Authentication method and device, communication equipment and storage medium

By generating and sending the first authentication information separately at least two second devices, the problem of the existing device authentication process dependence on authoritative institutions and low authentication efficiency is solved, and a safer and more convenient device authentication is achieved.

CN119945757APending Publication Date: 2025-05-06CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510040612.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-09
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing equipment authentication process relies too much on authoritative certification agencies, resulting in certificate issuance errors when authoritative institutions fail, affecting device authentication and encrypted transmission. Existing distributed technologies cannot select devices for authentication for authentication direction, and non-first authentication still requires traditional authentication methods, resulting in cumbersome and inefficient authentication.

Method used

The first information for identifying the first device transmitted by the first device is received by at least two second devices, and each generates the first authentication information and sends it to the third device to complete the authentication of the first device. This method adopts information dispersed transmission processing, improves the security of authentication information, and completes authentication through collaborative coordination between different functional devices, breaking away from the dependence on authoritative certification agencies.

Benefits of technology

It improves the security of equipment certification information, enhances the security of the certification process, simplifies the non-first certification process, makes it more convenient and fast, and gets rid of the dependence on authoritative certification agencies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945757A_ABST
    Figure CN119945757A_ABST
Patent Text Reader

Abstract

The invention discloses an authentication method. The method comprises the following steps: a second device receives first information sent by a first device and used for identifying the first device, and generates first authentication information based on the first information; wherein at least two pieces of second equipment respectively receive the first information, and the at least two pieces of second equipment respectively generate first authentication information; and the second device sends the first authentication information to a third device, so that the third device obtains second authentication information of the first device based on the first authentication information, and authenticates the first device based on the second authentication information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computers, and in particular to an authentication method, device, communication equipment and storage medium. Background Art

[0002] The existing device authentication process is too dependent on authoritative certification bodies, that is, all digital certificates are generated by authoritative bodies. If the authoritative bodies fail, it will lead to certificate issuance errors, making device authentication impossible, which will have a serious impact on encrypted transmission.

[0003] At present, in order to solve the above problems, distributed technology is often used to replace authoritative organizations to implement device verification and alleviate the computing pressure of a single device. However, the existing distributed technology requires all devices to participate in the device authentication operation with equal probability, and it is impossible to select devices related to the authenticated device to participate in the authentication according to the authentication direction. Moreover, for non-first authentication of stable devices, it is still necessary to repeatedly use traditional authentication methods (such as biometric authentication or dynamic verification code authentication, etc.) to authenticate the device, making the authentication process cumbersome and the authentication efficiency too low. Summary of the invention

[0004] In order to solve the existing technical problems, the embodiments of the present invention provide an authentication method, an apparatus, a communication device and a storage medium.

[0005] To achieve the above object, the technical solution of the embodiment of the present invention is implemented as follows:

[0006] In a first aspect, an embodiment of the present invention provides an authentication method, the method comprising: a second device receives first information sent by a first device for identifying the first device, and generates first authentication information based on the first information; wherein at least two second devices respectively receive the first information, and the at least two second devices respectively generate the first authentication information;

[0007] The second device sends the first authentication information to a third device, so that the third device obtains second authentication information of the first device based on the first authentication information, and authenticates the first device based on the second authentication information.

[0008] In the above scheme, generating the first authentication information based on the first information includes: the second device generates the first authentication information based on part of the first information; wherein at least two second devices generate the first authentication information based on different parts of the first information respectively.

[0009] In the above scheme, the generating of the first authentication information based on the first information includes: the second device generating the first authentication information based on the first information and a pre-stored first key value; wherein, the first key value corresponds to the first device, and the first key values ​​stored in the at least two second devices are the same or different.

[0010] In the above scheme, the method also includes: the second device receives the second information sent by the third device, the second information indicating that the first device has passed the authentication; updating the first key value, generating fourth authentication information based on the first information and the updated first key value, and sending the fourth authentication information to the fourth device for storage by the fourth device.

[0011] In a second aspect, an embodiment of the present invention provides an authentication method, the method comprising: a third device respectively receives first authentication information sent by at least two second devices, and combines at least two of the first authentication information to generate second authentication information; the first authentication information is generated by each second device based on first information used to identify the first device;

[0012] The third device obtains third authentication information of the first device from the fourth device, where the third authentication information is authentication information stored by the fourth device after the first device completed authentication last time;

[0013] The third device compares the second authentication information with the third authentication information, and when the comparison is consistent, determines that the first device authentication is successful.

[0014] In the above solution, the method further includes: the third device sends second information to each second device, and the second information indicates that the first device is authenticated.

[0015] In a third aspect, an embodiment of the present invention provides an authentication method, comprising: a fourth device sends third authentication information of a first device to a third device, the third authentication information being authentication information stored by the fourth device after the last authentication of the first device was completed, and the third authentication information is used by the third device to authenticate the first device.

