IoT Device Authentication System

By introducing a distributed consensus network and load balancing mechanism into the IoT device authentication system, the problem of busy congestion during the IoT device authentication process is solved, and the authentication efficiency is significantly improved and the system stability is achieved.

CN119675894BActive Publication Date: 2025-05-16BEIJING RES CENT FOR INFORMATION TECH & AGRI +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411532877.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-30
Publication Date
2025-05-16
Estimated Expiration
2044-10-30

AI Technical Summary

Technical Problem

In the prior art, there is a problem of congestion and busyness in the authentication process of IoT devices, resulting in inefficient authentication.

Method used

A IoT device authentication system is designed to achieve rapid verification of certificates and load balancing of CA management modules by establishing a distributed consensus network between the device management center and the CA management module, synchronizing and updating the MPT tree and load balancing list.

Benefits of technology

It effectively improves the certification efficiency of IoT devices, avoids congestion during the certification process, and ensures the efficiency and stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119675894B_ABST
    Figure CN119675894B_ABST
Patent Text Reader

Abstract

The present invention provides an Internet of Things device authentication system, which belongs to the field of agricultural science and technology. The system includes: a device management center; multiple CA management modules; each CA management module is respectively connected to the device management center, each CA management module is respectively connected to multiple gateways, and each gateway is connected to multiple Internet of Things devices; the device management center and each CA management module form a distributed consensus network; the device management center is used to maintain an MPT tree and a load balancing list, and each CA management module synchronizes and updates the MPT tree and the load balancing list through a distributed consensus network; the information of each certificate of the Internet of Things device authentication system is respectively stored in the MPT tree as a leaf node; the load balancing list records the real-time load information of each CA management module. The system can improve the authentication efficiency of Internet of Things devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of agricultural science and technology, and in particular to an Internet of Things device authentication system. Background Art

[0002] With the development of agricultural technology, orchards are gradually upgrading to unmanned, intelligent and intensive operations. In order to facilitate the production management of orchards, many IoT devices are installed in the orchards, including soil temperature and humidity sensors, meteorological soil moisture stations, water and fertilizer integration, pest and disease monitoring, intelligent grading and classification robots, orchard picking robots and intelligent weighing. Real-time reading of various orchard data from IoT devices and analysis of orchard growth status and production data based on data analysis technology have become essential items for orchard production management.

[0003] In this context, in order to effectively control the production of many orchards in various places, an orchard management platform was developed. The platform builds a server cluster through big data technology and connects orchard gateways in various places to transmit data. In this process, due to the large number of orchards and the built-in collection time of most IoT devices is full-time and half-time collection, the big data cluster server and the orchard gateways and IoT devices will encounter authentication congestion and busyness. Summary of the invention

[0004] The present invention provides an Internet of Things device authentication system, which is used to solve the defect of Internet of Things device authentication being busy and congested in the prior art and improve the efficiency of Internet of Things device authentication.

[0005] The Internet of Things device authentication system provided by the present invention includes:

[0006] Equipment management center;

[0007] Multiple CA management modules; each CA management module is respectively connected to the device management center in communication, each CA management module is respectively connected to multiple gateways in communication, and each gateway is connected to multiple IoT devices in communication;

[0008] The gateway is used to manage the authentication of the IoT device, and the CA management module is used to manage the authentication of the gateway and the IoT device;

[0009] The device management center is used to send certificate management information to the CA management module, and the certificate management information is used to implement device authentication;

[0010] The device management center and each CA management module form a distributed consensus network;

[0011] The device management center is used to maintain the MPT tree and the load balancing list, and each CA management module synchronizes and updates the MPT tree and the load balancing list through the distributed consensus network;

[0012] The information of each certificate of the IoT device authentication system is stored in the MPT tree as a leaf node; the load balancing list records the real-time load information of each CA management module.

[0013] In one embodiment, the device management center is in communication connection with a target gateway; the target gateway is any one of a plurality of gateways;

[0014] The target gateway sends a first certificate request to the device management center;

[0015] The device management center verifies the first certificate request, allocates a target CA management module to the target gateway based on the load balancing list if the verification passes, and sends allocation result information to the target gateway and the target CA management module;

[0016] The target gateway sends the first certificate request to the target CA management module based on the allocation result information;

[0017] The target CA management module generates a first certificate based on the first certificate request, and sends information of the first certificate to the device management center to update the MPT tree;

[0018] After the MPT tree is updated, the device management center sends first certificate management information to the target CA management module, where the first management information is used to instruct the target CA management module to send the first certificate to the target gateway.

