Iot login authentication method, device and related equipment
By introducing a mechanism in IoT devices that authenticates target tokens and application identifiers via an authentication server, the security risks of IoT device login authentication are resolved, a more secure login process is achieved, and the forged identifiers are prevented from obtaining login information.
Patent Information
- Application Number
- CN202410757429.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-12
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2044-06-12
AI Technical Summary
There is a security risk that IoT devices may forge IMEI or IMSI to obtain device information that does not belong to them during the login authentication process, which cannot ensure the security of the login.
The IoT server sends a redirection command to the user terminal. The user terminal sends the first application identifier code to the authentication server. The authentication server generates a target token and sends it to the user terminal. The user terminal then sends the token to the IoT server. After authenticating the token and identifier code, the authentication server obtains the user terminal's identifier code and sends login information if the authentication rules are met.
This enhances the security of IoT device login, prevents the forgery of user terminal identification codes to obtain login information that does not belong to the user terminal, and ensures the security of the login process.
Smart Images

Figure CN118827148B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of Internet of Things, and particularly relates to an Internet of Things login authentication method and device and related equipment. BACKGROUND
[0002] Internet of Things (IoT) refers to a network technology that connects all objects with the Internet through various information sensing devices and network technologies to realize intelligent identification, positioning, tracking, monitoring and management through information exchange and communication. Currently, when an Internet of Things device accesses an Internet of Things platform, the process of obtaining device authentication information by the Internet of Things device transmitting an International Mobile Equipment Identity (IMEI) or an International Mobile Subscriber Identity (IMSI) to the Internet of Things platform is implemented by the program logic of the device manufacturer, which may have the possibility of obtaining device information that does not belong to the user terminal by forging the IMEI, that is, the Internet of Things login authentication has security risks and cannot ensure the security of the Internet of Things device login. SUMMARY
[0003] The embodiments of the present application provide an Internet of Things login authentication method and device and related equipment, which can eliminate the possibility of obtaining login information that does not belong to the user terminal by forging the identification code of the user terminal, and further improve the security of the Internet of Things device login.
[0004] In a first aspect, the embodiments of the present application provide an Internet of Things login authentication method applied to a user terminal, and the method comprises the following steps.
[0005] According to a preset application programming interface of an Internet of Things server, a login request is sent to the Internet of Things server, so that the Internet of Things server sends a redirection command to the user terminal, the redirection command comprises a preset redirection path and a preset first application identification code, the first application identification code corresponds to the Internet of Things server, and the login request is used to request to obtain login information of the user terminal;
[0006] In response to the redirection command, the first application identification code is sent to an authentication server according to the redirection path, so that the authentication server generates a target token, the target token is associated with the user terminal, and the authentication server sends the target token and a preset callback address to the user terminal;
[0007] sending the target token to the IoT server according to the callback address, so that the IoT server sends an acquisition request to the authentication server, the acquisition request comprising the target token; the authentication server authenticates the target token and the first application identification code, generates a first authentication result, and in a case where the first authentication result indicates that the target token and the first application identification code satisfy the authentication rule, acquires an identification code of the user terminal and sends the identification code of the user terminal to the IoT server; and the IoT server sends the login information associated with the identification code of the user terminal to the user terminal.
[0008] logging in to the IoT server based on the login information.
[0009] In a second aspect, an IoT login authentication method is provided, applied to an IoT server, and comprising:
[0010] receiving a login request sent by a user terminal, the login request being a request sent by the user terminal to the IoT server according to a preset application programming interface of the IoT server, the login request being used to request acquisition of login information of the user terminal;
[0011] sending a redirection command to the user terminal, so that the user terminal sends a preset first application identification code to an authentication server according to a preset redirection path in response to the redirection command, the redirection command comprising the redirection path and the first application identification code, the first application identification code corresponding to the IoT server; the authentication server generates a target token and sends the target token and a preset callback address to the user terminal, the target token being associated with the user terminal; and the user terminal sends the target token to the IoT server according to the callback address.
[0012] sending an acquisition request to the authentication server, the acquisition request comprising the target token, so that the authentication server authenticates the target token and the first application identification code, generates a first authentication result, and in a case where the first authentication result indicates that the target token and the first application identification code satisfy the authentication rule, acquires an identification code of the user terminal and sends the identification code of the user terminal to the IoT server;
[0013] sending the login information associated with the identification code of the user terminal to the user terminal, so that the user terminal logs in to the IoT server based on the login information.
[0014] In a third aspect, an IoT login authentication method is provided, applied to an authentication server, and comprising:
[0015] receiving a preset first application identification code sent by the user terminal according to a preset redirection path in response to a redirection command, the redirection command being a command sent by the Internet of Things server to the user terminal in response to a login request sent by the user terminal to the Internet of Things server, the login request being a request sent by the user terminal to the Internet of Things server according to a preset application programming interface of the Internet of Things server, the login request being used to request to obtain login information of the user terminal, the redirection command including the redirection path and the first application identification code, the first application identification code corresponding to the Internet of Things server;
[0016] generating a target token, the target token being associated with the user terminal;
[0017] sending the target token and a preset callback address to the user terminal, so that the user terminal sends the target token to the Internet of Things server according to the callback address; the Internet of Things server sends an obtaining request to the authentication server, the obtaining request including the target token;
[0018] authenticating the target token and the first application identification code, and generating a first authentication result, the first authentication result being used to indicate whether the target token and the first application identification code meet the authentication rule;
[0019] in a case where the first authentication result indicates that the target token and the first application identification code meet the authentication rule, obtaining an identification code of the user terminal, and sending the identification code of the user terminal to the Internet of Things server, so that the Internet of Things server sends the login information associated with the identification code of the user terminal to the user terminal, and the user terminal logs in to the Internet of Things server based on the login information.
[0020] In a fourth aspect, an embodiment of the present application provides an Internet of Things login authentication device, applied to a user terminal, and the device comprises:
[0021] a first sending module, configured to send a login request to the Internet of Things server according to a preset application programming interface of the Internet of Things server, so that the Internet of Things server sends a redirection command to the user terminal, the redirection command including a preset redirection path and a preset first application identification code, the first application identification code corresponding to the Internet of Things server, the login request being used to request to obtain login information of the user terminal;
[0022] The second sending module is configured to, in response to the redirection command, send the first application identification code to an authentication server according to the redirection path, so that the authentication server generates a target token, the target token being associated with the user terminal; and the authentication server sends the target token and a preset callback address to the user terminal.
[0023] The third sending module is configured to send the target token to the Internet of Things server according to the callback address, so that the Internet of Things server sends an acquisition request to the authentication server, the acquisition request including the target token; the authentication server authenticates the target token and the first application identification code, generates a first authentication result, acquires an identification code of the user terminal, and sends the identification code of the user terminal to the Internet of Things server, in a case where the first authentication result indicates that the target token and the first application identification code satisfy the authentication rule; and the Internet of Things server sends the login information associated with the identification code of the user terminal to the user terminal.