[0016] In the above scheme, the method also includes: the fourth device receives fourth authentication information sent by at least two second devices respectively, and the fourth authentication information is generated by each second device based on an updated first key value and the first information used to identify the first device; the fourth device generates fifth authentication information based on at least two fourth authentication information, and the fifth authentication information is used for the next authentication process of the first device.

[0017] In a fourth aspect, an embodiment of the present invention provides an authentication method, the method comprising: a second device receives first information sent by a first device for identifying the first device, generates first authentication information based on the first information, and sends the first authentication information to a third device; wherein two second devices respectively receive the first information, and the two second devices respectively generate the first authentication information;

[0018] The third device receives the first authentication information sent by the two second devices respectively, and combines the two first authentication information to generate second authentication information;

[0019] The third device obtains the third authentication information of the first device from the fourth device, compares the second authentication information and the third authentication information, and determines that the first device is authenticated if the comparison is consistent; the third authentication information is the authentication information stored by the fourth device after the first device was last authenticated.

[0020] In a fifth aspect, an embodiment of the present invention further provides an authentication device, which is applied to a second device and includes: a first communication unit and a first processing unit; wherein:

[0021] The first communication unit is configured to receive first information sent by a first device and used to identify the first device; wherein the first communication units of the two second devices receive the first information respectively;

[0022] The first processing unit is configured to generate first authentication information based on the first information; wherein the first processing units of the two second devices respectively generate first authentication information based on the first information;

[0023] The first communication unit is further configured to send the first authentication information to a third device, so that the third device obtains second authentication information of the first device based on the first authentication information, and authenticates the first device based on the second authentication information.

[0024] In a sixth aspect, an embodiment of the present invention further provides an authentication device, which is applied to a third device, and includes: a second communication unit and a second processing unit; wherein,

[0025] The second communication unit is used to receive first authentication information sent by at least two second devices respectively; the first authentication information is generated by each second device based on the first information used to identify the first device;

[0026] The second processing unit is used to combine at least two of the first authentication information to generate second authentication information;

[0027] The second communication unit is further used to obtain third authentication information of the first device from a fourth device, where the third authentication information is authentication information stored by the fourth device after the first device completed authentication last time;

[0028] The second processing unit is further configured to compare the second authentication information with the third authentication information, and determine that the first device authentication is successful when the comparison shows that the second authentication information is consistent with the third authentication information.

[0029] In the seventh aspect, an embodiment of the present invention also provides an authentication device, which is applied to a fourth device, and the device includes a third communication unit, which is used to send third authentication information of a first device to the third device, and the third authentication information is the authentication information stored after the last authentication of the first device is completed, and the third authentication information is used by the third device to authenticate the first device.

[0030] In the eighth aspect, an embodiment of the present invention further provides a communication device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the method applied to the second device, the third device, or the fourth device described in the embodiment of the present invention are implemented.

[0031] In the ninth aspect, an embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method applied to the second device or the third device or the fourth device described in the embodiment of the present invention.

[0032] In the tenth aspect, an embodiment of the present invention further provides a computer program product, including a computer program, which, when executed by a processor, implements the method applied to the second device or the third device or the fourth device described in the embodiment of the present invention.

[0033] An authentication method, device, communication device and storage medium provided by an embodiment of the present invention respectively receive the first information for identifying the first device sent by the first device through at least two second devices participating in this authentication, and each sends the first authentication information generated based on the first information to the third device, so that the third device can obtain the second authentication information for authenticating the first device based on the first authentication information, and complete the authentication of the first device based on the second authentication information. On the one hand, by adopting the method of information decentralized transmission and processing, each second device participating in this authentication can only obtain the first information corresponding to each device, and cannot obtain the complete device information of the first device, thereby improving the security of transmitting the device information of the device to be authenticated; on the other hand, the first device cannot directly communicate with the third device used for authentication, but needs to initiate authentication to the third device through the second device, thereby improving the security of the authentication process; on the third hand, by completing the authentication process of the first device through the mutual cooperation between different functional devices such as the second device and the third device, it is possible to get rid of the dependence on the authoritative authentication agency, and for devices that are not authenticated for the first time, authentication without biometric information verification or dynamic verification code can be realized, making the authentication process more convenient and fast. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 A schematic diagram of a system architecture for an authentication method according to an embodiment of the present invention;

[0035] Figure 2 The following is a flow chart of the authentication method according to an embodiment of the present invention. Figure 1 ;

[0036] Figure 3 The following is a flow chart of the authentication method according to an embodiment of the present invention. Figure 2 ;

[0037] Figure 4 The following is a flow chart of the authentication method according to an embodiment of the present invention. Figure 3 ;

[0038] Figure 5 The interactive process diagram of the authentication method according to the embodiment of the present invention is as follows Figure 1 ;

[0039] Figure 6 The interactive process diagram of the authentication method according to the embodiment of the present invention is as follows Figure 2 ;

[0040] Figure 7 Schematic diagram of the composition structure of the authentication device provided in the embodiment of the present invention Figure 1 ;

[0041] Figure 8 Schematic diagram of the composition structure of the authentication device provided in the embodiment of the present invention Figure 2 ;

[0042] Fig. 9 Schematic diagram of the composition structure of the authentication device provided in the embodiment of the present invention Figure 3 ;

[0043] Fig.10 A schematic diagram of the hardware structure of a communication device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0044] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0045] It should be understood that the terms "system" and "network" are often used interchangeably in this article. The term "and / or" in this article is only a description of the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.