[0019] In one embodiment, the target IoT device sends a second certificate request to the target gateway; the target IoT device is any one of a plurality of IoT devices that are communicatively connected to the target gateway;

[0020] The target gateway generates a public-private key pair and a second certificate based on the second certificate request, and sends information of the second certificate to the device management center;

[0021] The device management center verifies the information of the second certificate, updates the MPT tree if the verification is successful, and sends second certificate management information to the target gateway, where the second certificate management information is used to instruct the target gateway to send the second certificate and public key to the target IoT device;

[0022] The target Internet of Things device establishes a secure connection with the target gateway based on the second certificate and the public key.

[0023] In one embodiment, the target IoT device establishes a secure connection with the target gateway based on the second certificate and the public key, including:

[0024] The target IoT device sends target data to the target gateway; the target data includes certificate information generated based on the second certificate and business data encrypted based on the public key;

[0025] The target gateway verifies the certificate information based on the second certificate, and if the verification passes, decrypts the service data based on the private key.

[0026] In one embodiment, the target gateway establishes a data transmission channel with the target CA management module based on the first certificate, and sends service data to the target CA management module based on the data transmission channel;

[0027] If the load of the target CA management module does not exceed the load threshold, the data node corresponding to the target CA management module receives the service data;

[0028] If the load of the target CA management module exceeds the load threshold, the target CA management module reallocates CA management modules to the target gateway based on the load balancing list, and sends CA management module adjustment information to the target gateway.

[0029] In one embodiment, the target gateway determines the adjusted CA management module based on the CA management module adjustment information, and sends a data transmission channel establishment request to the adjusted CA management module based on the first certificate;

[0030] The adjusted CA management module sends an MPT tree verification request for verifying the first certificate to the device management center;

[0031] After the MPT tree verification request is passed, the adjusted CA management module establishes a data transmission channel with the target gateway.

[0032] In one embodiment, whether the load of the target CA management module exceeds the load threshold is determined in the following manner:

[0033] If the queuing delay of the service data exceeds the delay threshold, the load of the target CA management module exceeds the load threshold.

[0034] In one embodiment, when an abnormality occurs in the verification of the target IoT device by the target gateway, the target gateway sends an error message to the device management center;

[0035] The device management center suspends the validity of the certificate information corresponding to the target gateway based on the error information.

[0036] In one embodiment, when an abnormality occurs in the target IoT device, the target gateway suspends the validity of the certificate information corresponding to the target IoT device.

[0037] In one embodiment, the device management center is further configured to adjust the number of the CA management modules according to the load of each CA management module.

[0038] The IoT device authentication system provided by the present invention distributes multiple CA management modules and enables the gateway, CA management module and device management center to form hierarchical management. Compared with the prior art, the present invention delegates the management authority to the CA management module, thereby avoiding the defect of busy authentication between the big data cluster server and the orchard gateways and IoT devices. Furthermore, by forming a distributed consensus network based on the device management center and the CA management modules, and enabling the CA management modules to synchronize and update the MPT tree and the load balancing list through the distributed consensus network, the certificate verification and the load balancing of the CA management module can be quickly realized, thereby effectively improving the authentication efficiency of the IoT devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0040] Figure 1 It is a structural diagram of the Internet of Things device authentication system provided by the present invention. DETAILED DESCRIPTION

[0041] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0042] Figure 1 Schematic diagram of the structure of the IoT device authentication system provided by the present invention. Figure 1 As shown, the present invention provides an Internet of Things device authentication system, which may include:

[0043] Device Management Center (IoT Device Authentication Management Center) 110;

[0044] Multiple CA (Certificate Authority) management modules 120; each CA management module 120 is respectively connected to the device management center 110 in communication, each CA management module 120 is respectively connected to multiple gateways 130 in communication, and each gateway 130 is respectively connected to multiple IoT devices 140 in communication;

[0045] Among them, the gateway 130 is used to manage the authentication of the IoT device 140, and the CA management module 120 is used to manage the authentication of the gateway 130 and the IoT device 140;

[0046] The device management center 110 is used to send certificate management information to the CA management module 120, and the certificate management information is used to implement device authentication;

[0047] The device management center 110 and each CA management module 120 form a distributed consensus network;

[0048] The device management center 110 is used to maintain the MPT (Merkle Patricia Tree) tree and the load balancing list, and each CA management module 120 synchronizes and updates the MPT tree and the load balancing list through a distributed consensus network;

[0049] Among them, the information of each certificate of the IoT device authentication system is stored as a leaf node in the MPT tree; the load balancing list records the real-time load information of each CA management module.

