Device authentication method, device, computer device and storage medium thereof
Through the device authentication relationship network screening and authentication, the authentication of master and slave devices is directly completed, solving the problem of cumbersome authentication process of multi-device and achieving rapid authentication.
Patent Information
- Application Number
- CN202310822630.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-05
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2043-07-05
AI Technical Summary
In the prior art, the multi-device authentication process is complicated and requires the use of a third-party platform, resulting in a lot of time consumption.
By receiving the authentication request from the master device, using the device authentication relationship network to screen the authentication relationship, and performing device authentication based on the device authentication relationship, including judging the authentication level and determining the authentication strategy, and directly completing the authentication of the master and slave devices.
It realizes the rapid completion of equipment authentication without a third-party platform, reducing the cumbersomeness of the authentication process and reducing time consumption.
Smart Images

Figure CN116707972B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of wireless communication technology, and in particular to a device authentication method, apparatus, computer equipment, and storage medium thereof. Background Art
[0002] With the continuous development of the Internet, users are able to realize more and more functions through various devices. In order to further improve the user experience, multiple devices can be authenticated and connected, thereby realizing remote control and coordinated use of multiple devices.
[0003] However, when authenticating multiple devices, a third-party platform is usually required, so the authentication process is relatively cumbersome and takes a long time to complete the authentication operation. Summary of the Invention
[0004] Based on this, it is necessary to provide a device authentication method, apparatus, computer device and storage medium thereof that can quickly complete device-to-device authentication operations in response to the above technical problems.
[0005] In a first aspect, the present application provides a device authentication method. The method comprises:
[0006] Receive an authentication request sent by the master device, where the authentication request includes a master device identifier of the master device and a slave device identifier of the slave device;
[0007] Screening the device authentication relationship network based on the master device identifier and the slave device identifier in the authentication request;
[0008] If a device authentication relationship between a master device and a slave device is found, device authentication is performed on the master device and the slave device based on the device authentication relationship.
[0009] In one embodiment, performing device authentication on a master device and a slave device based on a device authentication relationship includes:
[0010] Determine whether the certification level corresponding to the device certification relationship meets the certification level requirements;
[0011] If the conditions are met, the master device and the slave device are authenticated based on the device authentication relationship.
[0012] In one embodiment, performing device authentication on the master device and the slave device based on the authentication relationship between the master device and the slave device further includes:
[0013] If not, then determine the authentication policies corresponding to the master device and the slave device based on the device type of the master device and the device type of the slave device;
[0014] Based on each authentication policy, device authentication is performed on the master device and the slave device.
[0015] In one embodiment, determining whether the authentication level corresponding to the device authentication relationship meets the authentication level requirement includes:
[0016] Determine the number of devices included in the device authentication relationship based on the authentication level corresponding to the device authentication relationship;
[0017] Determine the quantity threshold corresponding to the certification level requirement. If the number of devices included in the device authentication relationship is greater than the quantity threshold, determine that the certification level corresponding to the device authentication relationship does not meet the certification level requirement; if the number of devices included in the device authentication relationship is less than or equal to the quantity threshold, determine that the certification level corresponding to the device authentication relationship meets the certification level requirement.
[0018] In one embodiment, the method further comprises:
[0019] Get the connection relationship between devices;
[0020] Based on the connection relationship between each device, a device authentication relationship network is constructed.
[0021] In one embodiment, the method further comprises:
[0022] If no device authentication relationship between the master device and the slave device is found, then the authentication policies corresponding to the master device and the slave device are determined based on the device types of the master device and the slave device;
[0023] Based on each authentication policy, device authentication is performed on the master device and the slave device.
[0024] In a second aspect, the present application also provides a device authentication apparatus. The apparatus includes:
[0025] A receiving module, configured to receive an authentication request sent by a master device, wherein the authentication request includes a master device identifier of the master device and a slave device identifier of the slave device;
[0026] A screening module is used to screen the device authentication relationship network based on the master device identifier and the slave device identifier in the authentication request;
[0027] The first authentication module is configured to perform device authentication on the master device and the slave device based on the device authentication relationship if a device authentication relationship between the master device and the slave device is found.
[0028] In a third aspect, the present application further provides a computer device comprising a memory and a receiver, wherein the memory stores a computer program, and a processor executes the computer program to implement the device authentication method according to any embodiment of the first aspect.
[0029] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the device authentication method according to any one of the embodiments of the first aspect.
[0030] In a fifth aspect, the present application further provides a computer program product, comprising a computer program, which, when executed by a processor, implements the device authentication method according to any one of the embodiments of the first aspect.