[0046] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and need not be used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable in appropriate circumstances, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein, for example. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, the process, method, system, product or equipment comprising a series of steps or units need not be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or equipment.

[0047] Figure 1 Schematic diagram of the system architecture of the authentication method of the embodiment of the present invention; Figure 1 As shown, the system architecture of the authentication method application of the embodiment of the present invention includes a first device, a second device, a third device and a fourth device.

[0048] Among them, the first device is a device to be authenticated for a non-first time (login), and for the first device to be authenticated for the first time, it is still necessary to complete the first login through traditional authentication methods (such as fingerprint recognition or verification code recognition); the second device is a device that matches the first device and is used to generate authentication information, that is, a device for encrypting the first information that identifies the first device; the third device is a device for authenticating the first device; the fourth device is a device for storing authentication information and authentication time.

[0049] In this embodiment, the first device can communicate with at least two second devices and a fourth device respectively in the corresponding steps of the authentication process; at least two second devices can communicate with the first device, the third device and the fourth device respectively in the corresponding steps of the authentication process; the third device can communicate with at least two devices and the fourth device respectively in the corresponding steps of the authentication process; the fourth device can communicate with the first device, at least two second devices and the third device respectively in the corresponding steps of the authentication process, thereby realizing device authentication through interaction between the above-mentioned devices.

[0050] It should be noted that after completing the first authentication, the first device can determine the second device and the fourth device that match it to improve the efficiency of re-authentication. However, in order to avoid direct communication between the first device to be authenticated and the third device used for authentication, the third device is not matched with the first device to ensure the security of the authentication process.

[0051] It should be noted that the first device, the second device, the third device and the fourth device can all be virtual servers in the cloud platform, and the above devices can all be devices in the same region after the virtual servers are divided according to the Internet Protocol (IP) address based on the network segment through the iptables service under the Linux firewall framework netfilter. By dividing the devices based on the network segment, the devices that authenticate the first device are all devices in the same region, reducing the possibility of intrusion by external unknown devices or devices outside the region, and greatly improving the security of the authentication process.

[0052] In other words, the first device, the second device, the third device and the fourth device, as devices participating in the authentication, are all devices in the same network segment or adjacent network segments based on the network segment division. The network segment can be not only a conventional network segment, but also other network segments set according to different requirements. Device division based on the above network segments can ensure that the above devices participating in the authentication are all devices in the same area and in a stable state, and during the authentication process of the first device, the above devices are always in the same area to maintain interaction between devices. The stable device can be a device that meets the preset authentication or login time limit.

[0053] It should be noted that, among the devices participating in the authentication in the same area, the second device (group), the third device (group) and the fourth device (group) with corresponding functions can be determined according to the capabilities of the devices in the same area. The embodiment of the present invention does not limit the method of selecting devices corresponding to different numbers from the device group for each device authentication, for example, it can be determined by random sampling. For example, a device with storage and computing capabilities can be determined as the second device for generating authentication information; a device with storage capabilities can be determined as the fourth device for storing authentication information.

[0054] based on Figure 1 The architecture design of the embodiment of the present invention shown in FIG. Figure 2 The following is a flow chart of the authentication method according to an embodiment of the present invention. Figure 1 ;like Figure 2 As shown, the method includes:

[0055] Step 101: A second device receives first information sent by a first device for identifying the first device, and generates first authentication information based on the first information; wherein at least two second devices receive the first information respectively, and the at least two second devices generate first authentication information respectively;

[0056] Step 102: The second device sends the first authentication information to a third device, so that the third device obtains second authentication information of the first device based on the first authentication information, and authenticates the first device based on the second authentication information.

[0057] In this embodiment, when a first device initiates a non-first authentication, the second device needs to receive the first information sent by the first device for identifying the first device, and generate first authentication information for authenticating the first device based on the first information. The embodiment of the present invention limits the number of second devices participating in the authentication each time to at least two, that is, the at least two second devices receive the first information respectively, and each generates the first authentication information.

[0058] It should be noted that, in the embodiment of the present invention, the second device that can participate in the authentication based on the network segment division can be a second device group. Since each second device in the second device group has the same function, the embodiment of the present invention does not limit the method of selecting at least two second devices from the second device group for each device authentication. For example, it can be determined by random selection, and the number of second devices matched with the first device this time can be set according to the complexity of the authentication environment. In other words, the number of second devices participating in this authentication is proportional to the complexity of this authentication environment.

[0059] In some implementations, generating the first authentication information based on the first information includes: the second device generating the first authentication information based on a portion of the first information; wherein at least two second devices generate the first authentication information based on different portions of the first information, respectively.