[0050] It should be noted that, in the present invention, one CA management module 120 may correspond to one data node (such as a large data node, etc.), that is, each data node may deploy one CA management module 120. The CA management module 120 may be responsible for processing the authentication of the gateway 130 and the IoT device 140 assigned to it.

[0051] Specifically, the CA management module 120 of each data node can operate independently to issue and manage the certificates of the gateway 130 and IoT device 140 to which it is assigned.

[0052] The device management center 110 can centrally manage the CA management modules 120 on all data nodes and provide a unified management interface and policy control. The device management center 110 can specifically include a gateway dynamic allocation module for dynamically allocating gateways 130 to different CA management modules 120 according to the load and resource conditions of the CA management modules 120.

[0053] Furthermore, the gateway dynamic allocation module may maintain a mapping table to record the CA management module 120 and the data node to which each gateway currently belongs.

[0054] The gateway 130 is responsible for managing the connected IoT devices 134 , and the IoT devices 134 are connected and authenticated through the gateway 130 , and obtain certificates and keys through the gateway 130 .

[0055] Furthermore, the device management center 110 can form a distributed consensus network with each CA management module 120. That is, each CA management module 120 is part of the distributed consensus network, and the data nodes corresponding to each CA management module 120 participate in the distributed consensus network, and synchronize and update the MPT tree and load balancing list by communicating with the device management center 110, thereby jointly maintaining the MPT tree and load balancing list with the device management center 110.

[0056] Among them, the MPT tree and the load balancing list can be set in the device management center 110. The MPT tree can store the information of each certificate of the IoT device authentication system, for example, the information of each certificate is used as a leaf node of the MPT tree. The load balancing list can record the real-time load information of each CA management module 120, so that the device management center 110 can allocate the CA management module 120 to the newly connected gateway 130 according to the real-time load of each CA management module 120.

[0057] It can be understood that by forming a distributed consensus network based on the device management center 110 and each CA management module 120, and allowing each CA management module 110 to synchronize and update the MPT tree and load balancing list through the distributed consensus network, certificate verification and load balancing of the CA management module 110 can be quickly achieved, thereby effectively improving authentication efficiency.

[0058] To sum up, the Internet of Things device authentication system provided by the present invention, by distributing multiple CA management modules, and forming a hierarchical management of the gateway, CA management module and device management center, compared with the prior art, the present invention delegates the management authority to the CA management module, thereby avoiding the defects of authentication congestion and busyness of the big data cluster server and each orchard gateway and Internet of Things device; further, by forming a distributed consensus network based on the device management center and each CA management module, and allowing each CA management module to synchronize and update the MPT tree and load balancing list through the distributed consensus network, the certificate verification and load balancing of the CA management module can be quickly realized, thereby effectively improving the authentication efficiency of the Internet of Things device.

[0059] In one embodiment, the device management center 110 is in communication connection with a target gateway 130 , and the target gateway 130 is any one of a plurality of gateways 130 .

[0060] The target gateway 130 sends a first certificate request to the device management center 110;

[0061] The device management center 110 verifies the first certificate request, and if the verification passes, allocates the target CA management module 110 to the target gateway 130 based on the load balancing list, and sends the allocation result information to the target gateway 130 and the target CA management module 110;

[0062] The target gateway 130 sends a first certificate request to the target CA management module 110 based on the allocation result information;

[0063] The target CA management module 110 generates a first certificate based on the first certificate request, and sends information of the first certificate to the device management center 110 to update the MPT tree;

[0064] After the MPT tree is updated, the device management center 110 sends first certificate management information to the target CA management module 120 , where the first management information is used to instruct the target CA management module 120 to send a first certificate to the target gateway 130 .

