, if the management platform device receives a successful verification message from the optical modem device, it determines that the target IPv6 address has been successfully verified. If the management platform device does not receive a successful verification message from the optical modem device, it determines that the target IPv6 address has failed verification.
[0075] Furthermore, it also includes, under preset conditions, the step of obtaining the target IPv6 address sent by the optical modem device after restarting the IoT device; the preset conditions include: the management platform device determines that the target IPv6 address verification fails relative to the target IPv6 address, the IoT device and the management platform device are not connected for a preset period of time, and the duration from the time the target IPv6 address is allocated to the current time is greater than the effective usage duration of the first key.
[0076] In this embodiment of the application, after the target IPv6 address is verified, the management platform device obtains the verification result sent by the optical modem device and then connects normally with the IoT device, and then performs relevant interactions with the IoT device.
[0077] Specifically, if the target IPv6 address fails to be verified, the management platform device, upon receiving the verification failure result from the optical modem device, rejects the connection request from the IoT device. The IoT device then needs to restart and re-execute steps S201 to S203 to obtain a new target IPv6 address assigned by the terminal optical modem device. Once the target IPv6 address is successfully verified, the device connects to the management platform device.
[0078] Furthermore, for IoT devices that do not connect to the management platform device within a preset time period, the IoT device needs to be restarted. Then, the IoT device re-executes S201 to S203 to obtain a new target IPv6 address assigned by the terminal optical modem device. After the target IPv6 address is verified, it connects to the management platform device.
[0079] In addition, for IoT devices that are normally connected to the management platform device, their authentication results are only valid for a certain period of time (based on the generation time of the 4-digit key and the corresponding validity period). After the validity period expires, the IoT device needs to re-execute S201 to S203 to obtain a new target IPv6 address assigned by the terminal optical modem device. After the target IPv6 address is verified, it connects to the management platform device.
[0080] In this embodiment of the application, the effective duration can be set to one month, one quarter, half a year or one year. For example, after the IoT device is connected to the management platform device, it needs to re-execute the above steps to re-establish the connection with the management platform device every six months.
[0081] In this embodiment of the application, the telecommunications operator makes full use of the scalability of the 128-bit IPv6 address and divides the 128-bit IPv6 address into three parts: a 60-bit optical modem device address, a 4-bit home optical modem first key, and a 64-bit physical identification information of the IoT device. This enables the IoT device to connect to the management platform device without authentication, while also ensuring that the management platform device protects the information security of the IoT device.
[0082] Reference Figure 4 This application provides another method for connecting IoT devices, applied to optical modem devices, specifically including the following steps:
[0083] S401 generates a target IPv6 address when an IoT device is connected to an optical modem.
[0084] The first 60 bits of the target IPv6 address are assigned by the telecommunications operator to the optical modem, the last 64 bits of the target IPv6 address are the identification information of the IoT device, and the middle 4 bits of the target IPv6 address are the first key assigned by the optical modem to the IoT device.
[0085] S402 sends the target IPv6 address to the IoT device.
[0086] S403, Receive the target IPv6 address sent by the management platform device through the telecommunications operator.
[0087] The target IPv6 address is carried in the connection request sent by the IoT device to the management platform device.
[0088] S404 verifies the target IPv6 address based on the target IPv6 address, and sends a verification success indication to the associated platform device if the target IPv6 address is successfully verified.
[0089] The verification pass indicator is used to instruct the management platform device to accept the connection of the IoT device.
[0090] Among them, verifying the target IPv6 address based on the target IPv6 address includes:
[0091] If the last 64 bits of the target IPv6 address are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key, the target IPv6 address verification is successful.
[0092] Furthermore, the first key corresponds to a verification validity period. If the last 64 bits of the target IPv6 address are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key, the target IPv6 address is determined to be verified successfully. This includes: if the verification validity period has not expired, and the last 64 bits of the target IPv6 address are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key, the target IPv6 address is determined to be verified successfully.
[0093] The validity period for verification is such as 1 hour or 1 day.
[0094] Furthermore, it also includes: determining that the target IPv6 address verification failed when the verification validity period expires, or when the last 64 bits of the target IPv6 address are not the identification information of the IoT device, or when the middle 4 bits of the target IPv6 address are not the first key; and sending a verification failure indication to the management platform device, which is used to instruct the management platform device to reject the connection of the IoT device.
