A device registration method and apparatus, an electronic device, and a storage medium

By generating and verifying an initial authentication token using an encryption algorithm after the device receives the password, the problem of balancing security and convenience in device registration is solved, thus improving both the security and convenience of the device registration process.

CN117061160BActive Publication Date: 2026-04-17CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER
Filing Date
2023-08-02
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In existing technologies, the initial identity authentication information of devices is manually configured by maintenance personnel, which is not secure and requires frequent updates, making it difficult to balance the security and convenience of device registration.

Method used

By generating an initial authentication token in real time using an encryption algorithm after the device receives the password, and verifying it on the platform, the reliance on maintenance personnel is reduced, and security and convenience are improved.

Benefits of technology

It improves the security and convenience of the device registration process, reduces the management difficulty and resource waste for operation and maintenance personnel, and enables timely handling of registration anomalies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117061160B_ABST
    Figure CN117061160B_ABST
Patent Text Reader

Abstract

This application relates to the field of communication technology, and more particularly to a device registration method, apparatus, electronic device, and storage medium. An embodiment of this application provides a device registration method. When a secure medium connected to the device receives a password, it reads the device identifier and, based on the stored correspondence between the password and user information, determines the first user information corresponding to the password. The secure medium processes the device identifier and the first user information using a pre-set first encryption algorithm to obtain an initial authentication token. A device registration request is sent to the platform so that the platform can determine whether the initial authentication token has passed verification. If the platform determines that the initial authentication token has passed verification, the device identity authentication information is received from the platform and written to the device. This solution improves both the security and convenience of device registration.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a device registration method, apparatus, electronic device, and storage medium. Background Technology

[0002] Device registration is closely related to whether a device can access the platform, and its security affects the platform's operational interests. During the initial registration service when a device first connects to the platform, authentication is performed between the device and the platform using initial authentication information. This initial authentication information can be an initial authentication token or a preset string. To prevent unauthorized devices from accessing the platform, the initial authentication information is typically manually configured by the device manufacturer's maintenance personnel before the device leaves the factory and then synchronized with the platform.

[0003] However, the initial authentication information manually configured by operations and maintenance personnel often fails to meet the security requirements for long-term use. Therefore, after successfully connecting to the platform for the first time, the initial authentication information needs to be updated to more secure authentication information for subsequent use.

[0004] How to improve the security and convenience of device registration is a question worth discussing. Summary of the Invention

[0005] This application provides a device registration method, apparatus, electronic device, and storage medium to improve both the security and convenience of device registration.

[0006] In a first aspect, embodiments of this application provide a device registration method. In this method, when a secure medium connected to the device receives a password, it reads the device identifier and, based on the stored correspondence between passwords and user information, determines the first user information corresponding to the password.

[0007] The device identifier and the first user information are processed using the set first encryption algorithm to obtain the initial authentication token;

[0008] Send a device registration request to the platform so that the platform can determine whether the initial authentication token has been verified. The device registration request includes the security media identifier, the device identifier, and the initial authentication token.

[0009] Once the platform confirms that the initial authentication token has passed verification, the device identity authentication information is received from the platform and written to the device.

[0010] Compared to existing technologies where the initial authentication token needs to be manually updated continuously, the above method improves the security and convenience of device registration by determining the initial authentication token in real time after receiving the password. Furthermore, since the initial authentication token does not need to be pre-installed on secure media and is invisible to maintenance personnel, the security of device registration is significantly enhanced.

[0011] Optionally, the device registration request may also include an encryption algorithm category code, which corresponds to the encryption algorithm set.

[0012] In the above method, by including the encryption algorithm category code in the device registration request, the platform can easily determine the encryption algorithm based on the correspondence between the encryption algorithm category code and the set encryption algorithm. This facilitates the platform's subsequent calculation of the verification token based on the encryption algorithm used in the secure medium, thereby improving the flexibility of using a unified encryption algorithm between the secure medium and the platform.

[0013] Secondly, embodiments of this application provide a device registration method. In this method, a platform receives a device registration request from a secure medium. The device registration request includes a secure medium identifier, a device identifier, and an initial authentication token. The initial authentication token is obtained by the secure medium using a set first encryption algorithm to calculate the device identifier and first user information. The first user information is determined by the secure medium based on the correspondence between a password and user information.

[0014] The security medium identifier, device identifier, and second user information are processed using the first encryption algorithm to obtain a verification token. The second user information is determined based on the correspondence between the stored security medium identifier and user information.

[0015] The verification token is compared with the initial authentication token to determine whether the initial authentication token has passed verification.

[0016] The above method determines whether the initial authentication token needs to be verified by comparing the verification token with the initial authentication token after receiving the device registration request. This eliminates the need for the platform to maintain initial identity authentication information for all devices; it only requires maintaining the corresponding information for a small amount of security media to perform initial authentication token verification. Compared to existing technologies that require pre-setting a large amount of device information, this reduces management complexity and resource waste.