[0065] When the target gateway 130 is to be connected to the IoT device authentication system as a new gateway, the target gateway 130 may directly communicate with the device management center 110 : the target gateway 130 sends a first certificate request to the device management center 110 .

[0066] After the device management center 110 receives the first certificate request from the target gateway 130, it will first verify the first certificate request, such as verifying whether the metadata of the first certificate request is legal, such as verifying whether the target gateway 130 is produced by a cooperative manufacturer or whether metadata such as the device name is in the system whitelist. If the verification passes, the device management center 110 will allocate a target CA management module 120 to the target gateway 130 based on the real-time load information of each CA management module 120 in the load balancing list, and send the allocation result information to the target gateway 130 and the target CA management module 120.

[0067] After receiving the allocation result information, the target gateway 130 can determine the target CA management module 120 to which it needs to connect, and then the target gateway 130 will send a first certificate request to the target CA management module 120 to request the CA management module 120 to issue a certificate.

[0068] The CA management module 120 will directly generate the first certificate according to the first certificate request without verifying the target gateway 130 , thereby saving the load resources of the CA management module 120 .

[0069] After the first certificate is generated, the CA management module sends the information of the first certificate to the device management center 110, thereby updating the MPT tree (the information of the first certificate becomes a leaf node of the MPT tree).

[0070] After the MPT tree is updated, the device management center 110 sends the first certificate management information to the target CA management module 120. The first certificate management information can at least achieve the following functions:

[0071] 1. Tell the target CA management module 120 to update the root hash of the MPT tree.

[0072] It should be noted that after the target CA management module 120 updates the root hash (i.e., updates the MPT tree) through the consensus algorithm, it will also send a synchronization request to other CA management modules 120 through the consensus algorithm. Other CA management modules 120 will request the root hash from the device management center 110. If the root hash of the synchronization request is the same as the root hash of the MPT tree of the device management center 110, the other CA management modules 120 will update the root hash. If the root hash of the synchronization request is not the same as the root hash of the MPT tree of the device management center 110, it means that the operation is illegal (it means that the information of the first certificate is not synchronized to the device management center 110), and other CA management modules 120 will send illegal information to the target CA management module 120 to prompt the target CA management module 120 to reject / suspend the authorization of the target gateway 130, and the MPT tree of the device management center 110 will be rolled back.

[0073] 2. Instruct the target CA management module 120 to send the first certificate to the target gateway 130 .

[0074] After receiving the first certificate management information, the target CA management module 120 sends the first certificate to the target gateway 130 according to the certificate management information, so that the target gateway 130 completes the device authentication.

[0075] After receiving the first certificate, the target gateway 130 may store the certificate in a hardware security module (HSM) for subsequent device connection and authentication.

[0076] It can be understood that by providing the gateway 130 with an HSM module for storing data, the security of data transmission can be ensured.

[0077] In a specific example, when the data node is started, the corresponding CA management module 120 is initialized. The CA management module 120 generates its own public and private key pair and simultaneously registers with the device management center 110, thereby obtaining a CA root certificate.

[0078] When the gateway 130 is initialized, it sends a certificate request to the device management center 110 using the original definition data (ODT) (as shown in Table 1).

[0079] Table 1 Original Definition Data (ODT) table

[0080]

[0081] The device management center 110 may include a gateway dynamic allocation module, which can analyze the current real-time load of each CA management module 120 according to the load balancing list, so as to determine to which big data node (CA management module 120) the gateway 130 is allocated, and update the mapping table according to the allocation result (i.e., determining the target IoT device, target gateway, and target CA management module).

[0082] The device management center 110 verifies the certificate request and after the verification is passed, it will update the device certification list (ECL) (as shown in Table 2).

[0083] Table 2 Equipment Certification List (ECL)

[0084]

[0085] The IoT device authentication system provided by the present invention realizes the verification of the new access gateway and the allocation of the CA management module based on the MPT tree and the load balancing list jointly maintained by the device management center and the CA management module, which can effectively improve the efficiency of device authentication and ensure security.