[0024] The login module is configured to log in to the Internet of Things server based on the login information.
[0025] In a fifth aspect, an embodiment of the present application provides an Internet of Things login authentication device, applied to an Internet of Things server, and the device includes:
[0026] The first receiving module is configured to receive a login request sent by a user terminal, the login request being a request sent by the user terminal to the Internet of Things server according to a preset application programming interface of the Internet of Things server, the login request being used to request acquisition of login information of the user terminal.
[0027] The fourth sending module is configured to send a redirection command to the user terminal, so that the user terminal sends a preset first application identification code to an authentication server according to a preset redirection path in response to the redirection command, the redirection command including the redirection path and the first application identification code, the first application identification code corresponding to the Internet of Things server; the authentication server generates a target token and sends the target token and a preset callback address to the user terminal, the target token being associated with the user terminal; and the user terminal sends the target token to the Internet of Things server according to the callback address.
[0028] The fifth sending module is used to send an acquisition request to the authentication server, the acquisition request including the target token, so that the authentication server can authenticate the target token and the first application identifier code, generate a first authentication result, and if the first authentication result indicates that the target token and the first application identifier code meet the authentication rules, acquire the identifier code of the user terminal, and send the identifier code of the user terminal to the Internet of Things server.
[0029] The sixth sending module is used to send the login information associated with the identification code of the user terminal to the user terminal, so that the user terminal can log in to the Internet of Things server based on the login information.
[0030] Sixthly, embodiments of this application provide an Internet of Things (IoT) login authentication device applied to an authentication server, the device comprising:
[0031] The second receiving module is used to receive a preset first application identifier code sent by a user terminal in response to a redirection command according to a preset redirection path. The redirection command is a command sent by the IoT server to the user terminal after receiving a login request from the user terminal. The login request is a request sent by the user terminal to the IoT server according to a preset application programming interface of the IoT server. The login request is used to request to obtain the login information of the user terminal. The redirection command includes the redirection path and the first application identifier code, and the first application identifier code corresponds to the IoT server.
[0032] A generation module is used to generate a target token, which is associated with the user terminal;
[0033] The seventh sending module is used to send the target token and a preset callback address to the user terminal, so that the user terminal sends the target token to the IoT server according to the callback address; the IoT server sends an acquisition request to the authentication server, the acquisition request including the target token;
[0034] A first authentication module is used to authenticate the target token and the first application identifier code, and generate a first authentication result. The first authentication result is used to indicate whether the target token and the first application identifier code meet the authentication rules.
[0035] The first acquisition module is configured to acquire the identifier code of the user terminal when the first authentication result indicates that the target token and the first application identifier code satisfy the authentication rules, and send the identifier code of the user terminal to the Internet of Things server, so that the Internet of Things server sends the login information associated with the identifier code of the user terminal to the user terminal, and the user terminal logs in to the Internet of Things server based on the login information.
[0036] In a seventh aspect, embodiments of this application provide an electronic device, the device including: a processor and a memory storing computer program instructions; the processor, when executing the computer program instructions, implements the IoT login authentication method as described above.
[0037] Eighthly, embodiments of this application provide a computer-readable storage medium storing computer program instructions, which, when executed by a processor, implement the IoT login authentication method described in any of the above claims.
[0038] Ninthly, embodiments of this application provide a computer program product, wherein instructions in the computer program product, when executed by a processor of an electronic device, cause the electronic device to perform the IoT login authentication method as described in any of the above claims.
[0039] The IoT login authentication method, apparatus, and related devices of this application embodiment allow a user terminal to send a login request to an IoT server according to a preset IoT server application programming interface; the IoT server sends a redirection command to the user terminal, the redirection command including a preset redirection path and a preset first application identifier; the user terminal responds to the redirection command and sends the first application identifier to an authentication server according to the redirection path; the authentication server generates a target token and sends the target token and a preset callback address to the user terminal, the target token being associated with the user terminal; the user terminal then sends the target token to the IoT server according to the callback address; the IoT server sends an acquisition request to the authentication server, the acquisition request including the target token; the authentication server authenticates the target token and the first application identifier, generates a first authentication result, and if the first authentication result indicates that the target token and the first application identifier satisfy the authentication rules, it acquires the user terminal's identifier and sends the user terminal's identifier to the IoT server; the IoT server sends login information associated with the user terminal's identifier to the user terminal; finally, the user terminal logs into the IoT server based on the login information. Thus, in this embodiment of the application, the target token and the first application identifier are authenticated by the authentication server. Only when the target token and the first application identifier meet the authentication rules is the identifier of the real and valid user terminal obtained and sent to the IoT server. In this way, the user terminal can obtain the login information associated with the identifier and log in. The entire login authentication process is secure, and there is no possibility of forging the user terminal's identifier to obtain login information that does not belong to the user terminal, further improving the security of IoT device login. Attached Figure Description
[0040] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0041] Figure 1 This is an architecture diagram of the IoT login authentication system provided in the embodiments of this application;
[0042] Figure 2 This is a flowchart illustrating the IoT login authentication method provided in an embodiment of this application;
[0043] Figure 3 This is a flowchart illustrating a scenario embodiment provided in this application.
[0044] Figure 4 This is a schematic diagram of the structure of an IoT login authentication device provided in an embodiment of this application;
[0045] Figure 5This is a schematic diagram of another IoT login authentication device provided in an embodiment of this application;
[0046] Figure 6 This is a schematic diagram of the structure of another IoT login authentication device provided in the embodiments of this application;
[0047] Figure 7 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0048] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.
[0049] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.
[0050] The Internet of Things (IoT) refers to a network technology that connects all objects to the internet through various information sensing devices and network technologies, enabling information exchange and communication to achieve intelligent identification, positioning, tracking, monitoring, and management. Currently, when IoT devices connect to an IoT platform, the process of transmitting the International Mobile Equipment Identity (IMEI) or International Mobile Subscriber Identity (IMSI) code to the platform for authentication is handled by the device manufacturer's own programming logic. This raises the possibility of forging IMEIs to obtain information about devices that do not belong to the manufacturer, thus creating a security vulnerability in IoT login authentication and failing to guarantee the security of IoT device logins.
[0051] To address the problems of existing technologies, embodiments of this application provide an IoT login authentication method, apparatus, and related equipment. The IoT login authentication method provided in this application is first described below, outlining the IoT login authentication system to which it is applicable.
[0052] Figure 1 An architecture diagram of an IoT login authentication system provided in one embodiment of this application is shown. Figure 1 As shown, the IoT login authentication system 100 may include: a user terminal 101, an IoT server 102, and an authentication server 103.
[0053] The aforementioned user terminal 101 can be a physical device capable of connecting to the Internet. It can collect data, send data, or perform data-based tasks. The range of user terminals is very broad, including but not limited to: smart home devices such as smart bulbs, smart sockets, and smart thermostats; wearable devices such as smartwatches and health monitoring bracelets; industrial automation equipment such as sensors, controllers, and robots; medical devices such as remote monitoring equipment and smart pillboxes; agricultural equipment such as soil moisture sensors and weather stations; and transportation equipment such as smart traffic lights and vehicle information systems. In this embodiment, the user terminal is a OneNET Narrow Band Internet of Things (NBOT) device.