[0017] Optionally, after determining the second user information based on the correspondence between the security medium identifier and user information, if the second user information includes multiple user information entries, the method further includes:

[0018] When the first user information is included among multiple user information, the security medium identifier, device identifier, and the first user information are processed using the first encryption algorithm to obtain a verification token;

[0019] If the first user information is not included in the multiple user information entries, a first message indicating registration failure is sent to the security medium.

[0020] In the above method, by determining whether the first user information is included among the multiple user information corresponding to the second user information, a correspondence between the security medium identifier and the first user information can be promptly determined. If the first user information is included among the multiple user information, the initial authentication token is further verified. If the first user information is not included among the multiple user information, a first message indicating registration failure is promptly sent to the security medium to prevent waste of computing resources.

[0021] Optionally, after determining the second user information based on the correspondence between the security medium identifier and user information, if the second user information includes a single user information entry, the method further includes:

[0022] When the second user information is the same as the first user information, the security medium identifier, device identifier and the second user information are processed using the first encryption algorithm to obtain the verification token;

[0023] If the second user information differs from the first user information, a first message indicating registration failure is sent to the security medium.

[0024] In the above method, by determining whether the second user information is the same as the first user information, it is possible to promptly determine whether there is a correspondence between the security medium identifier and the first user information. If the second user information is the same as the first user information, the initial authentication token is verified again. If the second user information is different from the first user information, a first message indicating registration failure is promptly sent to the security medium.

[0025] Optionally, the verification token can be compared with the initial authentication token to determine whether the initial authentication token has passed verification, specifically including:

[0026] If the verification token is the same as the initial authentication token, the device identity authentication information is sent to the secure medium.

[0027] In the above method, by sending the device identity authentication information to the security medium when the verification token is the same as the initial authentication token, the security medium can receive the device identity authentication information in a timely manner and register the device.

[0028] Optionally, comparing the verification token with the initial authentication token to determine whether the initial authentication token has passed verification also includes:

[0029] If the verification token is different from the initial authentication token, send the first message to the secure medium.

[0030] In the above method, by sending the first message to the security medium when the verification token is different from the initial authentication token, the user can promptly determine that the registration has failed.

[0031] Optionally, the device registration request may also include an encryption algorithm category code, which corresponds to the set encryption algorithm. The method may also include:

[0032] Based on the saved correspondence between encryption algorithm category codes and encryption algorithms, the first encryption algorithm corresponding to the encryption algorithm category code is determined.

[0033] In this method, by including the encryption algorithm category code in the device registration request, the platform can easily determine the encryption algorithm based on the correspondence between the encryption algorithm category code and the set encryption algorithm. Furthermore, a verification token is calculated based on the encryption algorithm used with the secure medium. This improves the flexibility of using a unified encryption algorithm between the secure medium and the platform.

[0034] Thirdly, embodiments of this application provide a device registration system. The system includes a security medium and a platform.

[0035] The security medium, when it receives a password, is used to read the device identifier and determine the first user information corresponding to the password based on the stored correspondence between the password and user information.

[0036] The security medium is also used to process the device identifier and the first user information using a set first encryption algorithm to obtain an initial authentication token;

[0037] The security medium is also used to send a device registration request to the platform so that the platform can determine whether the initial authentication token has been verified. The device registration request includes the security medium identifier, the device identifier, and the initial authentication token.

[0038] The platform is used to receive device registration requests from secure media and process the secure media identifier, device identifier, and second user information using a first encryption algorithm to obtain a verification token.

[0039] The platform is also used to compare the verification token with the initial authentication token to determine whether the initial authentication token has passed verification.

[0040] The secure medium is also used to receive device identity authentication information from the platform and write the device identity authentication information into the device, provided that the platform determines that the initial authentication token verification has passed.

[0041] Fourthly, embodiments of this application provide a device registration apparatus, the apparatus comprising:

[0042] The determination module is used to read the device identifier of the device when the security medium of the connected device receives the password, and determine the first user information corresponding to the password according to the correspondence between the stored password and user information.

[0043] The processing module is used to process the device identifier and the first user information using the set first encryption algorithm to obtain the initial authentication token;

[0044] The transceiver module is used to send a device registration request to the platform so that the platform can determine whether the initial authentication token has been verified. The device registration request includes the security medium identifier, the device identifier, and the initial authentication token.

[0045] The transceiver module is also used to receive device identity authentication information from the platform when the platform determines that the initial authentication token has been verified.

[0046] The processing module is also used to write device identity authentication information into the device.