[0095] In this embodiment, the optical modem can verify whether the current time is within the valid verification period of the first key. If so, it verifies the target IPv address; otherwise, it directly determines that the target IPv address has failed verification. When verifying the target IPv address, it can verify only the middle four bits (the first key) and the last 64 bits (the IoT device's identification information). If both the middle four bits and the last 64 bits are correct, the optical modem replies to the management platform that the device verification is successful and changes the IoT device's connection status to secure. If either the password bits or the IoT device's identification information are incorrect, the optical modem replies to the management platform that the device verification failed and changes the IoT device's connection status to insecure. If the first key has expired and the optical modem has not yet received the target IPv address from the telecommunications operator, it also changes the IoT device's connection status to insecure.
[0096] Other details can be found in the above embodiments and will not be repeated here.
[0097] In this embodiment of the application, the telecommunications operator makes full use of the scalability of the 128-bit IPv6 address and divides the 128-bit IPv6 address into three parts: a 60-bit optical modem device address, a 4-bit home optical modem first key, and a 64-bit physical identification information of the IoT device. This enables the IoT device to connect to the management platform device without authentication, while also ensuring that the management platform device protects the information security of the IoT device.
[0098] Figure 5 This is a structural block diagram of the connection device 50 for an IoT device provided in an embodiment of this application. Figure 5 As shown, the IoT device connection device 50 provided in this application is applied to IoT devices and includes:
[0099] The acquisition module 51 is used to acquire the target IPv6 address sent by the optical modem when the optical modem is connected. The first 60 bits of the target IPv6 address are assigned by the telecommunications operator to the optical modem, the last 64 bits of the target IPv6 address are the identification information of the IoT device, and the middle 4 bits of the target IPv6 address are the first key assigned by the optical modem to the IoT device.
[0100] Sending module 52 is used to send a connection request to the management platform device of the Internet of Things device, the connection request carrying the target IPv6 address;
[0101] The connection module 53 is used to connect to the management platform device after the management platform device determines that the target IPv6 address has been verified.
[0102] Optionally, the connection request is used to instruct the management platform device to determine the communication operator based on the first 60 bits of the target IPv6 address and send the target IPv6 address to the communication operator. The communication operator is used to determine the optical modem device based on the target IPv6 address and send the target IPv6 address to the optical modem device. The optical modem device is used to verify the target IPv6 address. If the verification is successful, it sends a message to the management platform device that the target IPv6 address has been verified relative to the target IPv6 address.
[0103] Optionally, the execution module (not shown) is used to perform the step of obtaining the target IPv6 address sent by the optical modem device after restarting the IoT device under preset conditions; the preset conditions include: the management platform device determines that the target IPv6 address verification fails relative to the target IPv6 address, the IoT device and the management platform device are not connected for a preset period of time, and the duration from the time of allocating the target IPv6 address to the current time is greater than the effective usage duration of the first key.
[0104] The connection device for the Internet of Things device provided in this application can execute the technical solution of any of the aforementioned methods. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0105] Figure 6 This is a structural block diagram of the connection device 60 for an IoT device provided in an embodiment of this application. Figure 6 As shown, the IoT device connection device 60 provided in this application is applied to an optical modem device and includes:
[0106] The generation module 61 is used to generate a target IPv6 address when the IoT device is connected to the optical modem device. The first 60 bits of the target IPv6 address are assigned by the telecommunications operator to the optical modem device, the last 64 bits of the target IPv6 address are the identification information of the IoT device, and the middle 4 bits of the target IPv6 address are the first key assigned by the optical modem device to the IoT device.
[0107] Sending module 62 is used to send the target IPv6 address to the Internet of Things device;
[0108] The receiving module 63 is used to receive the target IPv6 address sent by the management platform device through the communication operator. The target IPv6 address is carried in the connection request sent by the IoT device to the management platform device.
[0109] The verification module 64 is used to verify the target IPv6 address based on the target IPv6 address, and send a verification pass indication to the associated platform device if the target IPv6 address is verified successfully. The verification pass indication is used to instruct the management platform device to accept the connection of the IoT device.
[0110] Optionally, the verification module 64 is specifically used to: determine that the target IPv6 address has been verified if the last 64 bits of the target IPv6 address are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key.