[0054] The aforementioned IoT server 102 can refer to a computer device that provides user terminal management and data processing services in the Internet of Things (IoT). IoT servers are typically operated by IoT platform providers, and they are responsible for handling login requests from a large number of user terminals, data collection, analysis, and storage.
[0055] The aforementioned authentication server 103 can be a server capable of providing the identification code of a user terminal. For example, the authentication server can be a server of a mobile communication service operator providing cellular networks. After the communication module in the user terminal is attached to a base station near the mobile communication service operator and ready, the mobile communication service operator can know the identification code of the user terminal, such as IMSI, Integrated Circuit Card Identifier (ICCID), IMEI, mobile phone number, etc., thereby enabling the user terminal to log in to the Internet of Things server via the Internet.
[0056] User terminal 101, IoT server 102, and authentication server 103 are connected for communication. Specifically, they can communicate using Ethernet or wireless networks. Of course, the communication method is not limited to these; other network connection methods can also be used, which are not specifically limited here.
[0057] The IoT login authentication method provided in the embodiments of this application will be described below.
[0058] Figure 2 A flowchart illustrating an IoT login authentication method according to an embodiment of this application is shown. Optionally, the method of this application embodiment can be applied to the above-described... Figure 1 The user terminal 101, IoT server 102, and authentication server 103 are shown. Figure 2 As shown, an IoT login authentication method may include the following steps S201 to S211:
[0059] S201. The user terminal sends a login request to the IoT server according to the preset application programming interface of the IoT server. The login request is used to request the user terminal's login information.
[0060] S202. The IoT server sends a redirection command to the user terminal. The redirection command includes a preset redirection path and a preset first application identifier code, which corresponds to the IoT server.
[0061] S203. The user terminal responds to the redirection command and sends the first application identifier code to the authentication server according to the redirection path;
[0062] S204. The authentication server generates a target token, which is associated with the user terminal.
[0063] S205. The authentication server sends the target token and the preset callback address to the user terminal.
[0064] S206. The user terminal sends the target token to the IoT server according to the callback address;
[0065] S207. The IoT server sends an acquisition request to the authentication server, the acquisition request including the target token;
[0066] S208. The authentication server authenticates the target token and the first application identifier code, and generates the first authentication result.
[0067] S209. If the first authentication result indicates that the target token and the first application identifier code meet the authentication rules, the authentication server obtains the identifier code of the user terminal and sends the identifier code of the user terminal to the Internet of Things server.
[0068] S210, the IoT server sends the login information associated with the user terminal's identification code to the user terminal;
[0069] S211. The user terminal logs into the IoT server based on the login information.
[0070] The IoT login authentication method of this application embodiment includes the following steps: A user terminal can send a login request to an IoT server according to a preset IoT server application programming interface; the IoT server sends a redirection command to the user terminal, the redirection command including a preset redirection path and a preset first application identifier; the user terminal responds to the redirection command and sends the first application identifier to an authentication server according to the redirection path; the authentication server generates a target token and sends the target token and a preset callback address to the user terminal, the target token being associated with the user terminal; the user terminal then sends the target token to the IoT server according to the callback address; the IoT server sends an acquisition request to the authentication server, the acquisition request including the target token; the authentication server authenticates the target token and the first application identifier, generates a first authentication result, and if the first authentication result indicates that the target token and the first application identifier satisfy the authentication rules, it acquires the user terminal's identifier and sends the user terminal's identifier to the IoT server; the IoT server sends login information associated with the user terminal's identifier to the user terminal. Finally The user terminal logs into the IoT server based on the login information. Thus, in this embodiment, the target token and the first application identifier are authenticated by the authentication server. Only when the target token and the first application identifier meet the authentication rules is the genuine and valid user terminal identifier obtained and sent to the IoT server. This allows the user terminal to obtain the login information associated with the identifier and log in. The entire login authentication process is secure, eliminating the possibility of forging the user terminal's identifier to obtain login information that does not belong to the user terminal, further enhancing the security of IoT device login.
[0071] In S201, the aforementioned application programming interface (API) is a pre-set (e.g., burned) API interface exposed by the IoT server into the user terminal by the device manufacturer of the user terminal, which allows the user terminal to authenticate and log in to the IoT server through it.
[0072] The login request described above can be used to request login information from a user terminal. For example, login information may include a device ID and key named at the business level, a certificate, or login information such as username, client ID, and password.
[0073] In S202, the aforementioned redirection command may include a preset redirection path and a preset first application identifier. The redirection path is an address path that is pre-set in the IoT server and can be redirected to the authentication server. The first application identifier is an application identifier that represents the identity of the IoT server, that is, the first application identifier corresponds to the IoT server.
[0074] In S203, the user terminal responds to the redirection command and sends the first application identifier code to the authentication server according to the redirection path. For example, the user terminal may respond to the redirection command and send the first application identifier code to the authentication server via wireless communication according to the redirection path.
[0075] In S204, the authentication server generates a target token. For example, the authentication server may randomly and temporarily generate a target token and associate the target token with the user terminal.
[0076] In S205, the aforementioned callback address is a pre-set link address in the authentication server, used to send the target token back to the IoT server.
[0077] The authentication server sends the target token and the preset callback address to the user terminal. For example, the authentication server may send the target token and the preset callback address to the user terminal via wireless communication.
[0078] In S206, the user terminal sends the target token to the IoT server according to the callback address. For example, the user terminal may send the target token to the IoT server via wireless communication according to the callback address.
[0079] In S207, the aforementioned acquisition request includes the target token. The acquisition request can be used to request the identification code of the user terminal.
[0080] The aforementioned IoT server sends an acquisition request to the authentication server. For example, the IoT server may send the acquisition request to the authentication server via wireless communication.
[0081] In S208, the aforementioned first authentication result can be used to indicate whether the target token and the first application identifier code satisfy the authentication rules. These authentication rules can be whether the target token sent by the IoT server to the authentication server in step S207 is consistent with the target token generated by the authentication server in step S204, and whether the first application identifier code transmitted in steps S202 and S203 is consistent with the application identifier code pre-set in the authentication server corresponding to the IoT server; alternatively, the authentication rule can also be whether the result obtained by calculating the target token sent by the IoT server to the authentication server in step S207 and the first application identifier code transmitted in steps S202 and S203 using a preset encryption algorithm is consistent with the result obtained by calculating the target token generated by the authentication server in step S204 and the application identifier code pre-set in the authentication server corresponding to the IoT server using the same encryption algorithm.
[0082] In S209, the aforementioned first authentication result indicates that the target token and the first application identifier code meet the authentication rules, which means that the authentication process is secure.
[0083] The identification code of the aforementioned user terminal, for example, can be information that uniquely identifies the user terminal, such as at least one of IMEI, IMSI, ICCID, and mobile phone number.