[0060] In this embodiment, at least two second devices participating in this authentication respectively generate corresponding first authentication information based on the contents of different parts of the first information. In other words, the first device can split all or part of the first information according to the number of second devices participating in the authentication, and send the first information of different parts after splitting to the corresponding second devices (groups), so that at least two second devices can respectively generate the same number of first authentication information as the second devices based on the received parts of the first information.

[0061] It can be understood that the first device sends the partial first information split based on the number of second devices participating in this authentication to the corresponding second devices respectively, so that the second device can only receive the corresponding partial first information but cannot obtain the complete first information, thereby avoiding the occurrence of security issues such as information leakage, and thus improving the security of the authentication process.

[0062] It should be noted that the embodiment of the present invention does not specifically limit the content of the first information, and can identify the first device to achieve subsequent authentication. For example, the first information may include information such as the brand and / or model of the first device.

[0063] For example, taking the example that the above-mentioned first information includes the brand and model of the first device, when it is determined that the second devices participating in the authentication are the second device A and the second device B, the first device can split the first information into two parts, that is, send the brand of the first device to the second device A, and send the model of the first device to the second device B, so that the two second devices can respectively generate the first authentication information based on the received part of the first information.

[0064] In some embodiments, generating the first authentication information based on the first information includes: the second device generates the first authentication information based on the first information and a pre-stored first key value; wherein the first key value corresponds to the first device, and the first key values ​​stored in the at least two second devices are the same or different.

[0065] In this embodiment, at least two second devices participating in this authentication can each generate corresponding first authentication information based on the received part of the first information and the pre-stored first key value. The first key value is pre-generated and stored by the corresponding second device for the first device. For different second devices, their corresponding first key values ​​may be the same or different.

[0066] It should be noted that the present application does not specifically limit the method for the second device to generate the first authentication information based on the corresponding first information and the first key value. For example, the Message-Digest Algorithm 5 (MD5) algorithm can be used to combine the pre-stored first key value with the first information to obtain the first authentication information.

[0067] In this embodiment, after generating corresponding first authentication information based on the received first information and the pre-stored first key value, at least two second devices participating in this authentication respectively send the first authentication information to a third device, so that the third device can obtain the second authentication information of the first device based on the first authentication information, and authenticate the first device based on the second authentication information.

[0068] It can be understood that the second authentication information is complete authentication information used to authenticate the first device, and the second authentication information is composed of the first authentication information generated by the third device based on the second devices participating in the authentication.

[0069] It should be noted that, in the embodiment of the present invention, the third device that can participate in the authentication based on the network segment division can be a third device group. In the embodiment of the present invention, for each device authentication, the method of selecting a third device from the third device group is not limited, for example, it can be determined by random drawing.

[0070] In some embodiments, the method also includes: the second device receives second information sent by the third device, the second information indicating that the first device has passed authentication; updating the first key value, generating fourth authentication information based on the first information and the updated first key value, and sending the fourth authentication information to the fourth device for storage by the fourth device.

[0071] In this embodiment, after sending the generated first authentication information to the third device, all the second devices participating in this authentication can respectively receive the second information sent by the third device indicating that the first device has passed the authentication.

[0072] Furthermore, after determining that the authentication of the first device has passed, all second devices participating in this authentication need to respectively update the first key value used to generate the first authentication information this time, and regenerate the fourth authentication information based on the received first information and the updated first key value, and send the generated fourth authentication information to the fourth device for the fourth device to store the fourth authentication information.

[0073] It should be noted that, in the embodiment of the present invention, after the authentication is completed, the way in which the second device generates the fourth authentication information based on the first information and the updated first key value is the same as the way in which the second device generates the first authentication information in this authentication, and will not be elaborated here.

[0074] It should be noted that all or part of the first information sent by the first device to the second device participating in the authentication when initiating the authentication, and all or part of the first information sent to the second device after the authentication is passed for generating the fourth authentication information can be fixed or random.

[0075] That is to say, after completing the first authentication, the first device can store the corresponding first information that needs to be sent to each second device participating in the authentication, and send the stored corresponding first information to each second device participating in the authentication during each authentication, so that each second device can only receive the corresponding part of the first information, thereby ensuring the security of transmitting the first information.

[0076] It should be noted that the first key value generated by the second device before and / or after the update can only be stored in the second device and cannot be transmitted to the first device and the third device, thereby ensuring the security of the authentication information.

[0077] In some embodiments, the second device, the third device, and the fourth device participating in this authentication all have corresponding backup devices (or replacement machines, redundant machines), and the backup devices have the same functions as the corresponding original devices to avoid problems such as authentication failure due to some devices being offline.

[0078] In this embodiment, during the authentication of the first device, some devices participating in the authentication may be offline due to power outages, shutdowns, failures, etc. Therefore, it is necessary to set a certain number of backup devices for the devices participating in the authentication. When the original devices are offline, they can directly replace the original devices to participate in the device authentication, so as to avoid problems such as authentication failures caused by some devices being offline, thereby greatly improving the robustness and stability of the authentication equipment.