[0047] Fifthly, embodiments of this application provide a device registration apparatus. The apparatus includes:

[0048] The transceiver module is used to receive device registration requests from the secure medium. The device registration request includes the secure medium identifier, the device identifier, and the initial authentication token. The initial authentication token is obtained by the secure medium using a set first encryption algorithm to calculate the device identifier and the first user information. The first user information is determined by the secure medium based on the correspondence between the password and the user information.

[0049] The processing module is used to process the security medium identifier, device identifier and second user information using the first encryption algorithm to obtain a verification token. The second user information is determined based on the correspondence between the security medium identifier and user information.

[0050] The determination module compares the verification token with the initial authentication token to determine whether the initial authentication token has passed verification.

[0051] In a sixth aspect, embodiments of this application also provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the computer program is executed by the processor, the processor implements any one of the device registration methods in the first to second aspects.

[0052] In a seventh aspect, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements any one of the device registration methods in the first to second aspects.

[0053] Eighthly, embodiments of this application also provide a computer program product, including a computer program that is executed by a processor to implement any of the device registration methods described in the first to second aspects above.

[0054] The technical effects of any of the implementation methods in aspects three through eight can be found in the technical effects of the corresponding implementation methods in aspects one through two, and will not be repeated here. Attached Figure Description

[0055] Figure 1 This is a schematic diagram illustrating an application scenario of a device registration method provided in an embodiment of this application;

[0056] Figure 2 A flowchart of a device registration method provided in this application embodiment;

[0057] Figure 3 A flowchart illustrating another device registration method provided in this application embodiment;

[0058] Figure 4 An exemplary flowchart of a device registration method provided in this application embodiment;

[0059] Figure 5 This is a schematic diagram of the structure of a device registration apparatus provided in an embodiment of this application;

[0060] Figure 6 This is a schematic diagram of another device registration apparatus provided in an embodiment of this application;

[0061] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0062] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0063] The application scenarios described in this application are for the purpose of more clearly illustrating the technical solutions of this application, and do not constitute a limitation on the technical solutions provided in this application. Those skilled in the art will understand that with the emergence of new application scenarios, the technical solutions provided in this application are also applicable to similar technical problems. In the description of this application, unless otherwise stated, "multiple" means two or more.

[0064] Optional, such as Figure 1 As shown in the figure, an optional application scenario diagram based on the device registration method of this application is illustrated, including a server 100 and a terminal 101. The server 100 and the terminal 101 can be connected through a network to realize the device registration method of this application.

[0065] Users can use server 100 to interact with terminal 101 via the network, such as receiving or sending messages. Various client applications can be installed on terminal 101, such as programming applications, web browser applications, search applications, etc.

[0066] It is understood that in this embodiment, the server 100 can be a standalone server or a server cluster consisting of multiple servers. The terminal 101 can be various electronic devices with a display screen and support web browsing, including but not limited to smartphones, tablets, desktop computers, etc.

[0067] Device registration is closely related to a device's ability to connect to the platform, and its security impacts the platform's operational interests. To prevent unauthorized access by external devices, the initial authentication information is typically manually configured by the device manufacturer and its maintenance personnel before the device leaves the factory and then synchronized with the platform. For example, when a quantum key distribution device (QKD) registers for the first time, both ends need to manually pre-configure consistent initial authentication information.

[0068] However, the initial authentication information manually configured by operations and maintenance personnel often fails to meet the security requirements for long-term use. Therefore, after successfully connecting to the platform for the first time, the initial authentication information needs to be updated to more secure authentication information for subsequent use.

[0069] How to improve the security and convenience of device registration is a question worth discussing.

[0070] This application provides a device registration method. When a secure medium connected to the device receives a password, it reads the device identifier and determines the first user information corresponding to the password based on the stored correspondence between passwords and user information. The secure medium processes the device identifier and the first user information using a set first encryption algorithm to obtain an initial authentication token. A device registration request is sent to the platform so that the platform can determine whether the initial authentication token has been verified. The device registration request includes a secure medium identifier, a device identifier, and an initial authentication token. If the platform determines that the initial authentication token has been verified, the device identity authentication information is received from the platform and written to the device.

[0071] This application, compared to existing technologies where the initial authentication token needs to be manually updated continuously, improves the security and convenience of device registration by determining the initial authentication token in real time after receiving the password. Furthermore, since the initial authentication information does not need to be pre-installed in the device, its existence time is shorter, and the initial authentication token is invisible to maintenance personnel, significantly increasing device registration security. Moreover, the initial authentication token is obtained by calculating the first user information, which is determined based on the correspondence between user information and the password. Therefore, in the event of abnormal device registration, this application can promptly determine the user information based on the initial authentication token, facilitating data analysis, tracing relevant maintenance personnel, and resolving accountability issues related to abnormal device registration.

[0072] like Figure 2 As shown in the figure, a device registration flowchart provided in this application embodiment may specifically include the following steps:

[0073] Step S201: When the security medium of the connected device receives the password, it reads the device identifier of the device and determines the first user information corresponding to the password based on the correspondence between the stored password and user information.