[0031] The above-mentioned device authentication method, apparatus, computer device, and storage medium thereof, by receiving an authentication request sent by a master device, implements screening to obtain a device authentication relationship based on the master device identifier and slave device identifier in the authentication request, and then performs device authentication on the master device and slave device based on the device authentication relationship. Because the above process can complete device authentication between devices without going through a third-party platform, when device authentication of the master device and the slave device is required, the master device and the slave device can be quickly authenticated based on the device authentication relationship in the device authentication relationship network, thereby reducing the complexity of the authentication process and the time consumed in authenticating the master device and the slave device. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 An application environment diagram of a device authentication method provided in an embodiment of the present application;
[0033] Figure 2 A schematic diagram of a device authentication method provided in an embodiment of the present application;
[0034] Figure 3 A schematic diagram of the structure of a device authentication relationship network provided in an embodiment of the present application;
[0035] Figure 4 A schematic diagram of a process for authenticating a master device and a slave device according to an embodiment of the present application;
[0036] Figure 5 A schematic diagram of a process for verifying authentication level requirements provided in an embodiment of the present application;
[0037] Figure 6 A schematic diagram of another device authentication network structure provided in an embodiment of the present application;
[0038] Figure 7 A schematic diagram of a process for determining a device authentication relationship network provided in an embodiment of the present application;
[0039] Figure 8 A schematic diagram of a production equipment authentication network provided in an embodiment of the present application;
[0040] Figure 9 A flowchart of another device authentication method provided in an embodiment of the present application;
[0041] Figure 10 A flowchart of a device authentication method provided in an embodiment of the present application;
[0042] Figure 11 A structural block diagram of the first device authentication apparatus provided in an embodiment of the present application;
[0043] Figure 12 A structural block diagram of the second device authentication apparatus provided in an embodiment of the present application;
[0044] Figure 13 A structural block diagram of the third device authentication apparatus provided in an embodiment of the present application;
[0045] Figure 14 A structural block diagram of the fourth device authentication apparatus provided in an embodiment of the present application;
[0046] Figure 15 A structural block diagram of the fifth device authentication apparatus provided in an embodiment of the present application;
[0047] Figure 16 A structural block diagram of the sixth device authentication apparatus provided in an embodiment of the present application;
[0048] Figure 17 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0049] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0050] The device authentication method provided in the embodiment of the present application can be applied to Figure 1In the application environment shown. Among them, multiple devices 102 communicate with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or it can be placed on the cloud or other network servers. Receive the authentication request sent by the master device, and according to the authentication request, filter and obtain the device authentication relationship between the master device and the slave device, and then perform device authentication on the master device and the slave device based on the device authentication relationship. Among them, each device 102 can be but is not limited to various personal computers, laptops, smart phones, tablets, Internet of Things devices and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart car-mounted devices, etc. Portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server 104 can be implemented as an independent server or a server cluster consisting of multiple servers. Among them, each device 102 can be the master device or slave device of this application.
[0051] In one embodiment, Figure 2 As shown, a device authentication method is provided, which is applied to Figure 1 The following steps are used as an example to illustrate the server in the example:
[0052] Step 201: Receive an authentication request sent by a master device, where the authentication request includes a master device identifier of the master device and a slave device identifier of a slave device.
[0053] The master device identifier refers to an identifier corresponding to the master device that serves as an identity recognition function; the slave device identifier refers to an identifier corresponding to the slave device that serves as an identity recognition function.
[0054] It should be noted that after obtaining the master device identifier of the master device and the slave device identifier of the slave device through the authentication request, the validity of the master device identifier and the slave device identifier can be verified to determine whether the master device identifier and the slave device identifier are missing during the sending process. If the validity verification of the master device identifier and the slave device identifier is passed, subsequent operations are performed based on the master device identifier and the slave device identifier; if the validity verification of any of the master device identifier and the slave device identifier fails, a problem report is fed back to the master device, and the problem report indicates that the validity verification of the master device identifier and the slave device identifier fails.
[0055] In one embodiment of the present application, a standard identification structure corresponding to the device identification can be obtained, and the validity of the master device identification and the slave device identification can be verified based on the standard identification structure, so as to verify whether the identification structure of the master device identification and the slave device identification conforms to the standard identification structure; if the identification structure of the master device identification and the slave device identification both conforms to the standard identification structure, the identification validity verification passes, and then, subsequent operations are performed based on the master device identification and the slave device identification.
[0056] As an implementation method, if the identification structure of the master device identification does not conform to the standard identification structure, while the identification structure of the slave device identification conforms to the standard identification structure, the identification validity verification fails, and a problem report is fed back to the master device, and the problem report indicates that the identification structure of the master device identification does not conform to the standard identification structure.
[0057] As another implementation method, if the identification structure of the master device identifier conforms to the standard identification structure, but the identification structure of the slave device identifier does not conform to the standard identification structure, the identification validity verification fails, and a problem report is fed back to the master device, and the problem report indicates that the identification structure of the slave device identifier does not conform to the standard identification structure.
[0058] As another implementation method, if the identification structure of the master device identifier and the identification structure of the slave device identifier do not conform to the standard identification structure, the identification validity verification fails, and a problem report is fed back to the master device, and the problem report indicates that the identification structure of the master device identifier and the slave device identifier do not conform to the standard identification structure.
[0059] It should be noted that, depending on the type of device, device identifiers with different composition structures may be assigned to devices of different types.
[0060] For example, the device label corresponding to a communication device can be an eight-character label consisting of numbers; the device label corresponding to a home appliance device can be a five-character label consisting of lowercase letters; and the device label corresponding to a toy device can be a five-character label consisting of uppercase letters. Among them, communication devices can include but are not limited to: landlines, mobile phones, smart watches, etc.; home appliances can include but are not limited to: air conditioners, televisions, etc.; toy devices can include but are not limited to: robot toys, car toys, etc.
[0061] In one embodiment of the present application, since the device tags corresponding to different types of devices are different, when verifying the validity of the device tag, the type of the master device and the device type of the slave device can be identified based on the master device tag and the slave device tag included in the authentication request, and then the identification result is sent to the master device for confirmation. If the result received from the master device is: "The type identification is correct and the device tag is correct", subsequent operations are performed according to the master device identifier and the slave device identifier; if the result received from the master device is: "The type identification is wrong and the device tag has an error", the authentication request sent by the master device is received again.
[0062] To further illustrate, when the type of the master device and / or the slave device cannot be identified based on the master device tag and / or the slave device tag, a tag acquisition request is directly sent to the master device, so that the master device sends an authentication request again.
[0063] Step 202: Screen the device authentication relationship network based on the master device identifier and the slave device identifier in the authentication request.
[0064] It should be noted that the device authentication relationship network includes the device authentication relationship between at least two devices; wherein the structure of the device authentication relationship network is as follows: Figure 3 As shown, the device authentication relationship includes direct authentication relationship and indirect authentication relationship.
