Seamless authentication methods and systems for distributed devices

Seamless authentication is achieved through a distributed soft bus between distributed devices, using the device's public and private keys to generate authentication ciphertext. This solves the problems of cumbersome and inefficient device authentication processes, and realizes efficient and secure device authentication.

CN117834252BActive Publication Date: 2026-05-26FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD
Filing Date
2023-12-29
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

The device authentication process between the discoverer and the discoverer in distributed devices is cumbersome and inefficient, especially when manual intervention is required, resulting in a poor user experience and low security.

Method used

Seamless authentication is achieved through a distributed soft bus between distributed devices. Authentication ciphertext is generated using the device's public and private keys, and devices autonomously send and receive authentication information, simplifying the authentication process.

Benefits of technology

It enables device authentication without user intervention, improving authentication efficiency and security, optimizing user experience, and is applicable to seamless authentication between HarmonyOS devices from the same manufacturer.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117834252B_ABST
    Figure CN117834252B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for seamless authentication of distributed devices. A first device and a second device establish a distributed connection via a distributed soft bus. The first device obtains a matching public key and private key, and based on the public and private key pairs, obtains corresponding public key certificates and authentication ciphertext. The second device performs authentication based on the public key certificate and authentication ciphertext, and returns the corresponding authentication result, thus completing the authentication. This ensures the security of the distributed device connection and improves data security. Furthermore, during the authentication process between the first and second devices, the first and second devices autonomously send and return authentication information via the distributed soft bus, without user intervention or input, simplifying the device authentication process, achieving seamless authentication of distributed devices, optimizing user experience, and improving device authentication efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of device authentication technology, and in particular to a contactless authentication method and system for distributed devices. Background Technology

[0002] In distributed device management, the search interface of the native distributed device management is generally used first to discover nearby devices. After discovering untrusted devices in the vicinity, the identity of the untrusted devices is authenticated by calling the authentication device interface. After successful authentication, the device is added to the trusted device list.

[0003] In related technologies, the device authentication process between the discoverer and the discoverer in the authentication process of distributed devices is cumbersome and has the problem of low device authentication efficiency. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a method and system for seamless authentication of distributed devices, which simplifies the device authentication process, realizes seamless authentication of distributed devices, optimizes user experience, and improves authentication efficiency.

[0005] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows:

[0006] A seamless authentication method for distributed devices, the method comprising:

[0007] The first device obtains a device public key and a device private key, and the device public key and the device private key are matched with each other;

[0008] The first device obtains a public key certificate based on the device's public key;

[0009] The first device generates authentication ciphertext based on the device's private key;

[0010] The first device sends the public key certificate and the authentication ciphertext to the second device via a distributed soft bus. The first device is distributedly connected to at least one of the second devices. The first device is used to authenticate the second device.

[0011] The second device receives the public key certificate and authentication ciphertext;

[0012] The second device authenticates the ciphertext based on the public key certificate and returns the authentication result through the distributed soft bus;

[0013] The first device receives the authentication result and completes the authentication.

[0014] To solve the above-mentioned technical problems, another technical solution adopted by the present invention is as follows:

[0015] A contactless authentication system for distributed devices includes a first device and at least one second device, wherein the first device and at least one second device are distributedly connected, and the first device is used to authenticate the second device;

[0016] The first device is used for:

[0017] Obtain the device public key and device private key, and match the device public key and device private key with each other;

[0018] Obtain the public key certificate based on the device's public key;

[0019] Generate authentication ciphertext based on the device's private key;

[0020] The public key certificate and the authentication ciphertext are sent to the second device via a distributed soft bus;

[0021] The second device is used for:

[0022] Receive the public key certificate and authentication ciphertext;

[0023] The authentication ciphertext is authenticated based on the public key certificate, and the authentication result is returned through the distributed soft bus;

[0024] The first device is also used for:

[0025] Receive the authentication result and complete the authentication.