[0074] The first user information may include the user's identifier. The user's identifier is used to identify the user in a specific region. For example, the user's identifier can be the characters "Zhang San", an identity identifier, a numerical sequence, etc.

[0075] In one alternative embodiment, the maintenance personnel connect the security medium to the device and enter a password into the security medium. When the security medium connected to the device receives the password, it can read the device identifier of the device through the security medium engine.

[0076] The password can be a pre-defined string. The device identifier is used to uniquely identify the device. The device identifier can be an International Mobile Equipment Identity (IMEI), a Media Access Control Address (MAC), or a user-defined identifier. The mapping between passwords and user information can be stored in a primary database on secure media. The mapping can be many-to-one, meaning multiple passwords correspond to one user information. Alternatively, it can be one-to-one, meaning one password corresponds to one user information.

[0077] It is understood that the correspondence between passwords and user information can be pre-set by those skilled in the art. The correspondence between passwords and user information can also be changed according to specific application scenarios. This application does not impose specific limitations in this regard.

[0078] Step S202: Process the device identifier and the first user information using the set first encryption algorithm to obtain the initial authentication token.

[0079] In one alternative embodiment, the first encryption algorithm may be a cryptographic algorithm and includes a key (SK) unique to each secure medium. For example, the first encryption algorithm may include, but is not limited to, any of the following algorithms:

[0080] 1. Token = HMAC(SK, ID device || ID security medium || Hash(PW) || TS)

[0081] 2. Token = HMAC(SK, ID device || ID security medium || Hash(PW) || R)

[0082] 3. Token=E SK (ID device || ID security medium || Hash (PW) || TS)

[0083] 4. Token=E SK (ID Device||ID Security Medium||Hash(PW)||R)

[0084] Among them, E SK() indicates that a certain cryptographic algorithm is used for encryption calculation. SK represents the key. ID Security Medium represents the security medium identifier. ID Device represents the device identifier. Hash() represents the cryptographic hash algorithm, PW represents the password, TS represents the timestamp, and R represents the random number. HMAC() represents the Keyed-Hash Message Authentication Code (HMAC) function, whose input is a key and a message. SK represents the key. Token represents the initial authentication token.

[0085] Optionally, the secure medium may also use a first encryption algorithm to calculate the device identifier, secure medium identifier, password, and verification information to obtain an initial authentication token. The verification information may include a timestamp, a random number, or other verification information.

[0086] It is understood that the verification information can be preset by those skilled in the art. The verification information can also be modified according to specific application scenarios. This application does not impose specific limitations in this regard.

[0087] For example, the verification information can be a timestamp. The security medium processes the device identifier, security medium identifier, password, and timestamp using a pre-defined first encryption algorithm to obtain an initial authentication token.

[0088] For example, the verification information can be a random number. The security medium processes the device identifier, security medium identifier, password, and random number using the set first encryption algorithm to obtain the initial authentication token.

[0089] For example, the verification information can be a timestamp or a random number. The security medium processes the device identifier, security medium identifier, password, and verification information (timestamp or random number) using the set first encryption algorithm to obtain the initial authentication token.

[0090] Before processing the password using the set first encryption algorithm, the secure medium can calculate a digest value for the password using a cryptographic hash algorithm according to the set rules. Then, the device identifier, secure medium identifier, digest value, and verification information (timestamp or random number) are processed using the set first encryption algorithm to obtain the initial authentication token.

[0091] It is understood that the rules set can be to calculate the digest value using a specified cryptographic hash algorithm. Cryptographic hash algorithms can include Secure Hash Algorithm 2 (SHA-2), SM3 cryptographic hash algorithm, etc. This application does not specifically limit this.

[0092] Step S203: Send a device registration request to the platform so that the platform can determine whether the initial authentication token has been verified.

[0093] The device registration request includes a security media identifier, a device identifier, and an initial authentication token.

[0094] like Figure 3 As shown in the figure, this application provides a device registration method. Specifically, it may include the following steps:

[0095] Step S301: The platform receives a device registration request from the secure medium.

[0096] The platform's second database stores the correspondence between user information and security media identifiers. This correspondence can be one-to-one or one-to-many.

[0097] Step S302: Process the security medium identifier, device identifier, and second user information using the first encryption algorithm to obtain a verification token.

[0098] The second user information is determined based on the correspondence between the stored security medium identifier and the user information. The second user information may include the user's identifier. The user's identifier is used to identify the user in a specific region; for example, the user's identifier can be the characters "Li Si," an identity identifier, or a numerical sequence.