[0065] Specifically, a direct authentication relationship refers to the authentication between two devices without going through other devices, such as Figure 3 Device A-Device B, Device A-Device C, etc. Indirect authentication relationships refer to authentication achieved by two devices through connections with other devices, such as Device A-Device D, Device A-Device E, etc.
[0066] In one embodiment of the present application, when the device authentication relationship network is screened for authentication relationships, the master device and the slave device in the device authentication relationship network are first located through the master device identifier and the slave device identifier to determine whether the master device and the slave device exist in the device authentication relationship network; if both the master device and the slave device exist in the device authentication relationship network, then it is determined whether there is a device authentication relationship between the master device and the slave device in the device authentication relationship network.
[0067] Specifically, when determining whether there is a device authentication relationship between the master device and the slave device in the device authentication relationship network, it can be determined whether there is a direct authentication relationship between the master device and the slave device. If there is no direct authentication relationship between the master device and the slave device, it is determined whether there is an indirect direct authentication relationship between the master device and the slave device.
[0068] Furthermore, if a direct authentication relationship or an indirect direct authentication relationship exists between the master device and the slave device, the device authentication relationship between the master device and the slave device can be filtered out in the device authentication relationship network. If neither a direct authentication relationship nor an indirect direct authentication relationship exists between the master device and the slave device, the device authentication relationship between the master device and the slave device cannot be filtered out in the device authentication relationship network.
[0069] Step 203: If a device authentication relationship between the master device and the slave device is found, device authentication is performed on the master device and the slave device based on the device authentication relationship.
[0070] It should be noted that when it is determined that there are master devices and slave devices in the device authentication relationship network, and it is determined that there is a device authentication relationship between the master device and the slave device in the device authentication relationship network, the device authentication relationship between the master device and the slave device is determined to be screened.
[0071] To further illustrate, when performing device authentication on the master device and the slave device based on the device authentication relationship, it can be pre-determined whether the device authentication relationship is a direct authentication relationship or an indirect authentication relationship, and then different authentication methods can be used for the master device and the slave device according to the different device authentication relationships.
[0072] As an implementation method, if the master device and the slave device are in a direct authentication relationship, device authentication of the master device and the slave device can be directly completed.
[0073] As another implementation method, if the master device and the slave device are in an indirect authentication relationship, the number of devices included in the indirect authentication relationship between the master device and the slave device is determined, and the number of devices is compared with a pre-set number threshold, and then the device authentication method of the master device and the slave device is determined based on the comparison result.
[0074] In one embodiment of the present application, if it is predetermined that when the number of devices included in the indirect authentication relationship between the master device and the slave device is less than a quantity threshold, the authentication process of the master device and the slave device is considered safe, and conversely, when the number of devices included in the indirect authentication relationship between the master device and the slave device is greater than or equal to the quantity threshold, the authentication process of the master device and the slave device is considered to have hidden dangers; therefore, when the number of devices included in the indirect authentication relationship is less than the quantity threshold, the device authentication of the master device and the slave device can be completed directly. When the number of devices included in the indirect authentication relationship is greater than or equal to the quantity threshold, it is necessary to determine the device type of the master device and the device type of the slave device, and determine the authentication policy based on the device type of the master device and the device type of the slave device, so as to perform device authentication on the master device and the slave device according to the authentication policy.
[0075] Authentication strategies refer to the authentication methods between different types of devices; for example, authentication methods between communication devices and home appliances, and authentication methods between communication devices.
[0076] As an example, when device authentication between communication devices is required according to the authentication policy, communication device A sends an encrypted code to communication device B, and communication device B can decrypt the encryption method of the code. If communication device A receives the code fed back by communication device B, and the fed-back code is the correct code, it is determined that the authentication process between communication device A and communication device B is secure, and the device authentication of communication device A and communication device B can be completed directly.
[0077] To further illustrate, the master device and the slave device may be authenticated via CoAP (The Constrained Application Protocol, a computer protocol) protocol communication.
[0078] The above-mentioned device authentication method receives an authentication request from a master device, filters and obtains a device authentication relationship based on the master device identifier and slave device identifier in the authentication request, and then performs device authentication on the master and slave devices based on the device authentication relationship. Because the above process can complete device authentication between devices without going through a third-party platform, when device authentication is required for the master and slave devices, the master and slave devices can be quickly authenticated based on the device authentication relationship in the device authentication relationship network, reducing the complexity of the authentication process and the time consumed in authenticating the master and slave devices.
[0079] It should be noted that if the device authentication relationship between the master device and the slave device is not screened out, the device authentication of the master device and the slave device may include the following contents: If the device authentication relationship between the master device and the slave device is not screened out, then based on the device type of the master device and the device type of the slave device, the authentication policies corresponding to the master device and the slave device are determined; based on each authentication policy, the master device and the slave device are authenticated.
[0080] It should be noted that if the device authentication relationship between the master device and the slave device is not screened, the following situations may occur: (1) There is no master device in the device authentication relationship network; (2) There is no slave device in the device authentication relationship network; (3) There is neither a master device nor a slave device in the device authentication relationship network; (4) There are a master device and a slave device in the device authentication relationship network, but there is no device authentication relationship between the master device and the slave device.
[0081] In one embodiment of the present application, if the device authentication relationship between the master device and the slave device is not screened out, it is considered that there is a hidden danger in the authentication process of the master device and the slave device; therefore, the device type of the master device and the device type of the slave device are determined based on a pre-set device type and authentication policy comparison table to determine the authentication policy corresponding to the device type of the master device and the device type of the slave device.