[0079] It should be noted that the embodiment of the present invention requires that the number of backup devices corresponding to the at least two second devices, the third device, and the fourth device participating in the authentication is at least two, and the number of backup devices corresponding to different devices can be set according to the complexity of the authentication environment. For example, after the second device (group), the third device (group), and the fourth device (group) with corresponding functions are determined in the devices in the same area, except for the at least two second devices, one third device, and one fourth device selected to participate in this authentication, the remaining devices with the same function can all serve as corresponding backup devices.

[0080] Figure 3 The following is a flow chart of the authentication method according to an embodiment of the present invention. Figure 2 ;like Figure 3 As shown, the method includes:

[0081] Step 201: The third device receives first authentication information sent by at least two second devices respectively, and combines at least two of the first authentication information to generate second authentication information; the first authentication information is generated by each second device based on the first information used to identify the first device;

[0082] Step 202: the third device obtains third authentication information of the first device from the fourth device, where the third authentication information is authentication information stored by the fourth device after the first device completed authentication last time;

[0083] Step 203: The third device compares the second authentication information with the third authentication information, and if the comparison is consistent, determines that the first device authentication is successful.

[0084] In this embodiment, when a first device initiates non-first authentication, the third device receives first authentication information respectively sent by at least two second devices participating in this authentication, and combines the at least two received first authentication information to generate second authentication information for authenticating the first device.

[0085] Among them, the first authentication information is generated by each of the at least two second devices participating in this authentication based on the first information used to identify the first device. The specific generation process has been described in detail on the second device side above and will not be repeated here.

[0086] It can be understood that the second authentication information is complete authentication information used to authenticate the first device, and the second authentication information is composed of the first authentication information respectively generated by the second devices participating in the authentication.

[0087] It should be noted that in order to ensure the security of the authentication process, the third device is not matched with the first device. Therefore, the third device that receives each first authentication information can be a third device (group) divided into the same area, that is, all third devices in the same area can receive the first authentication information sent by each second device participating in this authentication, and then each third device generates the second authentication information based on the combination of all the received first authentication information. Finally, a third device for performing this authentication can be determined in the third machine (group) by random selection, thereby completing this authentication.

[0088] In this embodiment, after the third device generates the second authentication information based on the first authentication information sent by the second device, it needs to obtain the third authentication information of the first device from the fourth device for storing authentication information, so as to realize the authentication of the first device based on the second authentication information and the third authentication information.

[0089] The third authentication information is the authentication information that is pre-stored to the fourth device by the second device after the last successful authentication of the first device. In other words, the third authentication information is the complete authentication information composed of the newly generated fourth authentication information sent by the fourth device based on the second device after the last successful authentication of the first device.

[0090] In this embodiment, the third device implements the authentication of the first device based on the second authentication information and the third authentication information by comparing the second authentication information with the third authentication information, and determining that the authentication of the first device is successful when the two authentication information are consistent.

[0091] In some implementations, the method further includes: the third device sending second information to each second device, where the second information indicates that the first device has passed authentication.

[0092] In this embodiment, after the third device determines that the first device has passed the authentication based on the second authentication information and the third authentication information, it sends the second information indicating that the first device has passed the authentication to each second device participating in this authentication, so that each second device can generate fourth authentication information for forming the third authentication information.

[0093] It should be noted that the manner in which the second device generates the fourth authentication information in the embodiment of the present invention is the same as the manner in which the second device generates the first authentication information in this authentication, and has been described in detail above, so no further details will be given here.

[0094] In some embodiments, the second device, the third device, and the fourth device participating in this authentication all have corresponding backup devices (or replacement machines, redundant machines), and the backup devices have the same functions as the corresponding original devices to avoid problems such as authentication failure due to some devices being offline.

[0095] In this embodiment, during the authentication of the first device, some devices participating in the authentication may be offline due to power outages, shutdowns, failures, etc. Therefore, it is necessary to set a certain number of backup devices for the devices participating in the authentication. When the original devices are offline, they can directly replace the original devices to participate in the device authentication, so as to avoid problems such as authentication failures caused by some devices being offline, thereby greatly improving the robustness and stability of the authentication equipment.

[0096] It should be noted that the embodiment of the present invention requires that the number of backup devices corresponding to the at least two second devices, the third device, and the fourth device participating in the authentication is at least two, and the number of backup devices corresponding to different devices can be set according to the complexity of the authentication environment. For example, after the second device (group), the third device (group), and the fourth device (group) with corresponding functions are determined in the devices in the same area, except for the at least two second devices, one third device, and one fourth device selected to participate in this authentication, the remaining devices with the same function can all serve as corresponding backup devices.

[0097] Figure 4 The following is a flow chart of the authentication method according to an embodiment of the present invention. Figure 3 ;like Figure 4 As shown, the method includes:

[0098] Step 301: The fourth device sends the third authentication information of the first device to the third device. The third authentication information is the authentication information stored by the fourth device after the first device completed the last authentication. The third authentication information is used by the third device to authenticate the first device.