[0111] Optionally, the first key corresponds to a verification validity period. When the verification module 64 determines that the target IPv6 address has been verified, if the last 64 bits of the target IPv6 address are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key, it is specifically used to: determine that the target IPv6 address has been verified if the last 64 bits of the target IPv6 address are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key, provided that the verification validity period has not expired.
[0112] Optionally, the verification module 64 is further configured to: determine that the verification of the target IPv6 address has failed if the verification validity period expires, or if the last 64 bits of the target IPv6 address are not the identification information of the IoT device or the middle 4 bits of the target IPv6 address are not the first key; and send a verification failure indication to the management platform device, the verification failure indication being used to instruct the management platform device to reject the connection of the IoT device.
[0113] Figure 7This is a schematic diagram of the structure of an electronic device provided in an example embodiment of this disclosure. For example... Figure 7 As shown, the electronic device 70 includes a processor 71 and a memory 72 communicatively connected to the processor 71, the memory 72 storing computer execution instructions.
[0114] The electronic device provided in this application can execute any of the aforementioned methods, and its implementation principle and technical effect are similar, so they will not be described again here.
[0115] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, is used to implement the technical solutions in any of the aforementioned methods.
[0116] This application provides a computer program product, including a computer program that, when executed by a processor, implements the technical solutions in any of the aforementioned methods.
[0117] This application also provides a chip, including: a processing module and a communication interface, wherein the processing module is capable of executing the technical solutions in the aforementioned method.
[0118] Furthermore, the chip also includes a storage module (e.g., a memory), which is used to store instructions, and a processing module is used to execute the instructions stored in the storage module. The execution of the instructions stored in the storage module causes the processing module to execute the technical solution in the aforementioned method.
[0119] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly manifested as execution by a hardware processor, or execution by a combination of hardware and software modules within the processor.
[0120] The memory may include high-speed RAM, and may also include non-volatile storage (NVM), such as at least one disk storage device, and may also be a USB flash drive, external hard drive, read-only memory, disk or optical disc, etc.
[0121] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0122] The aforementioned storage medium can be implemented from any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium can be any available medium accessible to general-purpose or special-purpose computers.
[0123] An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Alternatively, the storage medium can be an integral part of the processor. Both the processor and the storage medium can reside in an application-specific integrated circuit (ASIC). Alternatively, the processor and storage medium can exist as discrete components in an electronic device.
[0124] Finally, it should be noted that the above descriptions are only used to illustrate the technical solutions of this application and are not intended to limit them. Although this application has been described in detail with reference to the foregoing, those skilled in the art should understand that modifications can still be made to the technical solutions described above, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of this application.
Claims
1. A method for connecting an Internet of Things (IoT) device, characterized in that, Applied to Internet of Things (IoT) devices, the connection method of the IoT devices includes: When connected to an optical modem, obtain the target IPv6 address sent by the optical modem. The first 60 bits of the target IPv6 address are assigned by the telecommunications operator to the optical modem, the last 64 bits of the target IPv6 address are the identification information of the IoT device, and the middle 4 bits of the target IPv6 address are the first key assigned by the optical modem to the IoT device. Send a connection request to the management platform device of the IoT device, the connection request carrying the target IPv6 address; If the management platform device determines that the target IPv6 address has been verified, then connect to the management platform device.
2. The connection method for IoT devices according to claim 1, characterized in that, The connection request instructs the management platform device to determine the communication operator based on the first 60 bits of the target IPv6 address and send the target IPv6 address to the communication operator. The communication operator determines the optical modem based on the target IPv6 address and sends the target IPv6 address to the optical modem. The optical modem verifies the received target IPv6 address. If the verification is successful, it sends a message to the management platform device indicating that the target IPv6 address received by the optical modem has been verified relative to the previously generated target IPv6 address.
3. The connection method for IoT devices according to claim 1 or 2, characterized in that, Also includes: Under preset conditions, the step of obtaining the target IPv6 address sent by the optical modem device is performed after the IoT device is restarted; The preset conditions include: when the management platform device determines that the target IPv6 address received by the optical modem fails to be verified relative to the previously generated target IPv6 address, when the IoT device and the management platform device are not connected for a preset time period, and when the duration from the time the target IPv6 address was allocated to the current time is greater than the effective usage duration of the first key.