[0084] The authentication server sends the user terminal's identification code to the IoT server. For example, the authentication server may send the user terminal's identification code to the IoT server via wireless communication.
[0085] In S210, the aforementioned IoT server can include login information for multiple user terminals, with different identifiers associated with the login information of different user terminals. If the login information for a user terminal does not exist in the IoT server, then the login information corresponding to that user terminal is created and generated.
[0086] The aforementioned IoT server sends login information associated with the user terminal's identification code to the user terminal. For example, the IoT server may send the login information associated with the user terminal's identification code to the user terminal via wireless communication.
[0087] In S211, the aforementioned user terminal logs into the IoT server based on login information. For example, the user terminal can log into the IoT server via the lwm2m protocol based on login information such as username, clientID, and password.
[0088] In existing technologies, when a user terminal connects to an IoT server, login information, such as keys or certificates, needs to be pre-written into the user terminal. This adds an extra step, meaning that the corresponding user terminal also needs to be created in the IoT server beforehand, and the recorded user terminal login information and its correspondence with the user terminals need to be maintained. In other words, it is necessary to record which user terminal has recorded which login information to facilitate subsequent after-sales management of user terminals, leading to an increase in production and management costs.
[0089] As one implementation of this application, in order to reduce production and management costs, prior to S201 above, the method may further include:
[0090] The user terminal obtains the application programming interface, application programming interface address and first application identifier code of the Internet of Things server. The first application identifier code is the identifier code corresponding to the Internet of Things server in the authentication server.
[0091] The user terminal sets the application programming interface, the application programming interface address, and the first application identifier code in the user terminal.
[0092] The aforementioned first application identifier code can be the identifier code corresponding to the IoT server in the authentication server.
[0093] The application programming interface (API), API address, and first application identifier of the aforementioned IoT server are publicly disclosed by the IoT server itself.
[0094] The aforementioned user terminal sets the application programming interface (API), API address, and first application identifier code in the user terminal. For example, the user terminal can write a program and burn firmware according to the API, API address, and first application identifier code to realize the setting of the API, API address, and first application identifier code in the user terminal.
[0095] In this embodiment, before a user terminal logs in, when a user terminal of the same model from the same manufacturer leaves the factory, it only needs to burn the same firmware (i.e., the aforementioned application programming interface, application programming interface address, and first application identifier code). It is no longer necessary to burn different login information (such as device ID, device key, or device certificate) for each device, nor is it necessary to create each user terminal in the IoT server in advance, nor is it necessary for the manufacturer to maintain a login information mapping table for each user terminal before leaving the factory, thereby reducing production and management costs.
[0096] As another implementation of this application, in order to securely generate the target token, the method may further include the following before S204:
[0097] The authentication server authenticates the first application identifier code based on the preset second application identifier code to obtain a second authentication result. The second authentication result is used to indicate whether the first application identifier code and the second application identifier code are consistent.
[0098] Specifically, S204 mentioned above may include:
[0099] If the authentication server generates a target token when the second authentication result indicates that the first application identifier code and the second application identifier code are consistent.
[0100] The aforementioned second application identifier is the application identifier corresponding to the IoT server in the authentication server. Theoretically, the first application identifier and the second application identifier are identical.
[0101] The aforementioned second authentication result can be used to indicate whether the first application identifier code and the second application identifier code are consistent.
[0102] In this embodiment of the application, there may be security risks in the process of the user terminal sending the first application identifier code to the authentication server through the redirection path. Therefore, the authentication server first authenticates the first application identifier code according to the preset second application identifier code to improve security, and finally securely generates the target token when the second authentication result indicates that the first application identifier code and the second application identifier code are consistent.
[0103] As another implementation of this application, in order to respect user privacy, protect user data security, and establish user trust, the aforementioned authentication server generates a target token when the second authentication result indicates that the first application identifier and the second application identifier are consistent. Specifically, this may include:
[0104] If the authentication server indicates that the first application identifier code and the second application identifier code are consistent in the second authentication result, it sends authorization confirmation information to the user terminal.
[0105] Based on the authorization confirmation information, the user terminal sends the user's confirmation authorization request to the authentication server. The authorization confirmation information is used to prompt the user whether to confirm the authorization.
[0106] The authentication server responds to the authorization confirmation request by generating the target token.
[0107] The aforementioned authorization confirmation information can be used to prompt the user to confirm authorization. This information may include: the platform name of the IoT server, a first application identifier, the desired IMEI and IMSI information of the user terminal, whether authorization is permitted, and an address where authorization is permitted. Furthermore, the user terminal also contains a second application identifier for the IoT server. After receiving the authorization confirmation information, the user can compare the first application identifier in the confirmation information with the preset second application identifier for the IoT server in the user terminal. Once the user confirms that everything is correct, they can enter a confirmation authorization request and send it to the authentication server.
[0108] In this embodiment, when the second authentication result indicates that the first application identifier code and the second application identifier code are consistent, the authentication server sends authorization confirmation information to the user terminal. This respects user privacy, protects user data security, and establishes user trust. The user terminal sends the user's confirmation authorization request to the authentication server based on the authorization confirmation information. Finally, the authentication server responds to the confirmation authorization request and generates a target token.
[0109] In some embodiments, the above-described S207 may specifically include:
[0110] The IoT server sends an acquisition request to the authentication server, and the acquisition request also includes a preset application key;
[0111] Specifically, S208 mentioned above may include:
[0112] The authentication server authenticates the target token, the first application identifier, and the application key, and generates a first authentication result. The first authentication result is used to indicate whether the target token, the first application identifier, and the application key meet the authentication rules.
[0113] The application key mentioned above is a preset key in the IoT server.
[0114] In this embodiment of the application, the request also includes a preset application key. In this way, the authentication server can generate a first authentication result using the target token, the first application identifier, and the application key, thereby further improving the security of the login authentication process and ensuring the authenticity of the user terminal's identifier.
[0115] To facilitate understanding of the IoT login authentication method in the embodiments of this application, the actual application process of this IoT login authentication method is described as follows:
[0116] During the process of a device (equivalent to the aforementioned user terminal) accessing the internet through the cellular network provided by an operator, once the communication module inside the device has attached to a nearby operator base station and is ready, the operator knows the device's (UE user terminal's) IMSI, ICCID, IMEI, and phone number. Based on this premise, operators have opened up device authentication capabilities through their capability open platforms, but currently this is limited to mobile devices. It requires importing Android or iOS software development kits (SDKs) on the terminal side, making it unsuitable for embedded devices like IoT devices with low computing power that are not running Android / iOS systems. Furthermore, it only allows the acquisition of phone numbers. The IoT SIM card authentication open platform (equivalent to the aforementioned authentication server) has the capability to provide the device's IMEI and IMSI.
[0117] The first step is preparation:
[0118] s1: The staff of the IoT platform (equivalent to the IoT server mentioned above) apply for an application ID (equivalent to the second application identifier code mentioned above) and an application secret (equivalent to the application key mentioned above) from the operator's IoT card authentication open platform, and set a result callback link (equivalent to the link of the callback address mentioned above) on the IoT card authentication open platform to obtain the authentication request address of the open platform (equivalent to the address of the redirect path mentioned above).