[0082] Among them, the authentication policy comparison table records different authentication policies corresponding to the device types of different master devices and different slave devices. For example, the authentication policy comparison table can record the authentication policies corresponding to the authentication between communication devices and communication devices, the authentication policies corresponding to the authentication between communication devices and home appliances, and the authentication policies corresponding to the authentication between communication devices and toy devices.
[0083] The authentication policy comparison table is constructed based on the user's historical authentication experience.
[0084] For example, if the device type of the main device is a communication device and the device type of the slave device is a toy device, therefore, through the authentication policy comparison table, the corresponding authentication policy when the communication device and the toy device are authenticated is found. The authentication policy specifically includes the following contents: obtain the authentication code set by the toy device at the factory, and log in to the control software corresponding to the toy device through the communication device, and enter the authentication code in the control software, and the toy device verifies the accuracy of the input authentication code; if the verification passes, it is determined that the authentication process of the communication device and the toy device is safe, and the device authentication of the communication device and the toy device can be completed directly at this time; if the verification fails, it is determined that there is a security risk in the authentication process between the communication device and the toy device, and the device authentication of the communication device and the toy device is stopped.
[0085] With the continuous development of the Internet, users have an increasing demand for remote control of various devices. However, when authenticating multiple devices, it is usually necessary to use a third-party platform, so the authentication process is relatively cumbersome. In order to prevent the above problem from causing users to spend more time to complete the authentication operation, this embodiment can be implemented by Figure 4 The method shown here performs device authentication on the master device and the slave device based on the device authentication relationship, specifically including the following steps:
[0086] Step 401: Determine whether the authentication level corresponding to the device authentication relationship meets the authentication level requirements. If yes, proceed to step 402; if not, proceed to step 403.
[0087] It should be noted that the authentication level can be used to indicate the degree of trustworthiness of the device authentication relationship. The higher the authentication level, the higher the degree of trustworthiness of the device authentication relationship. Conversely, the lower the authentication level, the lower the degree of trustworthiness of the device authentication relationship.
[0088] To further illustrate, the authentication level can be determined in various ways, for example, by the number of devices included in the device authentication relationship; or by the time of the most recent authentication of the slave device in the device authentication relationship; or by the distance between the master device and the slave device in the device authentication relationship. As can be seen from the above content, there are many ways to determine the authentication level. We will not elaborate on each method here. The following will explain in detail the above three situations:
[0089] As an implementation method, when determining the authentication level based on the number of devices included in the device authentication relationship, the following may be specifically included: determining the number of other devices included in the device authentication relationship between the master device and the slave device based on the device authentication relationship network; the fewer the number of other devices included in the device authentication relationship, the higher the authentication level corresponding to the device authentication relationship; the more the number of other devices included in the device authentication relationship, the lower the authentication level corresponding to the device authentication relationship.
[0090] For example, if it is pre-specified that: when the number of devices included in the device authentication relationship is 0 to 2, the authentication level corresponding to the device authentication relationship is level 3; when the number of devices included in the device authentication relationship is 3 to 5, the authentication level corresponding to the device authentication relationship is level 2; when the number of devices included in the device authentication relationship is 6 or more, the authentication level corresponding to the device authentication relationship is level 1, specifically, according to the device authentication relationship network, it is determined that the number of devices included in the device authentication relationship between the master device and the slave device is 1, then according to the pre-specified, the authentication level corresponding to the device authentication relationship is determined to be level 3.
[0091] As another implementation method, when determining the authentication level based on the time of the most recent authentication of the slave device in the device authentication relationship, it may specifically include the following contents: determining the time of the most recent authentication of the slave device based on the authentication record of the slave device; the closer the time of the most recent authentication of the slave device is to the current time, the higher the authentication level corresponding to the device authentication relationship; the farther the time of the most recent authentication of the slave device is from the current time, the lower the authentication level corresponding to the device authentication relationship.
[0092] For example, if it is pre-specified that: if the time from the last authentication of the device is within three days from the current time, the authentication level corresponding to the device authentication relationship is level 3; if the time from the last authentication of the device is between six and three days from the current time, the authentication level corresponding to the device authentication relationship is level 2; if the time from the last authentication of the device is more than six days from the current time, the authentication level corresponding to the device authentication relationship is level 1; specifically, according to the authentication record of the device, it is determined that the time of the last authentication of the device was four days ago, then according to the pre-specified, the authentication level corresponding to the device authentication relationship is determined to be level 2.
[0093] As another implementation method, when determining the authentication level based on the distance between the master device and the slave device in the device authentication relationship, it may specifically include the following contents: by performing positioning operations on the master device and the slave device, determining the coordinate positions corresponding to the master device and the slave device respectively, performing distance calculation on the coordinate position of the master device and the coordinate position of the slave device, and determining the distance between the master device and the slave device. The closer the distance between the master device and the slave device, the higher the authentication level corresponding to the device authentication relationship; the farther the distance between the master device and the slave device, the lower the authentication level corresponding to the device authentication relationship.
[0094] The coordinate positions of the master device and the slave device can be obtained by installing positioning devices on the master device and the slave device respectively; the positioning devices may include but are not limited to: GPS (Global Positioning System) module, geomagnetic signal acquisition module.
[0095] For example, if it is pre-specified that: if the distance between the master device and the slave device is less than or equal to 1 meter, the authentication level corresponding to the device authentication relationship is level 3; if the distance between the master device and the slave device is greater than 1 meter and less than or equal to 2 meters, the authentication level corresponding to the device authentication relationship is level 2; if the distance between the master device and the slave device is greater than 2 meters, the authentication level corresponding to the device authentication relationship is level 1; if the coordinate positions corresponding to the master device and the slave device are determined respectively, and the distance between the coordinate positions of the master device and the coordinate positions of the slave device is calculated, and it is determined that the distance between the master device and the slave device is 0.5 meters, then according to the pre-specified, the authentication level corresponding to the device authentication relationship is determined to be level 3.