[0099] Optionally, the platform can determine the second user information based on the stored correspondence between the security medium identifier and user information. Since the correspondence between the security medium identifier and user information can be one-to-many, the platform can determine whether the second user information includes multiple user information entries after determining the second user information based on the stored correspondence. If the second user information includes multiple user information entries, the platform compares these multiple entries with the first user information. If the first user information is included among the multiple entries, the platform can determine that a correspondence exists between the first user information and the security medium. The platform can then process the security medium identifier, device identifier, and the first user information using a pre-defined second encryption algorithm to obtain a verification token. If the first user information is not included among the multiple entries, the platform can determine that no correspondence exists between the first user information and the security medium. The platform can then send a first message indicating registration failure to the security medium.

[0100] If the second user information includes one user information entry, the platform compares the second user information with the first user information. If the second user information and the first user information are the same, the platform can determine that there is a correspondence between the first user information and the security medium. The platform processes the security medium identifier, device identifier, and the first user information using the set second encryption algorithm to obtain a verification token. If the second user information and the first user information are different, the platform can determine that there is no correspondence between the first user information and the security medium. The platform sends a first message indicating registration failure to the security medium.

[0101] Step S303: Compare the verification token with the initial authentication token to determine whether the initial authentication token has passed verification.

[0102] In one optional embodiment, the platform can compare the verification token with the initial authentication token to determine whether the initial authentication token has passed verification. If the verification token and the initial authentication token are the same, the initial authentication token is determined to have passed verification. The platform then sends device identity authentication information to the security medium. If the verification token and the initial authentication token are different, the initial authentication token is determined to have failed verification, and the platform sends a first message indicating registration failure to the security medium.

[0103] In one possible scenario, device authentication information may be in string format. This application does not impose specific limitations on this. The correspondence between device authentication information, device identifier, and first user information can be stored in a third-party database on the platform.

[0104] In another possible scenario, to eliminate the need for the platform to store device authentication information in its database, and instead only maintain the mapping between the device identifier and the first user information, the platform can calculate the device authentication information in real time. For example, the platform can process the device identifier and the first user information using a pre-defined second encryption algorithm to obtain the device authentication information, and then send this information to the secure medium.

[0105] It is understood that the second encryption algorithm can be pre-set by those skilled in the art. The second encryption algorithm can also be changed according to specific application scenarios. The second encryption algorithm can be the same as the first encryption algorithm in the examples above. This application does not specifically limit how the device authentication information is calculated.

[0106] In one possible scenario, to ensure that the platform and the secure medium use the same encryption algorithm to calculate and obtain the verification token, the device registration request may also include an encryption algorithm category code. This encryption algorithm category code corresponds to the specific encryption algorithm being set.

[0107] For example, the encryption algorithm category encoding can include the ZUC algorithm set of stream ciphers, the Rivest Cipher 4 (RC4) algorithm, Keyed-Hash Message Authentication Code (HMAC), the SM4 block cipher, the Advanced Encryption Standard (AES-128) with a 128-bit key, and the Advanced Encryption Standard (AES-256) with a 256-bit key. When using block ciphers, it is also necessary to specify the operating mode, such as Cipher Block Chaining (CBC), Courter with CBC-MAC (CCM), and Galois / Counter Mode (GCM). Furthermore, the padding method can be determined by the platform and the secure medium according to a pre-agreed padding method, such as padding with all zeros to an integer multiple of the block length.

[0108] It is understood that the correspondence between encryption algorithms and encryption algorithm category codes in the embodiments of this application can be preset by those skilled in the art. The correspondence between encryption algorithms and encryption algorithm category codes can also be flexibly set according to the application scenario. This application does not impose specific limitations in this regard.

[0109] As shown in Table 1, Table 1 is a comparison table of exemplary encryption algorithms and encryption algorithm category codes provided in the embodiments of this application.

[0110] Table 1. Comparison of Encryption Algorithms and Encryption Algorithm Category Codes

[0111]

[0112] The encryption algorithm categories for the following algorithms are listed: SM4_CBC (0x0001), SM4_CCM (0x0002), SM4_GCM (0x0003), AES_128_CBC (0x0101), AES_128_CCM (0x0102), AES_128_GCM (0x0103), ZUC (0x0200), RC4_128 (0x0300), HMAC-SM3 (0x0400), and HMAC-SHA-256 (0x0500). The encryption algorithm category code corresponding to the HMAC-SHA3-256 encryption algorithm is 0x0600.

[0113] When the device registration request includes an encryption algorithm category code, the platform, upon receiving the device registration request, can determine the first encryption algorithm corresponding to the encryption algorithm category code based on the saved correspondence between encryption algorithm category codes and encryption algorithms.

[0114] In the above method, by adding an encryption algorithm category code to the device registration request, the platform can promptly determine the encryption algorithm consistent with the security medium. The verification token is then calculated based on this consistent encryption algorithm. This improves the flexibility of using a unified encryption algorithm between the security medium and the platform.