[0026] The beneficial effects of this invention are as follows: The first device of this application is used to authenticate the second device. The first device and the second device are connected in a distributed manner through a distributed soft bus. The first device obtains a matching public key and a private key, obtains a corresponding public key certificate based on the public key, and generates corresponding authentication ciphertext based on the private key. The first device then sends the public key certificate and the authentication ciphertext to the second device through the distributed soft bus. The second device authenticates the authentication ciphertext based on the public key certificate and returns the authentication result through the distributed soft bus, thus completing the authentication. Using the method of this application, the authentication of the second device by the first device can be guaranteed, improving the security of the distributed device connection and enhancing data security. Meanwhile, during the authentication process between the first and second devices, the first and second devices autonomously send and return authentication information via a distributed soft bus. Specifically, during the device authentication interaction, the first device obtains a public key certificate using its public key and generates authentication ciphertext using its private key. Then, it sends the public key certificate authentication ciphertext to the second device via the distributed soft bus. The second device then authenticates the authentication ciphertext based on the public key certificate to complete the device authentication process. Therefore, the solution in this application eliminates the need for user intervention or information input during the entire device authentication process, simplifying the device authentication process, achieving seamless authentication of distributed devices, optimizing user experience, and improving device authentication efficiency. Attached Figure Description

[0027] Figure 1 A schematic diagram of a device certification procedure for related technologies;

[0028] Figure 2 A flowchart illustrating the steps of a contactless authentication method for a distributed device provided in an embodiment of the present invention;

[0029] Figure 3 A schematic diagram of a contactless authentication method for a distributed device provided in an embodiment of the present invention;

[0030] Figure 4 This is a schematic diagram of the architecture of a contactless authentication system for distributed devices provided in an embodiment of the present invention;

[0031] Figure 5 This is a schematic diagram of the architecture of a contactless authentication system for distributed devices provided in an embodiment of the present invention; Detailed Implementation

[0032] To make the technical problems, technical solutions, and beneficial effects to be solved by this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and are not intended to limit the scope of this application.

[0033] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0034] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0035] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0036] In distributed device management, the search interface of the native distributed device management is generally used first to discover nearby devices. After discovering untrusted devices in the vicinity, the identity of the untrusted devices is authenticated by calling the authentication device interface. After successful authentication, the device is added to the trusted device list.

[0037] However, in related technologies, the device authentication process between the discoverer and the discoverer in the authentication process of distributed devices is cumbersome and has low device authentication efficiency.

[0038] In related technologies, such as Figure 1 As shown, if device authentication is required, the discoverer selects a designated discoverer and sends an authentication request. After the discoverer agrees to the authentication request, a user manually views the PIN code or QR code displayed on the discoverer and then manually enters it into the discoverer to complete the authentication process. This device authentication process requires the user to view and enter a PIN code, relying too heavily on manual authentication, resulting in a poor user experience. Furthermore, the inability to directly interact with the discoverer makes the authentication process cumbersome and inefficient. Moreover, this solution cannot achieve seamless authentication between the discoverer and the discoverer; the authentication process requires manual intervention, making it tedious. In addition, PIN code mismatches are inevitable during manual intervention, significantly reducing authentication security.

[0039] To address the aforementioned issues, this application provides a method and system for seamless authentication of distributed devices. It should be noted that the first device and the second device in this application are two independent electronic devices. The first device can be the initiator of device authentication, i.e., the discoverer; the second device can be the receiver of device authentication, i.e., the discoverer; and the first device can perform seamless authentication on the second device. In some embodiments, the second device can also act as the initiator of device authentication, and the first device can also act as the receiver of device authentication, with the second device performing seamless authentication on the first device. This application does not limit this approach.

[0040] The following section details the contactless authentication method for distributed devices in this application.

[0041] This application provides a method for seamless authentication of distributed devices. Specifically, a first device is distributedly connected to at least one second device. The first and second devices are connected via a distributed soft bus. This distributed soft bus can automatically discover other nearby devices and connect them for network topology management, such as forming a star network topology or a mesh network topology. Furthermore, because software enables decentralized and distributed deployment, the distributed soft bus is similar to a physical bus being software-based. All devices connected to it operate in software form; they can be understood as individual devices. Most importantly, devices within the distributed soft bus can invoke the capabilities of other devices to process requests.

[0042] The first device in this embodiment is used to authenticate the second device. The first and second devices can be OpenHarmony devices or devices running the HarmonyOS operating system. The first and second devices can be terminals with payment processing capabilities, such as cash registers, financial POS machines, smart POS machines, card readers, and barcode scanners. They can also be terminals with specific payment capabilities, such as digital RMB acceptors, NFC payment devices, facial recognition payment devices, and fingerprint payment devices.

[0043] Based on this, please refer to Figure 2 The method includes steps S110-S170.