[0119] s2: The IoT platform discloses its login authentication API interface and address, along with its application ID (equivalent to the first application identifier code mentioned above).
[0120] s3: The device manufacturer writes a program and flashes firmware onto the device based on the API interface, address, and application ID (i.e., the second application identifier).
[0121] The second part of the steps is the login authentication process, such as... Figure 3 As shown:
[0122] s4: After the device successfully registers with the network, it requests login information from the IoT platform through the IoT platform's API interface.
[0123] s5: After receiving the device's login request, the IoT platform replies with a command to redirect the device to the IoT SIM card authentication open platform, and appends its own application ID to the redirection path as a parameter.
[0124] s6: The device performs a redirection, sending the application ID to the IoT SIM card authentication open platform.
[0125] S7: After receiving the device's request, the IoT SIM card authentication open platform verifies the application ID and replies to the device. If the verification is successful, the reply tells the device which platform it is, what its application ID is, what it wants to obtain the corresponding IMEI and IMSI information (i.e., the user terminal's identification code), whether authorization is allowed, and includes the authorized address.
[0126] s8: After receiving the authorization confirmation information from the IoT SIM card authentication open platform, the device sends a confirmation authorization request to the IoT SIM card authentication open platform.
[0127] S9: After receiving the confirmation and authorization request from the device, the IoT SIM card authentication open platform generates a random temporary token (i.e., the target token mentioned above), associates this token with the device, redirects to the IoT platform (the redirection address is the callback link set by the IoT platform), and appends the token to the link as a parameter.
[0128] s10: The device performs a redirection, returns the token to the IoT platform, and waits for a response from the IoT platform.
[0129] s11: After receiving the device's token, the IoT platform uses the token, its own application ID, and application secret to request the device's IMEI and IMSI from the IoT SIM card authentication open platform.
[0130] s12: The IoT SIM card authentication open platform receives the request, verifies it, and then returns the IMEI and IMSI of the device associated with the token.
[0131] S13: After receiving the response, the IoT platform obtains the device's IMEI and IMSI. The platform then responds to the request in S10 by providing the device login information associated with this IMEI and IMSI to the device. If the corresponding device login information does not exist on the platform, the platform creates the device, generates the device login information, and sends it back to the device.
[0132] s14: After receiving the login information (which may be the device ID and key, or a certificate) from the IoT platform, the device saves this login information and uses it to log in to the IoT platform (for example, an MQTT device obtains the username, clientId, and password and uses these three elements to log in to the IoT platform).
[0133] In this embodiment, during the process of a device obtaining its own login information, the device's application logic does not need to carry any identifiers or passwords, ensuring that each device only needs to flash the same firmware. Furthermore, the entire formal authentication process is fully automated and requires no manual intervention. Throughout the device authentication process, the IoT SIM card authentication open platform only provides the IoT platform with the device's IMSI, IMEI, and other information; even the device itself is unaware of this. The device only receives a token that is meaningless to itself. The IoT platform uses this token, along with its application ID and application secret, to obtain device information from the authentication platform. This ensures strict protection of device information. This method is also applicable to embedded IoT platforms with limited computing power and does not require importing (or compiling) the operator's Android / iOS SDK on the device side. The IMEI and IMSI are provided by the operator, not by the device itself, eliminating the possibility of the device forging others' information. On the IoT platform, it does not affect the pre-creation of devices; devices can be created after obtaining device information, improving the flexibility of device access to the platform. In step s1 above, the scope of information that the IoT platform needs to obtain can also be pre-set, so that the platform only obtains the IMEI and does not need IMSI, ICCID, or other information. In the steps described above (S7), the IoT SIM card authentication open platform will only respond to the device; this IoT platform only obtains your IMEI. This allows the device to independently determine the scope of the information it provides.
[0134] The aforementioned IoT platforms do not necessarily require both IMEI and IMSI. IoT platforms can choose to obtain only IMEI, IMSI, or other information such as ICCID based on their business needs (generally, only IMEI is obtained because the device is related to the IMEI, not the card; the device instance remains unchanged after a card replacement). Similarly, the IoT card authentication open platform can provide the IoT platform with information such as the traffic usage and approximate geographical location of the IoT card, making the entire method more powerful. If necessary, token expiration and refresh functions can also be added. To prevent malicious registration, IoT platforms can establish whitelists and blacklists for IMEI or IMSI.
[0135] Based on the IoT login authentication method provided in the above embodiments, this application also provides a specific implementation of an IoT login authentication device. It is understood that the relevant descriptions in the following device embodiments can be referenced from the foregoing method embodiments, and for the sake of brevity, will not be repeated. Please refer to the following embodiments.
[0136] Please see Figure 4This is a schematic diagram of the structure of an Internet of Things (IoT) login authentication device 400 provided in an embodiment of this application. It is applied to a user terminal. The device 400 may include: a first sending module 401, a second sending module 402, a third sending module 403, and a login module 404.
[0137] The first sending module 401 is used to send a login request to the Internet of Things (IoT) server according to the preset application programming interface of the IoT server, so that the IoT server sends a redirection command to the user terminal. The redirection command includes a preset redirection path and a preset first application identifier code. The first application identifier code corresponds to the IoT server. The login request is used to request the login information of the user terminal.
[0138] The second sending module 402 is used to respond to the redirection command and send the first application identifier code to the authentication server according to the redirection path, so that the authentication server generates a target token, which is associated with the user terminal; the authentication server sends the target token and a preset callback address to the user terminal.
[0139] The third sending module 403 is used to send the target token to the IoT server according to the callback address, so that the IoT server sends an acquisition request to the authentication server, the acquisition request including the target token; the authentication server authenticates the target token and the first application identifier code, generates a first authentication result, and if the first authentication result indicates that the target token and the first application identifier code meet the authentication rules, it obtains the identifier code of the user terminal and sends the identifier code of the user terminal to the IoT server; the IoT server sends the login information associated with the identifier code of the user terminal to the user terminal;
[0140] Login module 404 is used to log in to the IoT server based on login information.
[0141] The IoT login authentication device of this application embodiment allows a user terminal to send a login request to an IoT server according to a preset IoT server application programming interface; the IoT server sends a redirection command to the user terminal, the redirection command including a preset redirection path and a preset first application identifier; the user terminal responds to the redirection command and sends the first application identifier to the authentication server according to the redirection path; the authentication server generates a target token and sends the target token and a preset callback address to the user terminal, the target token being associated with the user terminal; the user terminal then sends the target token to the IoT server according to the callback address; the IoT server sends an acquisition request to the authentication server, the acquisition request including the target token; the authentication server authenticates the target token and the first application identifier, generates a first authentication result, and if the first authentication result indicates that the target token and the first application identifier satisfy the authentication rules, it acquires the user terminal's identifier and sends the user terminal's identifier to the IoT server; the IoT server sends login information associated with the user terminal's identifier to the user terminal; Finally The user terminal logs into the IoT server based on the login information. Thus, in this embodiment, the target token and the first application identifier are authenticated by the authentication server. Only when the target token and the first application identifier meet the authentication rules is the genuine and valid user terminal identifier obtained and sent to the IoT server. This allows the user terminal to obtain the login information associated with the identifier and log in. The entire login authentication process is secure, eliminating the possibility of forging the user terminal's identifier to obtain login information that does not belong to the user terminal, further enhancing the security of IoT device login.