[0115] Step S204: If the platform determines that the initial authentication token verification is successful, receive the device identity authentication information from the platform and write the device identity authentication information into the device.

[0116] Compared to the existing technology where maintenance personnel manually input the initial authentication token, the above method in this application uses a first encryption algorithm to calculate the device identifier and the first user information to obtain the initial authentication token. This ensures that maintenance personnel are unaware of the device's initial authentication information, improving the security and convenience of the device registration process.

[0117] The following is about Figure 2 The following examples illustrate the implementation:

[0118] For example, maintenance personnel connect the security medium to the device and successfully log in using their password. Upon receiving the password, the security medium reads the device identifier through its security medium engine. The security medium then determines the first user information in a first database based on the correspondence between the password and user information. After determining the first user information, the security medium processes the device identifier and the first user information using a pre-defined first encryption algorithm to obtain an initial authentication token. The security medium then sends a device registration request to the platform. This device registration request includes the security medium identifier, the device identifier, the initial authentication token, and the encryption algorithm category code.

[0119] After receiving a device registration request from the secure medium, the platform determines the second user information from the second database based on the mapping between the secure medium identifier and user information. The platform can also determine the first encryption algorithm corresponding to the encryption algorithm category code based on the mapping between encryption algorithm category codes and encryption algorithms. If the second user information includes the first user information, the platform processes the device identifier and the second user information using the set first encryption algorithm to obtain a verification token. The platform compares the verification token with the initial authentication token. If the verification token and the initial authentication token are the same, the platform determines that the initial authentication token has passed verification. The platform then sends the device identity authentication information to the secure medium.

[0120] The secure medium receives device authentication information from the platform and writes the device authentication information into the device.

[0121] like Figure 4 As shown in the figure, this application provides an exemplary device registration flowchart.

[0122] Step S401: When the security medium of the connected device receives the password, it reads the device identifier of the device and determines the first user information corresponding to the password according to the correspondence between the stored password and user information.

[0123] Step S402: The security medium processes the device identifier and the first user information using the set first encryption algorithm to obtain the initial authentication token;

[0124] Step S403: The secure medium sends a device registration request to the platform;

[0125] Step S404: The platform determines the second user information based on the correspondence between the security medium identifier and the user information;

[0126] Step S405: When the second user information includes multiple user information, and the multiple user information includes the first user information, the platform processes the security medium identifier, device identifier and the first user information using the first encryption algorithm to obtain a verification token.

[0127] Step S406: The platform compares the verification token with the initial authentication token to determine whether the verification token and the initial authentication token are the same. If yes, proceed to step S407; otherwise, proceed to step S409.

[0128] Step S407: The platform sends device authentication information to the security medium;

[0129] Step S408: The security medium writes the device authentication information into the device;

[0130] Step S409: The platform sends the first message indicating registration failure to the security medium.

[0131] Figure 5 This is a schematic diagram of the structure of a device registration apparatus provided in an embodiment of this application, as shown below. Figure 5 As shown, it includes: a determination module 501, a processing module 502, and a transceiver module 503.

[0132] The determination module 501 is used to read the device identifier of the device when the security medium of the connected device receives the password, and determine the first user information corresponding to the password according to the correspondence between the stored password and user information.

[0133] Processing module 502 is used to process the device identifier and the first user information using a set first encryption algorithm to obtain an initial authentication token;

[0134] The transceiver module 503 is used to send a device registration request to the platform so that the platform can determine whether the initial authentication token has been verified. The device registration request includes a security medium identifier, a device identifier, and an initial authentication token.

[0135] The transceiver module 503 is also used to receive device identity authentication information from the platform when the platform determines that the initial authentication token has been verified.

[0136] The processing module 502 is also used to write device identity authentication information into the device.

[0137] Optionally, the device registration request may also include an encryption algorithm category code, which corresponds to the encryption algorithm set.

[0138] Figure 6 This is a schematic diagram of the structure of a database maintenance device provided in an embodiment of this application, as shown below. Figure 6 As shown, it includes: a transceiver module 601, a processing module 602, and a determination module 603.

[0139] The transceiver module 601 is used to receive a device registration request from a secure medium. The device registration request includes a secure medium identifier, a device identifier, and an initial authentication token. The initial authentication token is obtained by the secure medium using a set first encryption algorithm to calculate the device identifier and the first user information. The first user information is determined by the secure medium based on the correspondence between the password and the user information.

[0140] The processing module 602 is used to process the security medium identifier, device identifier and second user information using the first encryption algorithm to obtain a verification token. The second user information is determined based on the correspondence between the stored security medium identifier and user information.

[0141] The determination module 603 is used to compare the verification token with the initial authentication token to determine whether the initial authentication token has passed verification.