[0044] Step S110: The first device obtains the device public key and the device private key, and the device public key and the device private key are matched with each other.

[0045] The device's public and private keys are generated before the device leaves the factory and are used for device authentication. The device's public and private keys are matched to form a public-private key pair for the first device.

[0046] Step S120: The first device obtains a public key certificate based on the device's public key.

[0047] Step S130: The first device generates authentication ciphertext based on the device's private key.

[0048] Step S140: The first device sends the public key certificate and authentication ciphertext to the second device via a distributed soft bus.

[0049] It should be noted that the first device and the second device are from the same manufacturer and are based on the HarmonyOS system. Therefore, the first device sends the public key certificate and authentication ciphertext to the second device based on the distributed soft bus of the HarmonyOS system.

[0050] Step S150: The second device receives the public key certificate and authentication ciphertext.

[0051] Step S160: The second device authenticates the ciphertext based on the public key certificate and returns the authentication result through the distributed soft bus.

[0052] Step S170: The first device receives the authentication result and completes the authentication.

[0053] In related technologies, for MIS-POS (Merchant Information System-Point of Sales Terminal) application scenarios, although the devices used by users are all from the same manufacturer, users often need to authenticate other devices by entering PIN codes when using the MIS-POS system to complete payments. The contactless authentication method proposed in this application can be applied to mutual authentication of all HarmonyOS system devices from the same manufacturer. For example, currently, a user needs to use a cash register to call a POS terminal to complete a payment task. In related technologies, the user needs to select the POS terminal in the cash register, and then the cash register sends a verification request to the POS terminal. The POS terminal interface displays the PIN code for verification, and then the user enters the PIN code into the cash register to complete the verification. In this verification process, the user needs to obtain and enter the PIN code between two devices, making the authentication process reliant on manual labor and cumbersome. In the contactless authentication method of this application, the user only needs to select the POS terminal to be authenticated in the cash register, and the cash register will initiate authentication to the POS terminal. The POS terminal will receive the authentication, thereby completing the authentication process between the cash register and the POS terminal. No user participation in data transmission is required, which realizes contactless authentication for the user and optimizes the user experience.

[0054] In some embodiments, the contactless authentication method of this application can perform "one-to-one" mutual authentication between devices. Specifically, the first device searches for other HarmonyOS devices based on the distributed search function of the HarmonyOS system, selects one of the HarmonyOS devices for pairing, records the device information of the HarmonyOS device after successful pairing, initiates authentication with the HarmonyOS device, and then receives the authentication result from the HarmonyOS device. The first device and the HarmonyOS device then complete mutual authentication.

[0055] In some embodiments, where the distributed soft bus of the HarmonyOS system allows, the seamless authentication method of this application can perform "one-to-many" authentication for devices. Specifically, a first device uses the distributed search function of the HarmonyOS system to find other HarmonyOS devices and selects multiple HarmonyOS devices for pairing. After successful pairing, the device information of the HarmonyOS device is recorded, and authentication is initiated with multiple HarmonyOS devices simultaneously. Authentication is completed with multiple HarmonyOS devices at the same time, thereby batch completing the authentication process for multiple HarmonyOS devices. When the number of HarmonyOS devices for a user is large, "one-to-many" authentication can improve authentication efficiency.

[0056] As can be seen from the above embodiments, the method of this application can ensure that the first device completes authentication of the second device, thereby improving the security of distributed device connections and data security. Furthermore, during the authentication process between the first and second devices, the first and second devices autonomously send and receive authentication information via a distributed soft bus. Specifically, in the device authentication interaction process, the first device obtains a public key certificate using its public key and generates authentication ciphertext using its private key. Then, it sends the public key certificate authentication ciphertext to the second device via the distributed soft bus. The second device then authenticates the ciphertext based on the public key certificate to complete the device authentication process. Therefore, the scheme of this application eliminates the need for user intervention or information input during the entire device authentication process, simplifying the device authentication process, achieving seamless authentication of distributed devices, optimizing user experience, and improving device authentication efficiency.

[0057] In one embodiment of this application, in a MIS-POS payment system scenario, the first device can be a host computer of the MIS system, such as a cash register; the second device can be a slave computer of the MIS system, such as a POS terminal. For example, when the cash register receives a payment order, it needs to call the corresponding POS terminal to complete the payment process with the user. At this time, the cash register can execute the corresponding steps of the first device, and the POS terminal can execute the corresponding steps of the second device. After completing the device authentication between the cash register and the POS terminal, the cash register can call the POS terminal to complete the payment process with the user based on a distributed soft bus.