[0096] It should be noted that when it is necessary to determine whether the authentication level corresponding to the device authentication relationship meets the authentication level requirements, a level threshold can be set in advance, and then, it is determined whether the authentication level corresponding to the device authentication relationship is greater than the level threshold. If the authentication level corresponding to the device authentication relationship is greater than the level threshold, it is determined that the authentication level corresponding to the device authentication relationship meets the authentication level requirements; and, if the authentication level corresponding to the device authentication relationship is less than or equal to the level threshold, it is determined that the authentication level corresponding to the device authentication relationship does not meet the authentication level requirements.
[0097] The level threshold may be set based on the historical experience of the staff or computer equipment, and the value range of the level threshold is not limited here.
[0098] Step 402: Perform device authentication on the master device and the slave device based on the device authentication relationship.
[0099] It should be noted that when the authentication level corresponding to the device authentication relationship meets the authentication level requirements, it means that the authentication level corresponding to the device authentication relationship is greater than the level threshold. Therefore, it can be determined that both the master device and the slave device are secure devices, so the master device and the slave device can be authenticated.
[0100] In one embodiment of the present application, when the authentication level corresponding to the device authentication relationship meets the authentication level requirements, the result that the authentication level corresponding to the device authentication relationship meets the authentication level requirements can be sent to the user in the form of an information prompt, and the user's operation feedback is received, wherein the operation feedback includes "confirm operation" and "oppose operation". When the user's operation feedback is "confirm operation", device authentication is performed on the master device and the slave device; when the user's operation feedback is "oppose operation", device authentication is stopped on the master device and the slave device.
[0101] Among them, the information reminder methods may include but are not limited to: SMS reminders, email reminders, terminal interface pop-up reminders, etc.
[0102] As an implementation method, it is pre-defined that after a notification message indicating that the authentication level corresponding to the device authentication relationship meets the authentication level requirements is sent to the user, if no "objection operation" feedback from the user is received within a preset time period, device authentication for the master and slave devices is performed by default. Specifically, when the authentication level corresponding to the device authentication relationship meets the authentication level requirements, the notification message indicating that the authentication level corresponding to the device authentication relationship meets the authentication level requirements is sent to the user, and a time calculation is performed. If no "objection operation" feedback from the user is received within the preset time period, device authentication for the master and slave devices is performed.
[0103] The setting of the preset time period can be adjusted in real time according to the actual situation and the user's usage habits, and the length of the preset time period is not limited here.
[0104] Step 403 : Determine authentication policies corresponding to the master device and the slave device based on the device types of the master device and the slave device; and perform device authentication on the master device and the slave device based on the authentication policies.
[0105] It should be noted that when the authentication level corresponding to the device authentication relationship does not meet the authentication level requirements, it means that the authentication level corresponding to the device authentication relationship is less than or equal to the level threshold. Therefore, it can be determined that there are hidden dangers in the device authentication process of the master device and the slave device, and therefore the master device and the slave device cannot be directly authenticated.
[0106] It is further explained that when it is necessary to determine the authentication policies corresponding to the master device and the slave device, at least one candidate authentication policy can be generated based on the operating instructions of the master device and the operating instructions of the slave device, respectively, and each candidate authentication policy is sent to the user, so that the user can select the authentication policies corresponding to the master device and the slave device from each candidate authentication policy; then, based on the user's selection, the authentication policies corresponding to the master device and the slave device are determined; and thus, the master device and the slave device are authenticated according to the authentication method corresponding to the authentication policy.
[0107] In one embodiment of the present application, a policy generation model can be pre-trained by inputting the operation instructions of the master device and the operation instructions of the slave device into the policy generation model and obtaining the transmission result of the policy generation model. The output result is at least one candidate authentication policy.
[0108] Furthermore, the operation instructions of multiple devices and the authentication policies of multiple devices can be used as training samples to perform model training on the initial generation model. When the training of the initial generation model is completed, the policy generation model can be obtained.
[0109] The above device authentication method determines whether the authentication level corresponding to the device authentication relationship meets the authentication level requirements, and implements security screening for the authentication of master and slave devices. This ensures that the security of device authentication is improved while ensuring that the master and slave devices can perform normal device authentication. This method reduces the level of human intervention in the authentication process, enables rapid device authentication of master and slave devices, and reduces the time consumed in authenticating master and slave devices.
[0110] In one embodiment, the number of devices included in the device authentication relationship can be determined to determine whether the authentication level corresponding to the device authentication relationship meets the authentication level requirements. The specific process is as follows: Figure 5 As shown, the method includes:
[0111] Step 501: Determine the number of devices included in the device authentication relationship according to the authentication level corresponding to the device authentication relationship.
[0112] It should be noted that when it is necessary to determine the number of devices included in the device authentication relationship, the authentication path corresponding to the device authentication relationship can be determined through the device authentication relationship network, and then the number of devices included in the authentication path can be determined to determine the number of devices included in the device authentication relationship.
[0113] The authentication path refers to the shortest path connecting the master device and the slave device in the device authentication relationship network.
[0114] For example, Figure 6 As shown, when it is necessary to determine the number of other devices included in the device authentication relationship between the master device M and the slave device N, the shortest path connecting the master device M and the slave device N in the device authentication relationship network is taken as the authentication path m, and the number of devices included in the authentication path is counted as 2. Therefore, the number of other devices included in the device authentication relationship between the master device M and the slave device N is 2.