[0142] Optionally, after determining the second user information based on the correspondence between the security medium identifier and user information, if the second user information includes multiple user information entries, the processing module 602 is further configured to:

[0143] When the first user information is included among multiple user information, the security medium identifier, device identifier, and the first user information are processed using the first encryption algorithm to obtain a verification token;

[0144] If the first user information is not included in the multiple user information entries, a first message indicating registration failure is sent to the security medium.

[0145] Optionally, after determining the second user information based on the correspondence between the security medium identifier and user information, if the second user information includes one user information, the processing module 602 is further configured to:

[0146] When the second user information is the same as the first user information, the security medium identifier, device identifier and the second user information are processed using the first encryption algorithm to obtain the verification token;

[0147] If the second user information differs from the first user information, a first message indicating registration failure is sent to the security medium.

[0148] Optionally, the verification token is compared with the initial authentication token to determine whether the initial authentication token has passed verification. Module 603 is specifically used for:

[0149] If the verification token is the same as the initial authentication token, the device identity authentication information is sent to the secure medium.

[0150] Optionally, the verification token is compared with the initial authentication token to determine whether the initial authentication token has passed verification. Module 603 is also used for:

[0151] If the verification token is different from the initial authentication token, send the first message to the secure medium.

[0152] Optionally, the device registration request may also include an encryption algorithm category code, which corresponds to the set encryption algorithm. The determining module 603 is further used for:

[0153] Based on the saved correspondence between encryption algorithm category codes and encryption algorithms, the first encryption algorithm corresponding to the encryption algorithm category code is determined.

[0154] Based on the same technical concept, this application also provides an electronic device that can perform the functions of the aforementioned database maintenance device.

[0155] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0156] At least one processor 701 and a memory 702 connected to at least one processor 701. In this embodiment, the specific connection medium between the processor 701 and the memory 702 is not limited. Figure 7 The example shown is the connection between processor 701 and memory 702 via bus 700. Bus 700 is... Figure 7 The connections between other components are indicated by thick lines and are for illustrative purposes only, not as limiting information. The 700 bus can be divided into address bus, data bus, control bus, etc., for ease of representation. Figure 7 The term is represented by a single thick line, but this does not imply that there is only one bus or one type of bus. Alternatively, the processor 701 can also be called a controller; there is no restriction on the name.

[0157] In this embodiment, memory 702 stores instructions executable by at least one processor 701. By executing the instructions stored in memory 702, at least one processor 701 can perform the device registration method described above. Processor 701 can implement... Figure 6 or Figure 7 The functions of each module in the device shown.

[0158] The processor 701 is the control center of the device. It can connect to various parts of the control device through various interfaces and lines. By running or executing instructions stored in memory 702 and calling data stored in memory 702, the processor can perform various functions and process data, thereby monitoring the device as a whole.

[0159] In one possible design, processor 701 may include one or more processing units. Processor 701 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, driver interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may also not be integrated into processor 701. In some embodiments, processor 701 and memory 702 may be implemented on the same chip; in some embodiments, they may also be implemented on separate chips.

[0160] The processor 701 can be a general-purpose processor, such as a central processing unit (CPU), digital signal processor, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the device registration method disclosed in the embodiments of this application can be directly manifested as execution by a hardware processor, or execution by a combination of hardware and software modules within the processor.

[0161] Memory 702, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 702 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. Memory 702 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 702 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.

[0162] By designing and programming the processor 701, the code corresponding to the device registration method described in the foregoing embodiments can be embedded into the chip, thereby enabling the chip to execute the code during operation. Figure 2The device registration method of the illustrated embodiment. How to design and program the processor 701 is a technique well-known to those skilled in the art and will not be described further here.

[0163] It should be noted that the electronic device provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.

[0164] This application also provides a computer-readable storage medium storing computer-executable instructions for causing a computer to execute the device registration method described above.

[0165] This application also provides a device registration system, which may include the aforementioned security medium and platform. The operations performed by the security medium and platform can be referred to... Figure 2 The relevant descriptions in the illustrated embodiments.

[0166] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0167] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0168] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0169] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the functions specified in one or more boxes. Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, this application also intends to include such modifications and variations if they fall within the scope of the claims of this application and their equivalents.

Claims

1. A device registration method, characterized in that, The method includes: When the security medium of the connected device receives the password, it reads the device identifier of the device and determines the first user information corresponding to the password based on the stored correspondence between the password and user information. The device identifier and the first user information are processed using the set first encryption algorithm to obtain an initial authentication token; A device registration request is sent to the platform so that the platform can determine whether the initial authentication token has been verified. The device registration request includes a security medium identifier, the device identifier, and the initial authentication token. If the platform determines that the initial authentication token has passed verification, it receives device identity authentication information from the platform and writes the device identity authentication information into the device.

2. The method according to claim 1, characterized in that, The device registration request also includes an encryption algorithm category code, which corresponds to the encryption algorithm set.