[0058] In another embodiment of this application, in a MIS-POS payment system scenario, the first device can be the device authentication initiator of the MIS system, such as POS terminal A; the second device can be the device authentication recipient of the MIS system, such as POS terminal B. That is, both the first and second devices are POS terminals. For example, POS terminal A receives a palmprint payment order, but the hardware module of POS terminal A cannot support it in completing the palmprint payment order. Therefore, POS terminal A can perform device authentication on POS terminal B, which supports palmprint payment orders, based on a distributed soft bus. POS terminal A executes the corresponding steps of the first device, and POS terminal B executes the corresponding steps of the second device. After completing the device authentication of POS terminal A and POS terminal B, POS terminal A can call POS terminal B based on the distributed soft bus to complete the palmprint payment order.

[0059] As can be seen from the above embodiments, after the first device and the second device complete authentication, the first device can call the second device to complete the specified instructions.

[0060] In one embodiment of this application, the method for the first device to generate authentication ciphertext based on the device private key in step S130 includes steps S210-S220.

[0061] Step S210: The first device generates an authentication random number.

[0062] Step S220: The first device encrypts the authentication random number using its private key to obtain the authentication ciphertext.

[0063] As can be seen from the above embodiments, the first device of this application generates an authentication random number as authentication ciphertext only during contactless authentication. This avoids the problem of authentication information being stolen due to malicious user attacks on the first device. Simultaneously, the random number ensures the randomness and immediacy of the authentication ciphertext, preventing the device's public or private key from being cracked, further improving authentication security. Furthermore, this application encrypts the authentication random number using the device's private key, thereby decrypting the authentication ciphertext based on the device's public key corresponding to the private key, completing the authentication process between the two devices without requiring other cumbersome authentication steps, thus improving authentication efficiency.

[0064] In one embodiment of this application, the method for the first device to generate authentication ciphertext based on the device private key in step S130 may further include step S1301.

[0065] Step S1301: The first device generates encrypted data based on its private key to obtain the authentication ciphertext. Generating the authentication ciphertext directly from the device's private key eliminates the need to generate a random number for encryption, further simplifying the device authentication process and improving efficiency. Simultaneously, generating encrypted data directly from the device's private key avoids attacks during the encryption of the authentication random number, preventing the device's private key from being leaked and thus enhancing authentication security.

[0066] In one embodiment of this application, the method of the first device sending the public key certificate and authentication ciphertext to the second device via a distributed soft bus in step S140 includes step S310.

[0067] Step S310: The first device sends the public key certificate, authentication ciphertext, and authentication random number to the second device via a distributed soft bus.

[0068] As can be seen from the above embodiments, the first device of this application automatically sends the public key certificate, authentication ciphertext, and authentication random number to the second device via a distributed soft bus, without requiring the user to manually obtain and input authentication information. During the authentication process between the first device and the second device, data transmission is handled by the distributed soft bus without user intervention, achieving seamless authentication for the user and improving the user experience.

[0069] In one embodiment of this application, the method of the second device authenticating the authentication ciphertext based on the public key certificate and returning the authentication result through the distributed soft bus in step S160 includes steps S410-S430.

[0070] Step S410: The second device obtains the device public key based on the public key certificate.

[0071] Step S420: The second device decrypts the authentication ciphertext using the device's public key to obtain the authentication plaintext.

[0072] Since the device public key and device private key are a matching pair, the authentication ciphertext encrypted with the device private key can be decrypted with the device public key to obtain the authentication plaintext.

[0073] Step S430: The second device compares the authentication plaintext and the authentication random number to obtain the authentication result, and returns the authentication result through the distributed soft bus.

[0074] Specifically, if the authentication plaintext matches the authentication random number, the authentication result is successful; if the authentication plaintext does not match the authentication random number, the authentication result is unsuccessful.

[0075] As shown in the above embodiments, the device public key is transmitted between the first and second devices in the form of a public key certificate, preventing the device public key from being stolen during data transmission and affecting authentication security. Therefore, after the second device obtains the public key certificate, it retrieves the device public key through the certificate. Since the device private key and device public key match, if the corresponding device public key can decrypt the authentication ciphertext and the obtained authentication plaintext matches the authentication random number, the second device is considered to have successfully authenticated. This method prevents external environments from authenticating the second device using an illegal public key, improving the security of device authentication.