[0086] In one embodiment, the target IoT device 140 sends a second certificate request to the target gateway 130; the target IoT device 140 may be any one of a plurality of IoT devices 140 that are communicatively connected to the target gateway 130;

[0087] The target gateway 130 generates a public-private key pair and a second certificate based on the second certificate request, and sends information of the second certificate to the device management center 110;

[0088] The device management center 110 verifies the information of the second certificate, updates the MPT tree if the verification is successful, and sends the second certificate management information to the target gateway 130; the second certificate management information is used to instruct the target gateway 130 to send the second certificate to the target IoT device 140;

[0089] The target IoT device 140 establishes a secure connection with the target gateway 130 based on the second certificate and the public key.

[0090] When the target IoT device 140 is newly connected to the target gateway 130 , the target IoT device 140 sends a second certificate request to the target gateway 130 .

[0091] After receiving the second certificate request, the target gateway 130 generates a public-private key pair and a second certificate based on the second certificate request, and sends information of the second certificate to the device management center 110 .

[0092] The device management center 110 will verify the information of the second certificate, for example, verify whether the metadata of the second certificate is legal.

[0093] If the verification is successful, the device management center 110 will update the information of the second certificate into the MPT tree and send the second certificate management information to the target gateway 130 .

[0094] The target gateway 130 sends the second certificate to the target IoT device 140 based on the second certificate management information.

[0095] The target IoT device 140 will establish a secure connection with the target gateway 130 based on the second certificate and the public key to transmit business data.

[0096] Optionally, in the case where the target gateway 130 includes an HSM, the target gateway 130 may also store the MPT tree formed by the certificates of all IoT devices 140 connected to the target gateway 130 through the HSM.

[0097] The Internet of Things device authentication system provided by the present invention can realize three-level certificate management of the device management center, the CA management module and the gateway by implementing certificate management for the Internet of Things devices through the gateway, thereby improving the security of the authentication system.

[0098] In one embodiment, the target IoT device establishes a secure connection with the target gateway based on the second certificate and the public key, which may include:

[0099] The target IoT device sends target data to the target gateway; the target data includes certificate information generated based on the second certificate and business data encrypted based on the public key;

[0100] The target gateway verifies the certificate information based on the second certificate, and if the verification passes, decrypts the business data based on the private key.

[0101] The target IoT device 140 generates certificate information based on the second certificate, encrypts the business data based on the public key in the public-private key pair, and then packages the certificate information and the encrypted business data into target data and sends them to the target gateway 130 .

[0102] After receiving the target data, the target gateway 130 will verify the certificate information based on the second certificate. Specifically, the target gateway 130 can compare the second certificate in the certificate information with the information of the second certificate stored in the MPT tree. If the two are consistent, the verification is successful; if they are inconsistent, the target gateway 130 can take processing measures, such as determining the target data as invalid data, or requesting the device management center 110 or the target CA management module 120 to suspend the certificate validity of the target IoT data.

[0103] If the verification is successful, the target gateway 130 will decrypt the business data based on the private key in the public-private key pair, and further process the decrypted business data.

[0104] The Internet of Things device authentication system provided by the present invention can ensure the security of data transmission by realizing business data transmission between the Internet of Things device and the gateway based on the second certificate and the public-private key pair.

[0105] In one embodiment, the target gateway 130 establishes a data transmission channel with the target CA management module 120 based on the first certificate, and sends business data to the target CA management module 120 based on the data transmission channel;

[0106] If the load of the target CA management module 120 does not exceed the load threshold, the data node corresponding to the target CA management module 120 receives the service data;

[0107] If the load of the target CA management module 120 exceeds the load threshold, the target CA management module 120 reallocates the CA management module 120 to the target gateway 130 based on the load balancing list, and sends CA management module adjustment information to the target gateway 130 .

[0108] After the target gateway 130 decrypts the business data based on the private key in the public-private key pair to obtain the decrypted business data, it will establish a data transmission channel with the target CA management module 120 based on the first certificate:

[0109] The target gateway 130 sends a transmission channel establishment request to the target CA management module 120 based on the first certificate; after receiving the request, the target CA management module 120 will match the first certificate information sent by the target gateway 130 with the first certificate information stored in the MPT tree. If the two are consistent, the target CA management module 120 accepts the request and establishes a data transmission channel with the target gateway 130.

[0110] The target gateway 130 may use the transmission channel to send service data to the target CA management module 120 .