[0099] Here, the fourth device is a device that matches the first device in the current first device authentication and is used to store authentication information and authentication time; the third device is a device used to authenticate the first device; the first device is a device to be authenticated for a non-first time (login), and for the first device being authenticated for the first time, it is still necessary to complete the first login through traditional authentication methods (such as fingerprint recognition or verification code recognition).

[0100] In this embodiment, after the first device initiates non-first authentication, the fourth device sends third authentication information for authenticating the first device to the third device. Specifically, the third authentication information is authentication information pre-stored by the fourth device after the first device completes the last authentication.

[0101] In some embodiments, the method also includes: the fourth device receives fourth authentication information sent by at least two second devices respectively, and the fourth authentication information is generated by each second device based on an updated first key value and the first information used to identify the first device; the fourth device generates fifth authentication information based on at least two fourth authentication information, and the fifth authentication information is used for the next authentication process of the first device.

[0102] In this embodiment, after completing the authentication of the first device, fourth authentication information sent by at least two second devices participating in the authentication can be received, and the fourth authentication information is generated by each second device based on the updated first key value and the first information used to identify the first device.

[0103] Furthermore, after receiving the corresponding at least two fourth authentication information sent by at least two second devices participating in this authentication, the fourth device combines the at least two fourth authentication information to generate fifth authentication information for the next authentication process of the first device.

[0104] It can be understood that the fifth authentication information is similar to the second authentication information, both of which are complete authentication information used to authenticate the first device. The fifth authentication information is composed of the fourth authentication information generated by the second device participating in the authentication after completing the authentication of the first device.

[0105] It should be noted that after the authentication of the first device is passed, the fourth device can not only store the fifth authentication information composed of the fourth authentication information received from the second device, but also record and store the authentication time when this authentication is completed, so that the fourth device can determine whether to allow the next authentication process to be executed before starting the next authentication.

[0106] In some embodiments, the method also includes: the fourth device receives first time information sent by the first device, the first time information indicating the last authentication time of the first device; the fourth device compares the first time information with the pre-stored second time information, and after the comparison is consistent, determines that the first device allows the authentication process to be executed; the second time information indicates the last authentication time of the first device.

[0107] In this embodiment, after the first device initiates this authentication, the fourth device needs to receive the first time information sent by the first device indicating the last authentication time of the first device, and compare the first time information with the last authentication time of the first device pre-stored by the fourth device. When it is determined that the first time information is consistent with the second time information, it means that the authentication initiated by the first device this time is the authentication time after the last authentication was completed, and the current authentication process is allowed to start.

[0108] It can be understood that the fourth device, as a device for storing authentication information and authentication time, can not only store historical authentication information (such as the third authentication information) and authentication time (such as the second time information) used to complete authentication, but also store authentication information (such as the fifth authentication information) and authentication time for the next authentication.

[0109] In some embodiments, the second device, the third device, and the fourth device participating in this authentication all have corresponding backup devices (or replacement machines, redundant machines), and the backup devices have the same functions as the corresponding original devices to avoid problems such as authentication failure due to some devices being offline.

[0110] In this embodiment, during the authentication of the first device, some devices participating in the authentication may be offline due to power outages, shutdowns, failures, etc. Therefore, it is necessary to set a certain number of backup devices for the devices participating in the authentication. When the original devices are offline, they can directly replace the original devices to participate in the device authentication, so as to avoid problems such as authentication failures caused by some devices being offline, thereby greatly improving the robustness and stability of the authentication equipment.

[0111] It should be noted that the embodiment of the present invention requires that the number of backup devices corresponding to the at least two second devices, the third device, and the fourth device participating in the authentication is at least two, and the number of backup devices corresponding to different devices can be set according to the complexity of the authentication environment. For example, after the second device (group), the third device (group), and the fourth device (group) with corresponding functions are determined in the devices in the same area, except for the at least two second devices, one third device, and one fourth device selected to participate in this authentication, the remaining devices with the same function can all serve as corresponding backup devices.

[0112] As an example, based on Figure 1 The relationship between the devices involved in authentication is shown. Figure 5 The interactive process diagram of the authentication method according to the embodiment of the present invention is as follows Figure 1 ;like Figure 5 As shown, after the first device, the second device, the third device and the fourth device participating in the authentication in the same area are divided based on the network segment, taking the number of the second devices participating in the authentication as two as an example, the specific process of implementing the authentication of the first device based on the two second devices, the third device and the fourth device is as follows:

[0113] Step 401: A second device receives first information sent by a first device and used to identify the first device.

[0114] Specifically, the two second devices participating in this authentication respectively receive part of the first information correspondingly sent by the first device and used to identify the first device.

[0115] Step 402: The second device generates first authentication information based on the first information.

[0116] Specifically, the two second devices participating in this authentication each combine the received first information with a pre-stored first key value to generate first authentication information.