[0142] As one implementation of this application, in order to respect user privacy, protect user data security, and establish user trust, the aforementioned device 400 may further include:
[0143] The eighth sending module is used to send the user's confirmation authorization request to the authentication server according to the authorization confirmation information, so that the authentication server responds to the confirmation authorization request and generates a target token. The authorization confirmation information is the information sent by the authentication server to the user terminal when the second authentication result indicates that the first application identifier code and the preset second application identifier code are consistent. The authorization confirmation information is used to prompt the user whether to confirm the authorization. The second authentication result is the result obtained by the authentication server based on the second application identifier code to authenticate the first application identifier code.
[0144] As one implementation of this application, in order to reduce production and management costs, the above-mentioned device 400 may further include:
[0145] The second acquisition module is used to acquire the application programming interface, application programming interface address and first application identification code of the Internet of Things server. The first application identification code is the identification code corresponding to the Internet of Things server in the authentication server.
[0146] The configuration module is used to set the application programming interface, application programming interface address and first application identifier code in the user terminal.
[0147] Please see Figure 5 This is a schematic diagram of another IoT login authentication device 500 provided in this application embodiment. It is applied to an IoT server. The device 500 may include: a first receiving module 501, a fourth sending module 502, a fifth sending module 503 and a sixth sending module 504.
[0148] The first receiving module 501 is used to receive a login request sent by a user terminal. The login request is a request sent by the user terminal to the Internet of Things server according to the preset application programming interface of the Internet of Things server. The login request is used to request the user terminal's login information.
[0149] The fourth sending module 502 is used to send a redirection command to the user terminal, so that the user terminal responds to the redirection command and sends a preset first application identifier code to the authentication server according to a preset redirection path. The redirection command includes a redirection path and a first application identifier code, and the first application identifier code corresponds to the IoT server. The authentication server generates a target token and sends the target token and a preset callback address to the user terminal. The target token is associated with the user terminal. The user terminal sends the target token to the IoT server according to the callback address.
[0150] The fifth sending module 503 is used to send an acquisition request to the authentication server. The acquisition request includes a target token, so that the authentication server can authenticate the target token and the first application identifier code, generate a first authentication result, and if the first authentication result indicates that the target token and the first application identifier code meet the authentication rules, acquire the identifier code of the user terminal and send the identifier code of the user terminal to the Internet of Things server.
[0151] The sixth sending module 504 is used to send login information associated with the identification code of the user terminal to the user terminal, so that the user terminal can log in to the Internet of Things server based on the login information.
[0152] The IoT login authentication device of this application embodiment allows a user terminal to send a login request to an IoT server according to a preset IoT server application programming interface; the IoT server sends a redirection command to the user terminal, the redirection command including a preset redirection path and a preset first application identifier; the user terminal responds to the redirection command and sends the first application identifier to the authentication server according to the redirection path; the authentication server generates a target token and sends the target token and a preset callback address to the user terminal, the target token being associated with the user terminal; the user terminal then sends the target token to the IoT server according to the callback address; the IoT server sends an acquisition request to the authentication server, the acquisition request including the target token; the authentication server authenticates the target token and the first application identifier, generates a first authentication result, and if the first authentication result indicates that the target token and the first application identifier satisfy the authentication rules, it acquires the user terminal's identifier and sends the user terminal's identifier to the IoT server; the IoT server sends login information associated with the user terminal's identifier to the user terminal; Finally The user terminal logs into the IoT server based on the login information. Thus, in this embodiment, the target token and the first application identifier are authenticated by the authentication server. Only when the target token and the first application identifier meet the authentication rules is the genuine and valid user terminal identifier obtained and sent to the IoT server. This allows the user terminal to obtain the login information associated with the identifier and log in. The entire login authentication process is secure, eliminating the possibility of forging the user terminal's identifier to obtain login information that does not belong to the user terminal, further enhancing the security of IoT device login.
[0153] In some embodiments, the fifth sending module 503 described above can be specifically used to send an acquisition request to the authentication server. The acquisition request also includes a preset application key, so that the authentication server can authenticate the target token, the first application identifier code and the application key, and generate a first authentication result. The first authentication result is used to indicate whether the target token, the first application identifier code and the application key meet the authentication rules.
[0154] Please see Figure 6 This is a schematic diagram of the structure of another IoT login authentication device 600 provided in the embodiments of this application. It is applied to an authentication server. The device 600 may include: a second receiving module 601, a generating module 602, a seventh sending module 603, a first authentication module 604, and a first acquisition module 605.
[0155] The second receiving module 601 is used to receive a preset first application identifier code sent by the user terminal in response to the redirection command according to a preset redirection path. The redirection command is a command sent by the IoT server to the user terminal after receiving the login request sent by the user terminal. The login request is a request sent by the user terminal to the IoT server according to the preset application programming interface of the IoT server. The login request is used to request to obtain the login information of the user terminal. The redirection command includes a redirection path and a first application identifier code, and the first application identifier code corresponds to the IoT server.
[0156] Generation module 602 is used to generate a target token, which is associated with the user terminal;
[0157] The seventh sending module 603 is used to send the target token and the preset callback address to the user terminal, so that the user terminal sends the target token to the IoT server according to the callback address; the IoT server sends an acquisition request to the authentication server, the acquisition request including the target token;
[0158] The first authentication module 604 is used to authenticate the target token and the first application identifier code, and generate a first authentication result. The first authentication result is used to indicate whether the target token and the first application identifier code meet the authentication rules.
[0159] The first acquisition module 605 is used to acquire the identification code of the user terminal when the first authentication result indicates that the target token and the first application identification code meet the authentication rules, and send the identification code of the user terminal to the Internet of Things server, so that the Internet of Things server sends the login information associated with the identification code of the user terminal to the user terminal, and the user terminal logs in to the Internet of Things server based on the login information.