[0111] At this time, the target CA management module 120 will evaluate whether the load of the target CA management module 120 exceeds the load threshold after receiving the service data. Specifically, whether the load of the target CA management module 120 exceeds the load threshold can be determined in the following manner:

[0112] If the queuing delay of the service data exceeds the delay threshold, the target CA management module 120 determines that the load exceeds the load threshold.

[0113] Among them, the queuing delay refers to the queuing delay for the target gateway 130 to send data to the target CA management module 120; the size of the delay threshold can be, for example, 0.2s, 1s, 2s, etc., and its specific size can be adjusted according to actual needs, and the present invention does not make specific limitations.

[0114] If the load of the target CA management module 120 does not exceed the load threshold, the data node corresponding to the target CA management module 120 receives the service data.

[0115] The load threshold may be, for example, 70%, 90%, 95%, etc., and its specific value may be adjusted according to actual conditions, and the present invention does not make any specific limitation thereto.

[0116] If the load of the target CA management module 120 exceeds the load threshold, the target CA management module 120 will reallocate CA management modules 120 to the target gateway 130 based on the load balancing list, i.e., select CA management modules 120 with sufficient load from each CA management module 120 and reallocate them to the target gateway 130.

[0117] It is understandable that the CA management module 120 exists inside the distributed data node. The CA management module 120 is equivalent to a "gateway", and each data node will have a CA management module 120. When the data nodes are distributed, the CA management modules 120 are also distributed (i.e., they can communicate with each other). This application can implement the consensus mechanism of the CA management module 120 by establishing a distributed consensus network and a load balancing list, so that the load balancing tables maintained by all CA management modules 120 are strongly identical to ensure the immutability and security of the load balancing list.

[0118] After the CA management module 120 is reallocated, the target CA management module 120 sends CA management module adjustment information to the target gateway 130 .

[0119] The Internet of Things device authentication system provided by the present invention can realize dynamic adjustment of the CA management module by determining the received business data or reallocating the CA management module to the gateway according to the real-time load of the CA management module, thereby ensuring that each CA management module can operate under a suitable load and effectively avoiding the phenomenon of authentication congestion.

[0120] In one embodiment, the target gateway 130 determines the adjusted CA management module 120 based on the CA management module adjustment information, and sends a data transmission channel establishment request to the adjusted CA management module 120 based on the first certificate;

[0121] The adjusted CA management module 120 sends an MPT tree verification request for verifying the first certificate to the device management center 110;

[0122] After the MPT tree verification request is passed, the adjusted CA management module 120 establishes a data transmission channel with the target gateway 130 .

[0123] Specifically, after receiving the CA management module adjustment information, the target gateway 130 determines the adjusted CA management module 120 based on the information, and sends a data transmission channel establishment request to the adjusted CA management module 120 based on the first certificate.

[0124] The adjusted CA management module 120 will parse the first certificate information from the request, and send an MPT tree verification request for verifying the first certificate to the device management center 110 based on the first certificate information.

[0125] After the device management center 110 determines the information of the first certificate through the verification request, it matches the information of the first certificate with the information of the first certificate stored in the MPT tree.

[0126] If the two are consistent, the device management center 110 will approve the request and instruct the adjusted CA management module 120 to establish a data transmission channel with the target gateway 130 .

[0127] If the two are inconsistent, the device management center 110 will instruct the adjusted CA management module to take further actions, such as ignoring the data transmission channel establishment request, or invalidating the first certificate.

[0128] The Internet of Things device authentication system provided by the present invention can simplify the authentication process and improve the operating efficiency of the system by directly performing MPT tree verification on the certificate when allocating a CA management center to a gateway center without the need to verify metadata again.

[0129] In one embodiment, when an abnormality occurs in the verification of the target IoT device 140 by the target gateway 130, the target gateway 130 sends an error message to the device management center 110;

[0130] The device management center 110 suspends the validity of the certificate information corresponding to the target gateway 130 in the MPT tree based on the error information.

[0131] When the target IoT device 140 fails or becomes abnormal, or the target gateway 130 itself fails or becomes abnormal, resulting in an abnormality in the verification of the target IoT device 140 by the target gateway 130, the target gateway 130 may send an error message to the device management center 110 to inform the device management center 110 that the verification function of the target gateway 130 cannot be performed normally.