[0117] Step 403: The second device sends the first authentication information generated based on the first information to the third device.

[0118] Specifically, the two second devices participating in this authentication respectively send the first authentication information generated based on the first key to the third device.

[0119] Step 404: The third device receives the first authentication information sent by two second devices respectively, and combines the two first authentication information to generate second authentication information.

[0120] Specifically, the third device respectively receives the first authentication information sent by each second device participating in this authentication, and combines the first authentication information to generate the second authentication information used for this authentication.

[0121] Step 405: The fourth device sends the third authentication information of the first device to the third device.

[0122] Specifically, after starting the authentication of the first device this time, the fourth device needs to send the third authentication information pre-stored by the fourth device after the last authentication of the first device is completed to the third device.

[0123] In addition, before executing step 405, the fourth device needs to first obtain the first authentication time when the first device completed the last authentication, and compare the first authentication time with the second authentication time when the first device completed the last authentication stored in the fourth device. After the comparison is passed, the current authentication process is allowed to be executed.

[0124] Step 406: The third device obtains the third authentication information of the first device from the fourth device, compares the second authentication information with the third authentication information, and determines that the first device is authenticated if the comparison is consistent.

[0125] Specifically, after obtaining the third authentication information sent by the fourth device, the third device compares the third authentication information with the second authentication information generated based on the first authentication information, and if the comparison passes, it is determined that the authentication of the first device is passed.

[0126] As another example, based on the above Figure 5 The steps shown, Figure 6 The interactive process diagram of the authentication method according to the embodiment of the present invention is as follows Figure 2 ;like Figure 6 As shown, after completing the authentication of the first device, the specific process based on the second device, the third device and the fourth device is as follows:

[0127] Step 407: The third device sends second information to each second device, where the second information indicates that the first device has passed authentication.

[0128] Specifically, after completing the authentication of the first device, the third device sends the second information indicating that the authentication of the first device is passed to each second device participating in the authentication.

[0129] Step 408: After receiving the second information sent by the third device, the second device updates the first key value, and generates fourth authentication information based on the first information and the updated first key value.

[0130] Specifically, after each second device participating in this authentication receives the second information sent by the third device indicating that the first device has completed the authentication, it updates the first key value used to generate the authentication information, and re-combines the acquired part of the first information of the first device with the updated first key value to generate the fourth authentication information.

[0131] In addition, before step 408, after the current authentication is completed, the first device needs to resend the corresponding first information to the two second devices participating in the current authentication respectively, so that the second devices can regenerate the fourth authentication information for the next authentication.

[0132] Step 409: The second device sends the fourth authentication information to the fourth device for storage by the fourth device.

[0133] Specifically, after generating the fourth authentication information, each second device participating in this authentication sends the fourth authentication information generated by each device to the fourth device for pre-storage for use in the next authentication process.

[0134] Step 410: The fourth device receives the fourth authentication information sent by the two second devices respectively, and generates fifth authentication information based on the two fourth authentication information, and the fifth authentication information is used for the next authentication process of the first device.

[0135] Specifically, the fourth device respectively receives the fourth authentication information generated and sent by each second device participating in this authentication based on the first information and the updated first key value, combines all the fourth authentication information, generates the fifth authentication information for the next authentication process, and stores the fifth authentication information while storing the authentication time when this authentication is completed, for use in authentication time comparison before the next authentication process.

[0136] It should be noted that the above example is described using the example that the number of second devices participating in this authentication is two. In the embodiment of the present invention, the number of second devices participating in the authentication may be more than two, and its implementation method is the same as the above example, which will not be elaborated here.

[0137] In this embodiment, at least two second devices participating in this authentication respectively receive the first information for identifying the first device sent by the first device, and each sends the first authentication information generated based on the first information to the third device, so that the third device can obtain the second authentication information for authenticating the first device based on the first authentication information, and complete the authentication of the first device based on the second authentication information. On the one hand, by adopting the method of information decentralized transmission and processing, each second device participating in this authentication can only obtain the first information corresponding to each device, and cannot obtain the complete device information of the first device, thereby improving the security of transmitting the device information of the device to be authenticated; on the other hand, the first device cannot directly communicate with the third device used for authentication, but needs to initiate authentication to the third device through the second device, thereby improving the security of the authentication process; on the third hand, by completing the authentication process of the first device through the mutual cooperation between the second device and the third device and other different functional devices, it is possible to get rid of the dependence on the authoritative authentication agency, and for devices that are not authenticated for the first time, authentication without biometric information verification or dynamic verification code can be realized, making the authentication process more convenient and fast.