[0076] In one embodiment of this application, the first device includes a first security chip, and the method further includes steps S510-S520 before step S110.

[0077] Step S510: The first device pre-installs a first vendor root certificate in the first security chip. The first vendor root certificate is used to verify the public key certificate of other devices sent by other devices when other devices perform seamless authentication of the first device, so as to obtain the device public key of other devices.

[0078] Step S520: The first device generates a device public key and a device private key, and stores the device private key in the first security chip.

[0079] As can be seen from the above embodiments, the root certificate of the first manufacturer is pre-installed in the security chip of the first device. When the first device performs authentication, the device public key of other devices can be obtained directly through the root certificate of the first manufacturer, thereby realizing the authentication process of other devices for the first device. That is, the contactless authentication method of this application can be applied to all devices produced by the same manufacturer, thereby ensuring the applicability of the contactless authentication method to all devices.

[0080] In one embodiment of this application, the method for the first device to obtain a public key certificate based on the device public key in step S120 includes step S610.

[0081] Step S610: The first device sends its public key and signing instruction to the encryption terminal. The signing instruction is used to instruct the encryption terminal to sign the device's public key and obtain a public key certificate. The encryption terminal is used to sign a certificate for the first device. The certificate issued by the encryption terminal matches the root certificate of the first vendor.

[0082] In some embodiments, all HarmonyOS devices manufactured by the same company have their corresponding manufacturer root certificate pre-installed in the security chip before leaving the factory. A matching device public key and device private key are also generated, and the device private key is stored in the security chip. All HarmonyOS devices then send the device public key and issuance command to the manufacturer's encrypted terminal to obtain the public key certificate, which is then downloaded and saved to the HarmonyOS device's security chip. Therefore, all HarmonyOS devices manufactured by the same company have the manufacturer root certificate, public key certificate, and device private key stored in their security chip before leaving the factory. When users perform device authentication in actual application scenarios, the device can directly obtain the corresponding data from the security chip to complete the authentication.

[0083] As described in the above embodiments, the first device sends its device public key and issuance command to the encryption terminal. The encryption terminal then issues the device public key, thereby verifying its legitimacy and ensuring its security. Simultaneously, the certificate issued by the encryption terminal matches the root certificate from the first vendor, ensuring that when other devices authenticate the first device, the first device can verify the public key certificate sent by other devices using the root certificate from the first vendor in the security chip, thus obtaining the device public key of the other devices and completing the authentication process. This improves the applicability of the authentication method described in this application.

[0084] In one embodiment of this application, the second device includes a second security chip, and the method further includes step S710 before step S110.

[0085] Step S710: The second device pre-installs the second vendor's root certificate in the second security chip.

[0086] The second vendor's root certificate is matched with the certificate issued by the encrypted terminal in step 620 above.

[0087] In one embodiment of this application, if the second device pre-installs a second vendor root certificate in the second security chip, then the method of step S410 includes steps S810-S820.

[0088] Step S810: The second device obtains the second vendor root certificate from the second security chip.

[0089] Step S820: When the first device performs seamless authentication on the second device, the second device verifies the public key certificate through the second vendor's root certificate. If the verification is successful, the device's public key is obtained.

[0090] As can be seen from the above embodiments, when the first device authenticates the second device, the second device obtains a pre-installed second vendor root certificate from its security chip, verifies the public key certificate sent by the first device using the second vendor root certificate, and thus obtains the device public key to complete the authentication process. During the authentication process, all data encryption and decryption processes are completed autonomously between the first and second devices without user intervention, achieving seamless authentication between devices and improving the user experience.

[0091] Both the first and second devices in this application are pre-configured with the vendor's root certificate, device public key, and device private key before leaving the factory. Since the first and second devices may act as authenticators or authenticated parties, different certificates will be used for different purposes. Taking the first device as the authenticator and the second device as the authenticated party as an example: the first device needs to obtain the device public key and device private key, while the second device needs to use the vendor's root certificate to verify and parse the public key certificate sent by the first device to obtain the first device's device public key. Therefore, the vendor's root certificate can be used when the device acts as an authenticated party.

[0092] Therefore, the solution in this application pre-configures the vendor's root certificate, device public key, and device private key for each HarmonyOS or OpenHarmony device. This enables seamless mutual authentication between these HarmonyOS or OpenHarmony devices, improving user experience and the efficiency of authentication between devices.