3. A device registration method, characterized in that, The method includes: The platform receives a device registration request from a secure medium. The device registration request includes a secure medium identifier, a device identifier, and an initial authentication token. The initial authentication token is obtained by the secure medium using a set first encryption algorithm to calculate the device identifier and first user information. The first user information is determined by the secure medium based on the correspondence between passwords and user information. The security medium identifier, the device identifier, and the second user information are processed using the first encryption algorithm to obtain a verification token. The second user information is determined based on the stored correspondence between the security medium identifier and the user information. The verification token is compared with the initial authentication token to determine whether the initial authentication token has passed verification; If the initial authentication token is verified to be valid, device identity authentication information is sent to the security medium.

4. The method according to claim 3, characterized in that, After determining the second user information based on the correspondence between the security medium identifier and user information, if the second user information includes multiple user information entries, the method further includes: When the first user information is included among the multiple user information, the security medium identifier, the device identifier, and the first user information are processed using the first encryption algorithm to obtain a verification token; If the first user information is not included in the plurality of user information, a first message indicating registration failure is sent to the security medium.

5. The method according to claim 4, characterized in that, After determining the second user information based on the correspondence between the security medium identifier and the user information, if the second user information includes a single user information, the method further includes: When the second user information is the same as the first user information, the security medium identifier, the device identifier, and the second user information are processed using the first encryption algorithm to obtain a verification token; When the second user information differs from the first user information, a first message indicating registration failure is sent to the security medium.

6. The method according to claim 3, characterized in that, The step of sending device identity authentication information to the security medium after confirming that the initial authentication token has passed verification specifically includes: If the verification token is the same as the initial authentication token, the device identity authentication information is sent to the security medium.

7. The method according to claim 3, characterized in that, The step of comparing the verification token with the initial authentication token to determine whether the initial authentication token has passed verification further includes: If the verification token is different from the initial authentication token, first information is sent to the secure medium.

8. The method according to claim 3, characterized in that, The device registration request also includes an encryption algorithm category code, which corresponds to a set encryption algorithm. The method further includes: Based on the stored correspondence between the encryption algorithm category code and the encryption algorithm, the first encryption algorithm corresponding to the encryption algorithm category code is determined.

9. A device registration system, characterized in that, The system includes: a security medium and a platform; When the security medium connected to the device receives a password, it is used to read the device identifier of the device and determine the first user information corresponding to the password based on the stored correspondence between the password and user information. The security medium is also used to process the device identifier and the first user information using a set first encryption algorithm to obtain an initial authentication token; The security medium is also used to send a device registration request to the platform so that the platform can determine whether the initial authentication token has been verified. The device registration request includes a security medium identifier, the device identifier, and the initial authentication token. The platform is configured to receive a device registration request from a secure medium, and process the secure medium identifier, the device identifier, and the second user information using the first encryption algorithm to obtain a verification token; The platform is also used to compare the verification token with the initial authentication token to determine whether the initial authentication token has passed verification; The security medium is also used to receive device identity authentication information from the platform and write the device identity authentication information into the device when the platform determines that the initial authentication token has passed verification.

10. A device registration apparatus, characterized in that, include: The determination module is used to read the device identifier of the device when the security medium of the connected device receives the password, and determine the first user information corresponding to the password according to the stored correspondence between the password and user information. The processing module is used to process the device identifier and the first user information using a set first encryption algorithm to obtain an initial authentication token; The transceiver module is used to send a device registration request to the platform so that the platform can determine whether the initial authentication token has been verified. The device registration request includes a security medium identifier, the device identifier, and the initial authentication token. The transceiver module is also configured to receive device identity authentication information from the platform when the platform determines that the initial authentication token has passed verification; The processing module is also used to write the device identity authentication information into the device.

11. A device registration apparatus, characterized in that, include: The transceiver module is used to receive a device registration request from a secure medium. The device registration request includes a secure medium identifier, a device identifier, and an initial authentication token. The initial authentication token is obtained by the secure medium using a set first encryption algorithm to calculate the device identifier and first user information. The first user information is determined by the secure medium based on the correspondence between passwords and user information. The processing module is used to process the security medium identifier, the device identifier, and the second user information using the first encryption algorithm to obtain a verification token, wherein the second user information is determined based on the correspondence between the security medium identifier and the user information; The determining module is used to compare the verification token with the initial authentication token to determine whether the initial authentication token has passed verification; The transceiver module is also used to send device identity authentication information to the security medium when it is determined that the initial authentication token has passed verification.

12. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the device registration method as described in any one of claims 1-8.

13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program for causing the computer to perform the device registration method according to any one of claims 1-8.

14. A computer program product, characterized in that, When the computer program product is invoked by a computer, it causes the computer to execute the device registration method as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Method for realizing terminal authentication based on OMA DM, terminal and server

    CN104125565A

  • Geographical location authentication identification device, system and method

    CN108989038A