[0160] The IoT login authentication device of this application embodiment allows a user terminal to send a login request to an IoT server according to a preset IoT server application programming interface; the IoT server sends a redirection command to the user terminal, the redirection command including a preset redirection path and a preset first application identifier; the user terminal responds to the redirection command and sends the first application identifier to the authentication server according to the redirection path; the authentication server generates a target token and sends the target token and a preset callback address to the user terminal, the target token being associated with the user terminal; the user terminal then sends the target token to the IoT server according to the callback address; the IoT server sends an acquisition request to the authentication server, the acquisition request including the target token; the authentication server authenticates the target token and the first application identifier, generates a first authentication result, and if the first authentication result indicates that the target token and the first application identifier satisfy the authentication rules, it acquires the user terminal's identifier and sends the user terminal's identifier to the IoT server; the IoT server sends login information associated with the user terminal's identifier to the user terminal;Finally The user terminal logs into the IoT server based on the login information. Thus, in this embodiment, the target token and the first application identifier are authenticated by the authentication server. Only when the target token and the first application identifier meet the authentication rules is the genuine and valid user terminal identifier obtained and sent to the IoT server. This allows the user terminal to obtain the login information associated with the identifier and log in. The entire login authentication process is secure, eliminating the possibility of forging the user terminal's identifier to obtain login information that does not belong to the user terminal, further enhancing the security of IoT device login.
[0161] As another implementation of this application, in order to securely generate the target token, the above-mentioned device 600 may further include:
[0162] The second authentication module is used to authenticate the first application identifier code according to the preset second application identifier code to obtain a second authentication result. The second authentication result is used to indicate whether the first application identifier code and the second application identifier code are consistent.
[0163] The aforementioned generation module 602 is specifically used to generate a target token when the second authentication result indicates that the first application identifier code and the second application identifier code are consistent.
[0164] As another implementation of this application, in order to respect user privacy, protect user data security, and establish user trust, the aforementioned generation module 602 may specifically include:
[0165] The sending unit is used to send authorization confirmation information to the user terminal when the second authentication result indicates that the first application identifier code and the second application identifier code are consistent, so that the user terminal sends the user's confirmation authorization request to the authentication server according to the authorization confirmation information. The authorization confirmation information is used to prompt the user whether to confirm the authorization.
[0166] The generation unit is used to generate the target token in response to the authorization confirmation request.
[0167] In some embodiments, the above acquisition request may also include a preset application key;
[0168] The aforementioned first authentication module 604 can also be used to authenticate the target token, the first application identifier code, and the application key, and generate a first authentication result. The first authentication result is used to indicate whether the target token, the first application identifier code, and the application key meet the authentication rules.
[0169] Figure 7 A schematic diagram of the hardware structure of the electronic device provided in an embodiment of this application is shown.
[0170] An electronic device may include a processor 701 and a memory 702 storing computer program instructions.
[0171] Specifically, the processor 701 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0172] Memory 702 may include mass storage for data or instructions. For example, and not limitingly, memory 702 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 702 may include removable or non-removable (or fixed) media. Where appropriate, memory 702 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 702 is non-volatile solid-state memory.
[0173] In a particular embodiment, memory 702 may include read-only memory (ROM), random access memory (RAM), disk storage media device, optical storage media device, flash memory device, electrical, optical, or other physical / tangible memory storage device. Thus, generally, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to one aspect of this disclosure.
[0174] The processor 701 reads and executes computer program instructions stored in the memory 702 to implement any of the IoT login authentication methods in the above embodiments.
[0175] In one example, the electronic device may also include a communication interface 703 and a bus 710. For example, Figure 7 As shown, the processor 701, memory 702, and communication interface 703 are connected through bus 710 and complete communication with each other.
[0176] The communication interface 703 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0177] Bus 710 includes hardware, software, or both, that couples components of an electronic device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 710 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, any suitable bus or interconnect is contemplated herein.
[0178] The electronic device can execute the IoT login authentication method in the embodiments of this application, thereby achieving a combination of Figure 2 and Figures 4-6 The IoT login authentication method and apparatus are described.
[0179] Furthermore, in conjunction with the IoT login authentication methods in the above embodiments, this application embodiment can provide a computer-readable storage medium for implementation. This computer-readable storage medium stores computer program instructions; when executed by a processor, these computer program instructions implement any of the IoT login authentication methods in the above embodiments.
[0180] In conjunction with the IoT login authentication method in the above embodiments, this application embodiment can provide a computer program product, in which the instructions of the computer program product, when executed by the processor of an electronic device, cause the electronic device to execute any of the above IoT login authentication methods.
[0181] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0182] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0183] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0184] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0185] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.
Claims
1. An Internet of Things (IoT) login authentication method, characterized in that, Applied to a user terminal, the method includes: According to the preset application programming interface of the IoT server, a login request is sent to the IoT server, so that the IoT server sends a redirection command to the user terminal. The redirection command includes a preset redirection path and a preset first application identifier code, which corresponds to the IoT server. The login request is used to request the login information of the user terminal. In response to the redirection command, the first application identifier is sent to the authentication server according to the redirection path, so that the authentication server generates a target token, which is associated with the user terminal; the authentication server sends the target token and a preset callback address to the user terminal. The target token is sent to the IoT server according to the callback address, so that the IoT server sends an acquisition request to the authentication server, the acquisition request including the target token; the authentication server authenticates the target token and the first application identifier, generates a first authentication result, and if the first authentication result indicates that the target token and the first application identifier meet the authentication rules, it obtains the identifier of the user terminal and sends the identifier of the user terminal to the IoT server; the IoT server sends the login information associated with the identifier of the user terminal to the user terminal; Log in to the IoT server based on the login information.
2. The method according to claim 1, characterized in that, After responding to the redirection command and sending the first application identifier to the authentication server according to the redirection path, the method further includes: Based on the authorization confirmation information, the user-input authorization confirmation request is sent to the authentication server, so that the authentication server responds to the authorization confirmation request and generates a target token. The authorization confirmation information is the information sent by the authentication server to the user terminal when the second authentication result indicates that the first application identifier code and the preset second application identifier code are consistent. The authorization confirmation information is used to prompt the user whether to confirm the authorization. The second authentication result is the result obtained by the authentication server authenticating the first application identifier code based on the second application identifier code.
3. The method according to claim 1, characterized in that, Before sending a login request to the IoT server according to the preset IoT server application programming interface, the method further includes: Obtain the application programming interface (API), API address, and first application identifier code of the IoT server, wherein the first application identifier code is the identifier code in the authentication server corresponding to the IoT server; The application programming interface, the application programming interface address, and the first application identifier are set in the user terminal.
4. An Internet of Things (IoT) login authentication method, characterized in that, Applied to Internet of Things (IoT) servers, the method includes: The system receives a login request sent by a user terminal. The login request is a request sent by the user terminal to the Internet of Things (IoT) server according to the preset application programming interface of the IoT server. The login request is used to request the user terminal's login information. A redirection command is sent to the user terminal, causing the user terminal to respond to the redirection command and send a preset first application identifier to the authentication server according to a preset redirection path. The redirection command includes the redirection path and the first application identifier, which corresponds to the IoT server. The authentication server generates a target token and sends the target token and a preset callback address to the user terminal. The target token is associated with the user terminal. The user terminal sends the target token to the IoT server according to the callback address. Send an acquisition request to the authentication server, the acquisition request including the target token, so that the authentication server authenticates the target token and the first application identifier code, generates a first authentication result, and if the first authentication result indicates that the target token and the first application identifier code meet the authentication rules, acquire the identifier code of the user terminal, and send the identifier code of the user terminal to the IoT server. The login information associated with the identifier of the user terminal is sent to the user terminal so that the user terminal can log in to the Internet of Things server based on the login information.