[0093] In one embodiment of this application, after the first device receives the authentication result in step S170 and the authentication is completed, the method further includes step S910.

[0094] Step S910: When the first device determines that the authentication result is successful, the second device is added to the preset list of trusted devices.

[0095] In some embodiments, when the communication connection between the first device and the second device is disconnected, and the first device needs to call the second device to perform a task again, since the second device is in the list of trusted devices, the first device does not need to re-authenticate the second device, thereby improving device authentication efficiency.

[0096] In some embodiments, when the first device determines that the authentication result is authentication failure, the second device is re-authenticated; if the number of authentication failures of the second device reaches a preset number, the current second device is skipped and authentication of other devices is performed.

[0097] As can be seen from the above embodiments, after the first device successfully authenticates the second device, the second device is added to the preset trusted device list. In this way, even if the first device and the second device are disconnected, the first device does not need to re-authenticate the second device, which can ensure a long-term and effective authentication relationship between the first device and the second device, simplify the authentication steps between devices, and improve authentication efficiency.

[0098] In one embodiment of this application, the method of the first device sending the public key certificate and authentication ciphertext to the second device via a distributed soft bus in step S140 includes steps S1010-S1030.

[0099] Step S1010: The first device obtains communication topology information, which includes a first communication connection between the first device and the relay device, and a second communication connection between the second device and the relay device.

[0100] Step S1020: The first device sends the forwarding instruction, public key certificate and authentication ciphertext to the relay device through the first communication connection. The forwarding instruction is used to instruct the relay device to send the public key certificate and authentication ciphertext to the second device.

[0101] Step S1030: The second device obtains the communication topology information and receives the public key certificate and authentication ciphertext sent by the relay device through the second communication connection.

[0102] The first device, the second device, and the relay device are interconnected in a distributed manner. The relay device is an electronic device based on the HarmonyOS system.

[0103] In a specific scenario, a first device, a second device, and a relay device are connected in a distributed manner based on a distributed soft bus. The communication connections between the first and second devices differ: for example, the first device communicates with the relay device via Wi-Fi, the second device communicates with the relay device via Bluetooth, and there is no direct connection between the first and second devices. In related technologies, data transmission between the first and second devices cannot be performed through the relay device, thus preventing the completion of the device authentication process. However, the contactless authentication method of this application, based on the distributed connection of a distributed soft bus, enables heterogeneous communication between the first and second devices, thereby completing device authentication between them.

[0104] As can be seen from the above embodiments, when there is only a distributed connection between the first device and the second device, but no direct communication connection, authentication data can be forwarded through a relay device between the first device and the second device. Simultaneously, the first device and the relay device form a first communication connection, and the second device and the relay device form a second communication connection; that is, even when the first device and the second device are in a heterogeneous communication connection, data forwarding can still be performed through the relay device. This application solves the problem that the first device and the second device cannot directly communicate to complete authentication due to differences in their device communication structures by forwarding data through a relay device, effectively improving the adaptability of the seamless authentication method to heterogeneous devices.

[0105] In one embodiment of this application, if other HarmonyOS devices are connected to the first device in a distributed manner, and the first device is authenticated by the other HarmonyOS devices, then the other HarmonyOS devices execute the steps executed by the first device in the contactless authentication method of this application, and the first device executes the steps executed by the second device in the contactless authentication method of this application, thereby completing the authentication process of the first device by the other HarmonyOS devices.

[0106] Please refer to Figure 3 In one embodiment of this application, after the first device discovers multiple second devices based on a distributed soft bus, the user selects one of the second devices for seamless authentication. The first device first reads its own public key certificate and device private key, and simultaneously generates an authentication random number; then, it encrypts the authentication random number using the device private key to obtain the authentication ciphertext. The first device sends the authentication random number, public key certificate, and authentication ciphertext to the second device via the distributed soft bus. Upon receiving the authentication random number, public key certificate, and authentication ciphertext, the second device first reads its own second vendor root certificate; then, it verifies the public key certificate based on the second vendor root certificate to obtain the device public key; it decrypts the authentication ciphertext using the device public key to obtain the authentication plaintext; finally, it compares the authentication plaintext and the authentication random number. If they match, the authentication is successful. The second device returns the authentication result to the first device via the distributed soft bus, completing the authentication process between the first device and the second device.