[0115] Step 502, determine the quantity threshold corresponding to the authentication level requirement. If the number of devices included in the device authentication relationship is greater than the quantity threshold, determine that the authentication level corresponding to the device authentication relationship does not meet the authentication level requirement; if the number of devices included in the device authentication relationship is less than or equal to the quantity threshold, determine that the authentication level corresponding to the device authentication relationship meets the authentication level requirement.
[0116] Among them, the quantity threshold can be determined based on the user's historical authentication records. The setting range of the quantity threshold is not limited here, and it needs to be emphasized.
[0117] As an example, if the quantity threshold is 3, the number of devices included in the device authentication relationship 1 is 2. Since the number of devices included in the device authentication relationship is less than or equal to the quantity threshold, the authentication level corresponding to the device authentication relationship 1 meets the authentication level requirements.
[0118] As another example, if the quantity threshold is 3, the number of devices included in device authentication relationship 2 is 4. Since the number of devices included in device authentication relationship 2 is greater than the quantity threshold, the authentication level corresponding to device authentication relationship 2 does not meet the authentication level requirements.
[0119] The above-mentioned device authentication method determines the number of devices included in the device authentication relationship and compares the number of devices with the number threshold to determine whether the authentication level corresponding to the device authentication relationship meets the authentication level requirements, thereby realizing security screening for the master device and the slave device, and ensuring the smooth authentication process of the master device and the slave device.
[0120] In one embodiment, when it is necessary to determine the device authentication relationship network, the specific process is as follows: Figure 7 As shown, the method includes:
[0121] Step 701: Acquire the connection relationship between devices.
[0122] It should be noted that when it is necessary to determine the connection relationship between devices, the historical authentication records of each device can be searched to determine the records of each device successfully establishing authentication with other devices. Then, based on the records of each device successfully establishing authentication with other devices, the connection relationship between the devices can be determined.
[0123] To further explain, since some devices do not have historical authentication records, when searching the historical authentication records of each device, if it is found in the historical authentication records of device a that device a and device b have successfully established authentication, but device b cannot find the historical authentication records with device a, then it can be determined that there is a connection relationship between device a and device b.
[0124] Step 702: construct a device authentication relationship network based on the connection relationship between the devices.
[0125] It should be noted that when it is necessary to construct a device authentication relationship network, the connection relationships between the devices can be combined to complete the construction of the device authentication relationship network.
[0126] Specifically, identical devices in the connection relationships between the devices are screened out, and the connection relationships between the devices are combined based on the identical devices in the connection relationships between the devices, wherein the identical devices refer to devices that appear in at least two connection relationships.
[0127] For example, the connection relationship p corresponding to device P and the connection relationship q corresponding to device Q are both as follows Figure 8 As shown, the device K that exists in both the connection relationship p and the connection relationship q is determined. The device K is the same device in the connection relationship p and the connection relationship q. The connection relationship between the device P and the device Q is combined through the device K to construct a device authentication relationship network.
[0128] The above device authentication method realizes the determination of the device authentication relationship network through the connection relationship between each device, provides a data basis for the subsequent determination of the device authentication relationship between the master device and the slave device, and ensures that the master device and the slave device can be authenticated smoothly in the future.
[0129] In one embodiment, when it is necessary to authenticate the master device and the slave device, Figure 9 Specifically, it may include the following:
[0130] Step 901: Acquire the connection relationship between devices.
[0131] Step 902: construct a device authentication relationship network based on the connection relationship between the devices.
[0132] Step 903: Receive an authentication request sent by the master device, where the authentication request includes a master device identifier of the master device and a slave device identifier of the slave device.
[0133] Step 904: Screen the device authentication relationship network based on the master device identifier and the slave device identifier in the authentication request.
[0134] If the device authentication relationship between the master device and the slave device is found through screening, step 905 is executed; if the device authentication relationship between the master device and the slave device is not found through screening, step 910 is executed.
[0135] Step 905: Determine the number of other devices included in the device authentication relationship according to the authentication level corresponding to the device authentication relationship.
[0136] Step 906 determines the quantity threshold corresponding to the authentication level requirement. Based on the relationship between the number of other devices included in the device authentication relationship and the quantity threshold, a determination is made as to whether the authentication level corresponding to the device authentication relationship meets the authentication level requirement. If so, step 909 is executed; if not, step 907 is executed.
[0137] Step 907: Perform device authentication on the master device and the slave device based on the device authentication relationship.
[0138] Step 908: Determine the authentication policies corresponding to the master device and the slave device based on the device type of the master device and the device type of the slave device.
[0139] Step 909: Perform device authentication on the master device and the slave device based on each authentication policy.
[0140] Step 910: Determine authentication policies corresponding to the master device and the slave device based on the device type of the master device and the device type of the slave device.
[0141] Step 911: Perform device authentication on the master device and the slave device based on various authentication policies.
[0142] In one embodiment of the present application, Figure 10 As shown, when device authentication of the master device and the slave device is required, the following may be specifically included: after receiving the authentication request sent by the master device, query the device authentication relationship network to determine whether a device authentication relationship exists between the master device and the slave device; if not, authenticate the master device and the slave device using conventional authentication methods; if so, verify the authentication level corresponding to the device authentication relationship; if it meets the requirements, complete the device authentication of the master device and the slave device.
[0143] It should be understood that, although the steps in the flowcharts of the above embodiments are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts of the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily to be performed in sequence, but can be performed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0144] Based on the same inventive concept, embodiments of the present application also provide a device authentication apparatus for implementing the aforementioned device authentication method. The solution provided by this apparatus is similar to the solution described in the aforementioned method. Therefore, the specific limitations in one or more device authentication apparatus embodiments provided below can be found in the limitations of the device authentication method above and will not be further elaborated here.