[0132] After receiving the error information, the device management center 110 will suspend the validity of the certificate information corresponding to the target gateway 130 in the MPT tree based on the information.

[0133] The certificate information corresponding to the target gateway 130 may include only the first certificate information of the target gateway 130 , or may also include the second certificate information of the target IoT device 140 connected to the target gateway 130 .

[0134] Optionally, when an exception occurs in the verification of the target IoT device 140 by the target gateway 130, the target gateway 130 may also send an error message to the target CA management module 120, so that the target CA management module 120 suspends the validity of the certificate information corresponding to the target gateway 130 in the MPT tree.

[0135] The networked device authentication system provided by the present invention can avoid further escalation of faults and security risks by suspending the validity of the certificate information corresponding to the target gateway in the MPT tree when an abnormality occurs in the verification of the target Internet of Things device by the target gateway, thereby ensuring the normal operation and security of the authentication system.

[0136] In one embodiment, when an abnormality occurs in the target IoT device 140 , the target gateway 130 suspends the validity of the certificate information corresponding to the target IoT device 140 .

[0137] In the event of an abnormality in the target IoT device 140, such as an abnormality in sending a verification request to the target gateway 130, or an abnormality in the function of the target IoT device 140 itself resulting in the target IoT device 140 being unable to send a second certificate request to the target gateway 130 within a certain period of time after registration, the target gateway 130 will suspend the validity of the certificate information corresponding to the target IoT device, that is, shut down the authentication authority of the target IoT device 140 and record a detailed error log (exception type, timestamp, detailed information, etc.).

[0138] The certain time length may be 1 minute, 5 minutes, etc., and its specific length may be adjusted according to actual conditions, and the present invention does not make any specific limitation thereto.

[0139] The target gateway 130 may further generate exception information (including error logs) and send it to the target CA management module 120; the target CA management module 120 then updates the exception record table.

[0140] The target CA management module 120 can summarize the exception information from each gateway 130 (the summary data includes device ID, exception type, detection time, log details and node source, etc.), analyze the exception data, execute corresponding security policies, such as alarm notification, device isolation or recovery operations, etc., and send the summarized exception information to the device management center 110.

[0141] The device management center 110 generates a detailed error report and sends a notification to the relevant client or system administrator, including the device ID, abnormality type, timestamp, and log details.

[0142] The networked device authentication system provided by the present invention can avoid further escalation of faults and security risks by suspending the validity of certificate information corresponding to the target IoT device when an abnormality occurs in the target IoT device, thereby ensuring the normal operation and security of the authentication system.

[0143] In one embodiment, the device management center 110 is further configured to adjust the number of CA management modules according to the load of each CA management module 120 .

[0144] For example, when the device management center 110 determines that the load of each CA management module 120 exceeds the load threshold, the device management center 110 can set a new data node, open a new CA management module 120 for the newly set data node, and adjust the gateway 130 of other CA management modules 120 to the new CA management module 120.

[0145] When the device management center 110 determines that the load of each CA management module 120 is not saturated, for example, the average load of each CA management module is significantly smaller than the load threshold, for example, the average load is 40% and the load threshold is 80%, then the device management center 110 can cancel some existing data nodes, that is, reduce the number of CA management modules 120, and adjust the gateway of the cut CA management module 120 to other existing CA management modules 120.

[0146] In summary, in the IoT device authentication system provided by the present invention, the device management center can uniformly manage and coordinate all distributed CA management modules (and support horizontal expansion), and disperse the authentication tasks of the gateway to multiple CA management modules. Each CA management module is responsible for the authentication of gateways and IoT devices in a specific area. At the same time, the authentication architecture adopts a gateway dynamic allocation mechanism to optimize the data transmission load. With the help of the distributed collaboration principle, the device management center dynamically allocates the gateway to other CA management modules with lower loads, and at the same time, waives the authentication step and directly transmits while ensuring safety, ensuring the efficiency and stability of the system. In addition, as a secondary authentication agency, the gateway assumes the authentication management and some exception handling functions of IoT devices in its area, further reducing the pressure on the data center.

[0147] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.