5. The method according to claim 4, characterized in that, Sending the acquisition request to the authentication server includes: The authentication server sends an acquisition request, which also includes a preset application key, to enable the authentication server to authenticate the target token, the first application identifier, and the application key, and generate a first authentication result. The first authentication result is used to indicate whether the target token, the first application identifier, and the application key meet the authentication rules.
6. An Internet of Things (IoT) login authentication method, characterized in that, Applied to an authentication server, the method includes: The system receives a preset first application identifier code sent by a user terminal in response to a redirection command according to a preset redirection path. The redirection command is a command sent by the IoT server to the user terminal after receiving a login request from the user terminal. The login request is a request sent by the user terminal to the IoT server according to a preset application programming interface of the IoT server. The login request is used to request the login information of the user terminal. The redirection command includes the redirection path and the first application identifier code, and the first application identifier code corresponds to the IoT server. Generate a target token, which is associated with the user terminal; The target token and a preset callback address are sent to the user terminal, so that the user terminal sends the target token to the IoT server according to the callback address; the IoT server sends an acquisition request to the authentication server, the acquisition request including the target token; The target token and the first application identifier are authenticated to generate a first authentication result, which indicates whether the target token and the first application identifier meet the authentication rules. If the first authentication result indicates that the target token and the first application identifier code satisfy the authentication rules, the identifier code of the user terminal is obtained and sent to the IoT server, so that the IoT server sends the login information associated with the identifier code of the user terminal to the user terminal, and the user terminal logs in to the IoT server based on the login information.
7. The method according to claim 6, characterized in that, Prior to generating the target token, the method further includes: The first application identifier is authenticated according to a preset second application identifier to obtain a second authentication result. The second authentication result is used to indicate whether the first application identifier and the second application identifier are consistent. The generation of the target token includes: If the second authentication result indicates that the first application identifier and the second application identifier are consistent, a target token is generated.
8. The method according to claim 7, characterized in that, The step of generating a target token when the second authentication result indicates that the first application identifier and the second application identifier are consistent includes: If the second authentication result indicates that the first application identifier code and the second application identifier code are consistent, an authorization confirmation message is sent to the user terminal so that the user terminal sends the user's confirmation authorization request to the authentication server according to the authorization confirmation message. The authorization confirmation message is used to prompt the user whether to confirm the authorization. In response to the confirmation authorization request, a target token is generated.
9. The method according to claim 6, characterized in that, The acquisition request also includes a preset application key; The authentication of the target token and the first application identifier code generates a first authentication result, including: The target token, the first application identifier, and the application key are authenticated to generate a first authentication result. The first authentication result is used to indicate whether the target token, the first application identifier, and the application key meet the authentication rules.
10. An Internet of Things (IoT) login authentication device, characterized in that, The device, applied to a user terminal, includes: The first sending module is used to send a login request to the Internet of Things (IoT) server according to the preset application programming interface of the IoT server, so that the IoT server sends a redirection command to the user terminal. The redirection command includes a preset redirection path and a preset first application identifier code, the first application identifier code corresponding to the IoT server. The login request is used to request to obtain the login information of the user terminal. The second sending module is configured to, in response to the redirection command, send the first application identifier code to the authentication server according to the redirection path, so that the authentication server generates a target token, the target token being associated with the user terminal; the authentication server then sends the target token and a preset callback address to the user terminal. The third sending module is configured to send the target token to the IoT server according to the callback address, so that the IoT server sends an acquisition request to the authentication server, the acquisition request including the target token; the authentication server authenticates the target token and the first application identifier, generates a first authentication result, and if the first authentication result indicates that the target token and the first application identifier satisfy the authentication rules, obtains the identifier of the user terminal and sends the identifier of the user terminal to the IoT server; the IoT server sends the login information associated with the identifier of the user terminal to the user terminal; The login module is used to log in to the IoT server based on the login information.
11. An Internet of Things (IoT) login authentication device, characterized in that, The device, used in Internet of Things (IoT) servers, includes: The first receiving module is used to receive a login request sent by a user terminal. The login request is a request sent by the user terminal to the Internet of Things server according to the preset application programming interface of the Internet of Things server. The login request is used to request to obtain the login information of the user terminal. The fourth sending module is used to send a redirection command to the user terminal, so that the user terminal responds to the redirection command and sends a preset first application identifier to the authentication server according to a preset redirection path. The redirection command includes the redirection path and the first application identifier, which corresponds to the IoT server. The authentication server generates a target token and sends the target token and a preset callback address to the user terminal. The target token is associated with the user terminal. The user terminal sends the target token to the IoT server according to the callback address. The fifth sending module is used to send an acquisition request to the authentication server. The acquisition request includes the target token, so that the authentication server can authenticate the target token and the first application identifier code, generate a first authentication result, and if the first authentication result indicates that the target token and the first application identifier code meet the authentication rules, acquire the identifier code of the user terminal and send the identifier code of the user terminal to the Internet of Things server. The sixth sending module is used to send the login information associated with the identification code of the user terminal to the user terminal, so that the user terminal can log in to the Internet of Things server based on the login information.
12. An Internet of Things (IoT) login authentication device, characterized in that, The apparatus, used in an authentication server, includes: The second receiving module is used to receive a preset first application identifier code sent by a user terminal in response to a redirection command according to a preset redirection path. The redirection command is a command sent by the IoT server to the user terminal after receiving a login request from the user terminal. The login request is a request sent by the user terminal to the IoT server according to a preset application programming interface of the IoT server. The login request is used to request to obtain the login information of the user terminal. The redirection command includes the redirection path and the first application identifier code, and the first application identifier code corresponds to the IoT server. A generation module is used to generate a target token, which is associated with the user terminal; The seventh sending module is used to send the target token and a preset callback address to the user terminal, so that the user terminal sends the target token to the IoT server according to the callback address; the IoT server sends an acquisition request to the authentication server, the acquisition request including the target token; The first authentication module is used to authenticate the target token and the first application identifier code, and generate a first authentication result. The first authentication result is used to indicate whether the target token and the first application identifier code meet the authentication rules. The first acquisition module is configured to acquire the identifier code of the user terminal when the first authentication result indicates that the target token and the first application identifier code satisfy the authentication rules, and send the identifier code of the user terminal to the Internet of Things server, so that the Internet of Things server sends the login information associated with the identifier code of the user terminal to the user terminal, and the user terminal logs in to the Internet of Things server based on the login information.
13. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, it implements the IoT login authentication method as described in any one of claims 1-9.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the Internet of Things login authentication method as described in any one of claims 1-9.
15. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device performs the Internet of Things login authentication method as described in any one of claims 1-9.
Citation Information
Patent Citations
Method, apparatus and related device for single sign-on and processing method and apparatus of application
CN106209749A
Identity Authentication Method and Apparatus
US20180309756A1