[0107] Please refer to Figure 4 Another embodiment of this application provides a contactless authentication system for distributed devices, including a first device and at least one second device, wherein the first device and at least one second device are distributedly connected, and the first device is used to authenticate the second device;

[0108] The first device is used to: obtain the device's public key and private key; match the device's public key and private key with each other; obtain a public key certificate based on the device's public key; generate authentication ciphertext based on the device's private key; and send the public key certificate and authentication ciphertext to the second device via a distributed soft bus.

[0109] The second device is used to: receive the public key certificate and the authentication ciphertext, authenticate the authentication ciphertext based on the public key certificate, and return the authentication result through the distributed soft bus.

[0110] The first device is also used to: receive the authentication result and complete the authentication.

[0111] The details of the first and second devices in the seamless authentication system for distributed devices have already been disclosed in the above sections and will not be repeated here.

[0112] In one embodiment of this application, please refer to Figure 5 The seamless authentication system for distributed devices also includes other devices. The first device, the second device, and other devices are connected in a distributed manner.

[0113] The first device is also used for:

[0114] A first vendor root certificate is pre-installed in the first security chip. The first vendor root certificate is used to verify the public key certificate of other devices sent by other devices when other devices perform seamless authentication of the first device, so as to obtain the device public key of other devices.

[0115] In one embodiment of this application, please refer to Figure 5 The seamless authentication system for distributed devices also includes relay devices. The first device, the second device, and the relay devices are connected in a distributed manner.

[0116] The first device is also used for:

[0117] Obtain communication topology information, which includes the existence of a first communication connection between the first device and the relay device, and the existence of a second communication connection between the second device and the relay device;

[0118] The forwarding instruction, public key certificate, and authentication ciphertext are sent to the relay device through the first communication connection. The forwarding instruction is used to instruct the relay device to send the public key certificate and authentication ciphertext to the second device.

[0119] The second device is also used for:

[0120] Obtain communication topology information and receive the public key certificate and authentication ciphertext sent by the relay device through the second communication connection.

[0121] The beneficial effects of the transfer equipment have been explained in steps S1010-S1030 above, and will not be repeated here.

[0122] In summary, the seamless authentication method and system for distributed devices provided by this invention ensures that HarmonyOS devices manufactured by the same company have a pre-installed manufacturer's root certificate, public key certificate, and device private key in their security chip before leaving the factory. When a first device and a second device establish a distributed connection via a distributed soft bus, the first device directly obtains the public key certificate and device private key from the security chip, generates authentication ciphertext based on the device private key, and sends the public key certificate, device private key, and authentication ciphertext to the second device. Simultaneously, the second device obtains its internal manufacturer's root certificate to verify the public key certificate, obtains the device public key, decrypts the authentication ciphertext, and compares the decrypted authentication plaintext with the original authentication plaintext. If they match, the first device and the second device have successfully authenticated. Using the method of this application, the first device can guarantee the authentication of the second device, improving the security of distributed device connections and enhancing data security. Simultaneously, during the authentication process between the first and second devices, the first and second devices autonomously send and return authentication information via a distributed soft bus. Therefore, the solution in this application eliminates the need for user intervention or information input during the entire device authentication process, simplifying the authentication process, achieving seamless authentication of distributed devices, optimizing user experience, and improving authentication efficiency. Furthermore, since all devices from the same manufacturer have pre-set mutually matching authentication data, the seamless authentication method of this application can be applied to all HarmonyOS devices from the same manufacturer, effectively improving the device applicability of the authentication method.

[0123] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent modifications made based on the content of the present invention specification and drawings, or direct or indirect applications in related technical fields, are similarly included within the patent protection scope of the present invention.

Claims

1. A seamless authentication method for distributed devices, characterized in that, The method includes: The first device obtains a device public key and a device private key, and the device public key and the device private key are matched with each other; The first device obtains a public key certificate based on the device's public key; The first device generates authentication ciphertext based on the device's private key; The first device sends the public key certificate and the authentication ciphertext to the second device via a distributed soft bus. The first device is distributedly connected to at least one of the second devices. The first device is used to authenticate the second device. The second device receives the public key certificate and authentication ciphertext; The second device authenticates the ciphertext based on the public key certificate and returns the authentication result through the distributed soft bus; The first device receives the authentication result and completes the authentication; The first device includes a first security chip; the first device has a first vendor root certificate pre-installed in the first security chip, the first vendor root certificate is used to verify the public key certificate of other devices sent by other devices when other devices perform seamless authentication of the first device, so as to obtain the device public key of other devices; The second device includes a second security chip; the second device has a second vendor root certificate pre-installed in the second security chip; the second vendor root certificate is used by the second device to verify the public key certificate when the first device performs contactless authentication on the second device; The first vendor root certificate and the second vendor root certificate are matched.