[0148] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0149] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An Internet of Things device authentication system, characterized in that: include: Equipment management center; Multiple CA management modules; Each CA management module is respectively connected to the device management center for communication, each CA management module is respectively connected to multiple gateways for communication, and each gateway is connected to multiple IoT devices for communication; The gateway is used to manage the authentication of the IoT device, and the CA management module is used to manage the authentication of the gateway and the IoT device; The device management center is used to send certificate management information to the CA management module, and the certificate management information is used to implement device authentication; the device management center and each CA management module form a distributed consensus network; The device management center is used to maintain the MPT tree and the load balancing list, and each CA management module synchronizes and updates the MPT tree and the load balancing list through the distributed consensus network; The information of each certificate of the IoT device authentication system is stored in the MPT tree as a leaf node; the load balancing list records the real-time load information of each CA management module.

2. The IoT device authentication system according to claim 1, characterized in that: The device management center is in communication connection with a target gateway; the target gateway is any one of a plurality of gateways; The target gateway sends a first certificate request to the device management center; The device management center verifies the first certificate request, allocates a target CA management module to the target gateway based on the load balancing list if the verification passes, and sends allocation result information to the target gateway and the target CA management module; The target gateway sends the first certificate request to the target CA management module based on the allocation result information; The target CA management module generates a first certificate based on the first certificate request, and sends information of the first certificate to the device management center to update the MPT tree; After the MPT tree is updated, the device management center sends first certificate management information to the target CA management module, where the first certificate management information is used to instruct the target CA management module to send the first certificate to the target gateway.

3. The IoT device authentication system according to claim 2, characterized in that: The target IoT device sends a second certificate request to the target gateway; the target IoT device is any one of a plurality of IoT devices that are communicatively connected to the target gateway; The target gateway generates a public-private key pair and a second certificate based on the second certificate request, and sends information of the second certificate to the device management center; The device management center verifies the information of the second certificate, updates the MPT tree if the verification is successful, and sends second certificate management information to the target gateway, where the second certificate management information is used to instruct the target gateway to send the second certificate and public key to the target IoT device; The target Internet of Things device establishes a secure connection with the target gateway based on the second certificate and the public key.

4. The IoT device authentication system according to claim 3, characterized in that: The target IoT device establishes a secure connection with the target gateway based on the second certificate and the public key, including: The target IoT device sends target data to the target gateway; the target data includes certificate information generated based on the second certificate and business data encrypted based on the public key; The target gateway verifies the certificate information based on the second certificate, and if the verification passes, decrypts the service data based on the private key.

5. The IoT device authentication system according to claim 4, characterized in that: The target gateway establishes a data transmission channel with the target CA management module based on the first certificate, and sends business data to the target CA management module based on the data transmission channel; If the load of the target CA management module does not exceed the load threshold, the data node corresponding to the target CA management module receives the service data; If the load of the target CA management module exceeds the load threshold, the target CA management module reallocates CA management modules to the target gateway based on the load balancing list, and sends CA management module adjustment information to the target gateway.

6. The IoT device authentication system according to claim 5, characterized in that: The target gateway determines the adjusted CA management module based on the CA management module adjustment information, and sends a data transmission channel establishment request to the adjusted CA management module based on the first certificate; The adjusted CA management module sends an MPT tree verification request for verifying the first certificate to the device management center; After the MPT tree verification request is passed, the adjusted CA management module establishes a data transmission channel with the target gateway.

7. The IoT device authentication system according to claim 5, characterized in that: Whether the load of the target CA management module exceeds the load threshold is determined in the following manner: If the queuing delay of the service data exceeds the delay threshold, the load of the target CA management module exceeds the load threshold.

8. The IoT device authentication system according to claim 3, characterized in that: In the case where an abnormality occurs in the verification of the target IoT device by the target gateway, the target gateway sends an error message to the device management center; The device management center suspends the validity of the certificate information corresponding to the target gateway based on the error information.

9. The IoT device authentication system according to claim 3, characterized in that: In the event that an abnormality occurs to the target IoT device, the target gateway suspends the validity of the certificate information corresponding to the target IoT device.

10. The IoT device authentication system according to any one of claims 1 to 9, characterized in that: The device management center is also used to adjust the number of the CA management modules according to the load of each CA management module.

Citation Information

Patent Citations

  • Multilevel management system of intelligent power terminals based on load balancing and authentication method thereof

    CN105577757A

  • Secure communication system and method

    CN116545671A