[0145] In one embodiment, Figure 11 As shown, a device authentication apparatus is provided, comprising: a receiving module 10, a screening module 20 and a first authentication module 30, wherein:
[0146] The receiving module 10 is configured to receive an authentication request sent by a master device, where the authentication request includes a master device identifier of the master device and a slave device identifier of the slave device.
[0147] The screening module 20 is configured to screen the device authentication relationship network for authentication relationships based on the master device identifier and the slave device identifier in the authentication request.
[0148] The first authentication module 30 is configured to perform device authentication on the master device and the slave device based on the device authentication relationship if a device authentication relationship between the master device and the slave device is found.
[0149] The device authentication apparatus receives an authentication request from a master device, filters the master device identifier and slave device identifier in the authentication request, obtains a device authentication relationship, and then authenticates the master and slave devices based on the device authentication relationship. Because inter-device authentication can be completed without going through a third-party platform, when authentication is required for the master and slave devices, rapid authentication can be performed based on the device authentication relationship in the device authentication relationship network, reducing the complexity of the authentication process and the time consumed in authenticating the master and slave devices.
[0150] In one embodiment, Figure 12 As shown, a device authentication device is provided, in which the first authentication module 30 includes: a judgment unit 31 and a first authentication unit 32, wherein:
[0151] The judging unit 31 is configured to judge whether the authentication level corresponding to the device authentication relationship meets the authentication level requirement.
[0152] The first authentication unit 32 is configured to perform device authentication on the master device and the slave device based on the device authentication relationship if the conditions are met.
[0153] In one embodiment, Figure 13As shown, a device authentication device is provided, wherein the first authentication module 30 in the device authentication device further includes: a determination unit 33 and a second authentication unit 34, wherein:
[0154] a determining unit 33 configured to determine, if the conditions are not met, authentication policies corresponding to the master device and the slave device based on the device type of the master device and the device type of the slave device;
[0155] The second authentication unit 34 is configured to perform device authentication on the master device and the slave device based on various authentication policies.
[0156] In one embodiment, Figure 14 As shown, a device authentication device is provided, in which the judgment unit 31 includes: a first determination subunit 311 and a second determination subunit 312, wherein:
[0157] The first determining subunit 311 is configured to determine the number of other devices included in the device authentication relationship according to the authentication level corresponding to the device authentication relationship.
[0158] The second determining subunit 312 is used to determine the quantity threshold corresponding to the authentication level requirement, and judge whether the authentication level corresponding to the device authentication relationship meets the authentication level requirement based on the relationship between the number of devices included in the device authentication relationship and the quantity threshold.
[0159] In one embodiment, Figure 15 As shown, a device authentication device is provided, which further includes: an acquisition module 40 and a construction module 50, wherein:
[0160] The acquisition module 40 is configured to acquire the connection relationship between the devices.
[0161] The construction module 50 is used to construct a device authentication relationship network based on the connection relationship between each device.
[0162] In one embodiment, Figure 16 As shown, a device authentication device is provided, which further includes: a determination module 60 and a second authentication module 70, wherein:
[0163] The determination module 60 is configured to determine the authentication policies corresponding to the master device and the slave device based on the device type of the master device and the device type of the slave device if no device authentication relationship between the master device and the slave device is found.
[0164] The second authentication module 70 is configured to perform device authentication on the master device and the slave device based on various authentication policies.
[0165] Each module in the device authentication apparatus described above may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in hardware form, or may be stored in a computer device memory in software form, so that the processor can call and execute the corresponding operations of each module.
[0166] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 17 As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. The processor, the memory and the input / output interface are connected via a system bus, and the communication interface, the display unit and the input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a device authentication method is implemented. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse.
[0167] Those skilled in the art will understand that Figure 17 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0168] In one embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:
[0169] Receive an authentication request sent by the master device, where the authentication request includes a master device identifier of the master device and a slave device identifier of the slave device;
[0170] Screening the device authentication relationship network based on the master device identifier and the slave device identifier in the authentication request;
[0171] If a device authentication relationship between a master device and a slave device is found, device authentication is performed on the master device and the slave device based on the device authentication relationship.
[0172] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0173] Determine whether the certification level corresponding to the device certification relationship meets the certification level requirements;
[0174] If the conditions are met, the master device and the slave device are authenticated based on the device authentication relationship.
[0175] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0176] If not, then determine the authentication policies corresponding to the master device and the slave device based on the device type of the master device and the device type of the slave device;
[0177] Based on each authentication policy, device authentication is performed on the master device and the slave device.
[0178] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0179] Determine the number of devices included in the device authentication relationship based on the authentication level corresponding to the device authentication relationship;
[0180] Determine the quantity threshold corresponding to the authentication level requirement, and judge whether the authentication level corresponding to the device authentication relationship meets the authentication level requirement based on the relationship between the number of devices included in the device authentication relationship and the quantity threshold.
[0181] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0182] Get the connection relationship between devices;
[0183] Based on the connection relationship between each device, a device authentication relationship network is constructed.
[0184] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0185] If no device authentication relationship between the master device and the slave device is found, then the authentication policies corresponding to the master device and the slave device are determined based on the device types of the master device and the slave device;
[0186] Based on each authentication policy, device authentication is performed on the master device and the slave device.
[0187] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0188] Receive an authentication request sent by the master device, where the authentication request includes a master device identifier of the master device and a slave device identifier of the slave device;
[0189] Screening the device authentication relationship network based on the master device identifier and the slave device identifier in the authentication request;
[0190] If a device authentication relationship between a master device and a slave device is found, device authentication is performed on the master device and the slave device based on the device authentication relationship.
[0191] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0192] Determine whether the certification level corresponding to the device certification relationship meets the certification level requirements;
[0193] If the conditions are met, the master device and the slave device are authenticated based on the device authentication relationship.