4. A method for connecting an Internet of Things (IoT) device, characterized in that, The connection method of the IoT device, applied to optical modem devices, includes: When an IoT device is connected to the optical modem, a target IPv6 address is generated. The first 60 bits of the target IPv6 address are assigned by the telecommunications operator to the optical modem, the last 64 bits of the target IPv6 address are the identification information of the IoT device, and the middle 4 bits of the target IPv6 address are the first key assigned by the optical modem to the IoT device. Send the target IPv6 address to the IoT device; The receiving management platform device receives a target IPv6 address sent by a communication operator, the target IPv6 address being carried in the connection request sent by the IoT device to the management platform device; Based on the previously generated target IPv6 address, the IoT device verifies the target IPv6 address received by the IoT device. If the target IPv6 address received by the IoT device is successfully verified, a verification success indication is sent to the management platform device. The verification success indication is used to instruct the management platform device to accept the connection of the IoT device.
5. The connection method for IoT devices according to claim 4, characterized in that, The step of verifying the target IPv6 address received by the IoT device based on the previously generated target IPv6 address includes: If the last 64 bits of the target IPv6 address received by the IoT device are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key, it is determined that the target IPv6 address received by the IoT device has been verified.
6. The connection method for IoT devices according to claim 5, characterized in that, The first key corresponds to a verification validity period. The step of determining that the verification of the target IPv6 address received by the IoT device is successful if the last 64 bits of the target IPv6 address received by the IoT device are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key includes: If the verification validity period has not expired, and the last 64 bits of the target IPv6 address received by the IoT device are the identification information of the IoT device and the middle 4 bits of the target IPv6 address are the first key, it is determined that the verification of the target IPv6 address received by the IoT device is successful.
7. The connection method for IoT devices according to claim 6, characterized in that, Also includes: If the verification validity period expires, or the last 64 bits of the target IPv6 address received by the IoT device are not the identification information of the IoT device, or the middle 4 bits of the target IPv6 address are not the first key, it is determined that the verification of the target IPv6 address received by the IoT device has failed. A verification failure indication is sent to the management platform device, which is used to instruct the management platform device to reject the connection of the IoT device.
8. A connection device for an Internet of Things (IoT) device, characterized in that, Applied to Internet of Things (IoT) devices, the connection device of the IoT device includes: The acquisition module is used to acquire the target IPv6 address sent by the optical modem when the optical modem is connected. The first 60 bits of the target IPv6 address are assigned by the telecommunications operator to the optical modem, the last 64 bits of the target IPv6 address are the identification information of the IoT device, and the middle 4 bits of the target IPv6 address are the first key assigned by the optical modem to the IoT device. The sending module is used to send a connection request to the management platform device of the IoT device, wherein the connection request carries the target IPv6 address; A connection module is used to connect to the management platform device when the management platform device determines that the target IPv6 address has been verified.
9. A connection device for an Internet of Things (IoT) device, characterized in that, The connection device of the IoT device, applied to optical modem equipment, includes: The generation module is used to generate a target IPv6 address when an IoT device is connected to the optical modem. The first 60 bits of the target IPv6 address are assigned by the telecommunications operator to the optical modem, the last 64 bits of the target IPv6 address are the identification information of the IoT device, and the middle 4 bits of the target IPv6 address are the first key assigned by the optical modem to the IoT device. The sending module is used to send the target IPv6 address to the IoT device; The receiving module is used to receive the target IPv6 address sent by the management platform device through the communication operator. The target IPv6 address is carried in the connection request sent by the IoT device to the management platform device. The verification module is used to verify the target IPv6 address received by the IoT device based on the previously generated target IPv6 address, and if the target IPv6 address received by the IoT device is successfully verified, it sends a verification success indication to the management platform device, which is used to instruct the management platform device to accept the connection of the IoT device.
10. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the electronic device to perform the connection method of the Internet of Things device according to any one of claims 1 to 7.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the connection method of the Internet of Things device according to any one of claims 1 to 7.
Citation Information
Patent Citations
Compression of internet protocol version 6 addresses in wireless sensor networks
CN105450789A
Method for safety switching of mobile terminal between wireless local net access nodes
CN1482832A