2. The contactless authentication method for distributed devices according to claim 1, characterized in that, The first device generates authentication ciphertext based on the device's private key, including: The first device generates an authentication random number; The first device encrypts the authentication random number using the device's private key to obtain the authentication ciphertext.

3. The contactless authentication method for distributed devices according to claim 2, characterized in that, The first device sends the public key certificate and authentication ciphertext to the second device via a distributed soft bus, including: The first device sends the public key certificate, the authentication ciphertext, and the authentication random number to the second device via the distributed soft bus.

4. The contactless authentication method for distributed devices according to claim 3, characterized in that, The second device authenticates the ciphertext based on the public key certificate and returns the authentication result, including: The second device obtains the device public key based on the public key certificate; The second device decrypts the authentication ciphertext using the device's public key to obtain the authentication plaintext; The second device compares the authentication plaintext and the authentication random number to obtain the authentication result, and returns the authentication result through the distributed soft bus.

5. The contactless authentication method for distributed devices according to claim 1, characterized in that, Before the first device obtains the device public key and device private key, the process also includes: The first device generates a device public key and a device private key, and stores the device private key in the first security chip.

6. The contactless authentication method for distributed devices according to claim 5, characterized in that, The first device obtains a public key certificate based on the device's public key, including: The first device sends the device public key and the issuance instruction to the encryption terminal. The issuance instruction is used to instruct the encryption terminal to issue the device public key to obtain a public key certificate. The encryption terminal is used to issue a certificate for the first device. The certificate issued by the encryption terminal matches the root certificate of the first vendor.

7. The contactless authentication method for distributed devices according to claim 4, characterized in that, The second device obtains the device public key based on the public key certificate, including: The second device obtains the second vendor's root certificate from the second security chip; When the first device performs seamless authentication on the second device, the second device verifies the public key certificate through the second vendor's root certificate. If the verification is successful, the device's public key is obtained.

8. The contactless authentication method for distributed devices according to claim 1, characterized in that, After the first device receives the authentication result, it further includes: When the first device determines that the authentication result is successful, it adds the second device to a preset list of trusted devices.

9. The contactless authentication method for distributed devices according to claim 1, characterized in that, The first device sends the public key certificate and the authentication ciphertext to the second device via a distributed soft bus, including: The first device acquires communication topology information, which includes a first communication connection between the first device and the relay device, and a second communication connection between the second device and the relay device. The first device sends a forwarding instruction, the public key certificate, and the authentication ciphertext to the relay device through the first communication connection. The forwarding instruction is used to instruct the relay device to send the public key certificate and the authentication ciphertext to the second device. The second device acquires the communication topology information and receives the public key certificate and the authentication ciphertext sent by the relay device through the second communication connection; The first device, the second device, and the relay device are connected in a distributed manner.

10. A contactless authentication system for distributed devices, characterized in that, It includes a first device and at least one second device, wherein the first device and at least one second device are distributedly connected, and the first device is used to authenticate the second device; The first device is used for: Obtain the device public key and device private key, and match the device public key and device private key with each other; Obtain the public key certificate based on the device's public key; Generate authentication ciphertext based on the device's private key; The public key certificate and the authentication ciphertext are sent to the second device via a distributed soft bus; The second device is used for: Receive the public key certificate and authentication ciphertext; The authentication ciphertext is authenticated based on the public key certificate, and the authentication result is returned through the distributed soft bus; The first device is also used for: Receive the authentication result and complete the authentication; The first device includes a first security chip; the first device has a first vendor root certificate pre-installed in the first security chip, the first vendor root certificate is used to verify the public key certificate of other devices sent by other devices when other devices perform seamless authentication of the first device, so as to obtain the device public key of other devices; The second device includes a second security chip; the second device has a second vendor root certificate pre-installed in the second security chip; the second vendor root certificate is used by the second device to verify the public key certificate when the first device performs seamless authentication on the second device.