[0194] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0195] If not, then determine the authentication policies corresponding to the master device and the slave device based on the device type of the master device and the device type of the slave device;
[0196] Based on each authentication policy, device authentication is performed on the master device and the slave device.
[0197] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0198] Determine the number of devices included in the device authentication relationship based on the authentication level corresponding to the device authentication relationship;
[0199] Determine the quantity threshold corresponding to the authentication level requirement, and judge whether the authentication level corresponding to the device authentication relationship meets the authentication level requirement based on the relationship between the number of devices included in the device authentication relationship and the quantity threshold.
[0200] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0201] Get the connection relationship between devices;
[0202] Based on the connection relationship between each device, a device authentication relationship network is constructed.
[0203] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0204] If no device authentication relationship between the master device and the slave device is found, then the authentication policies corresponding to the master device and the slave device are determined based on the device types of the master device and the slave device;
[0205] Based on each authentication policy, device authentication is performed on the master device and the slave device.
[0206] In one embodiment, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the following steps:
[0207] Receive an authentication request sent by the master device, where the authentication request includes a master device identifier of the master device and a slave device identifier of the slave device;
[0208] Screening the device authentication relationship network based on the master device identifier and the slave device identifier in the authentication request;
[0209] If a device authentication relationship between a master device and a slave device is found, device authentication is performed on the master device and the slave device based on the device authentication relationship.
[0210] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0211] Determine whether the certification level corresponding to the device certification relationship meets the certification level requirements;
[0212] If the conditions are met, the master device and the slave device are authenticated based on the device authentication relationship.
[0213] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0214] If not, then determine the authentication policies corresponding to the master device and the slave device based on the device type of the master device and the device type of the slave device;
[0215] Based on each authentication policy, device authentication is performed on the master device and the slave device.
[0216] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0217] Determine the number of devices included in the device authentication relationship based on the authentication level corresponding to the device authentication relationship;
[0218] Determine the quantity threshold corresponding to the authentication level requirement, and judge whether the authentication level corresponding to the device authentication relationship meets the authentication level requirement based on the relationship between the number of devices included in the device authentication relationship and the quantity threshold.
[0219] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0220] Get the connection relationship between devices;
[0221] Based on the connection relationship between each device, a device authentication relationship network is constructed.
[0222] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0223] If no device authentication relationship between the master device and the slave device is found, then the authentication policies corresponding to the master device and the slave device are determined based on the device types of the master device and the slave device;
[0224] Based on each authentication policy, device authentication is performed on the master device and the slave device.
[0225] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.
[0226] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.
[0227] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0228] The above embodiments merely illustrate several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A device authentication method, characterized in that: The method comprises: receiving an authentication request sent by a master device, wherein the authentication request includes a master device identifier of the master device and a slave device identifier of the slave device; Get the standard identification structure corresponding to the device identification; Verify whether the identification structures of the master device identification and the slave device identification conform to the standard identification structure; if the identification structures of the master device identification and the slave device identification conform to the standard identification structure, determine that the validity verification of the master device identification and the slave device identification has passed; If the validity verification of the master device identifier and the slave device identifier passes, performing authentication relationship screening on the device authentication relationship network according to the master device identifier and the slave device identifier in the authentication request; wherein the device authentication relationship network includes device authentication relationships between at least two devices, and the device authentication relationships include direct authentication relationships and indirect authentication relationships; If a device authentication relationship between the master device and the slave device is found through screening, device authentication is performed on the master device and the slave device based on the device authentication relationship.
2. The method according to claim 1, characterized in that The performing device authentication on the master device and the slave device based on the device authentication relationship includes: Determining whether the authentication level corresponding to the device authentication relationship meets the authentication level requirements; If so, device authentication is performed on the master device and the slave device based on the device authentication relationship.
3. The method according to claim 2, characterized in that The performing device authentication on the master device and the slave device based on the device authentication relationship further includes: If not, determining the authentication policies corresponding to the master device and the slave device based on the device type of the master device and the device type of the slave device; Based on the authentication policies, device authentication is performed on the master device and the slave device.
4. The method according to claim 2, characterized in that The determining whether the authentication level corresponding to the device authentication relationship meets the authentication level requirement includes: Determining the number of other devices included in the device authentication relationship based on the authentication level corresponding to the device authentication relationship; Determine the quantity threshold corresponding to the authentication level requirement. If the number of devices included in the device authentication relationship is greater than the quantity threshold, determine that the authentication level corresponding to the device authentication relationship does not meet the authentication level requirement; if the number of devices included in the device authentication relationship is less than or equal to the quantity threshold, determine that the authentication level corresponding to the device authentication relationship meets the authentication level requirement.
5. The method according to claim 1, wherein The method further comprises: Get the connection relationship between devices; The device authentication relationship network is constructed based on the connection relationship between the devices.
6. The method according to claim 1, characterized in that The method further comprises: If no device authentication relationship between the master device and the slave device is found, determining authentication policies corresponding to the master device and the slave device based on the device type of the master device and the device type of the slave device; Based on the authentication policies, device authentication is performed on the master device and the slave device.
7. A device authentication apparatus, characterized in that: For implementing the device authentication method according to any one of claims 1 to 6, the apparatus comprises: A receiving module, configured to receive an authentication request sent by a master device, wherein the authentication request includes a master device identifier of the master device and a slave device identifier of the slave device; a screening module, configured to screen the device authentication relationship network for authentication relationships according to the master device identifier and the slave device identifier in the authentication request; The first authentication module is configured to perform device authentication on the master device and the slave device based on the device authentication relationship if a device authentication relationship between the master device and the slave device is found.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Node authentication method and node authentication system
CN107278364A