[0138] Based on the above embodiment, an embodiment of the present invention further provides an authentication device, which is applied to a second device; Figure 7 Schematic diagram of the composition structure of the authentication device provided in the embodiment of the present invention Figure 1 ;like Figure 7 As shown, the device includes: a first communication unit 51 and a first processing unit 52; wherein,

[0139] The first communication unit 51 is used to receive first information sent by a first device for identifying the first device; wherein the first communication units 51 of the two second devices receive the first information respectively;

[0140] The first processing unit 52 is used to generate first authentication information based on the first information; wherein the first processing units 52 of the two second devices respectively generate first authentication information based on the first information;

[0141] The first communication unit 51 is further configured to send the first authentication information to a third device, so that the third device obtains second authentication information of the first device based on the first authentication information, and authenticates the first device based on the second authentication information.

[0142] In an optional embodiment of the present invention, the first processing unit 52 is used to generate first authentication information based on part of the first information; wherein the first processing units 52 of at least two second devices respectively generate first authentication information based on different parts of the first information.

[0143] In an optional embodiment of the present invention, the first processing unit 52 is used to generate first authentication information based on the first information and a pre-stored first key value; wherein the first key value corresponds to the first device, and the first key values ​​stored in the at least two second devices are the same or different.

[0144] In an optional embodiment of the present invention, the first communication unit 51 is further configured to receive second information sent by the third device, where the second information indicates that the first device has been authenticated;

[0145] The first processing unit 52 is further configured to update the first key value and generate fourth authentication information based on the first information and the updated first key value;

[0146] The first communication unit 51 is further configured to send the fourth authentication information to a fourth device for storage by the fourth device.

[0147] In the implementation of the present invention, the first processing unit 52 in the device can be implemented by a central processing unit (CPU), a digital signal processor (DSP), a microcontroller unit (MCU) or a programmable gate array (FPGA) in the second device in actual applications; the first communication unit 51 in the device can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna in actual applications.

[0148] Based on the above embodiment, an embodiment of the present invention further provides an authentication apparatus, which is applied to a third device. Figure 8 Schematic diagram of the composition structure of the authentication device provided in the embodiment of the present invention Figure 2 ;like Figure 8 As shown, the device includes: a second communication unit 61 and a second processing unit 62; wherein,

[0149] The second communication unit 61 is used to receive first authentication information sent by two second devices respectively; the first authentication information is generated by each second device based on the first information used to identify the first device;

[0150] The second processing unit 62 is used to combine at least two of the first authentication information to generate second authentication information;

[0151] The second communication unit 61 is further configured to obtain third authentication information of the first device from a fourth device, where the third authentication information is authentication information stored by the fourth device after the first device completed authentication last time;

[0152] The second processing unit 62 is further configured to compare the second authentication information with the third authentication information, and determine that the first device authentication is successful when the comparison shows that the second authentication information is consistent with the third authentication information.

[0153] In an optional embodiment of the present invention, the second communication unit 61 is further configured to send second information to each second device, where the second information indicates that the first device has passed authentication.

[0154] In the implementation of the present invention, the second processing unit 62 in the device can be implemented by the CPU, DSP, MCU or FPGA in the third device in actual applications; the second communication unit 61 in the device can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna in actual applications.

[0155] Based on the above embodiment, an embodiment of the present invention further provides an authentication apparatus, which is applied to a fourth device. Fig. 9 Schematic diagram of the composition structure of the authentication device provided in the embodiment of the present invention Figure 3 ;like Fig. 9 As shown, the device includes a third communication unit 71, which is used to send third authentication information of the first device to a third device. The third authentication information is the authentication information stored after the first device was last authenticated. The third authentication information is used by the third device to authenticate the first device.

[0156] In an optional embodiment of the present invention, the third communication unit 71 is further used to respectively receive fourth authentication information sent by at least two second devices, where the fourth authentication information is generated by each second device based on the updated first key value and the first information used to identify the first device;

[0157] The apparatus further comprises a third processing unit 72, configured to generate fifth authentication information based on at least two fourth authentication information, wherein the fifth authentication information is used for a next authentication process of the first device.

[0158] In the implementation of the present invention, the third processing unit 72 in the device can be implemented by the CPU, DSP, MCU or FPGA in the fourth device in actual applications; the third communication unit 71 in the device can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna in actual applications.

[0159] It should be noted that: when the above-mentioned authentication device performs device authentication, only the division of the above-mentioned program modules is used as an example. In actual applications, the above-mentioned processing can be assigned to different program modules as needed, that is, the internal structure of the device is divided into different program modules to complete all or part of the above-mentioned processing. In addition, the authentication device and the authentication method embodiment provided in the above embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.

[0160] The embodiment of the present invention further provides a communication device, Fig.10 A schematic diagram of the hardware structure of the communication provided by the embodiment of the present invention is shown in FIG. Fig.10 As shown, the communication device includes a memory 82 , a processor 81 , and a computer program stored in the memory 82 and executable on the processor 81 .

[0161] Optionally, the communication device may specifically be the second device, the third device, or the fourth device of the embodiment of the present invention; when the processor 81 executes the program, the steps of the authentication method applied to the second device, the third device, or the fourth device of the embodiment of the present invention are implemented.

[0162] Optionally, the communication device further includes at least one communication component 84. The various components in the communication device can be coupled together via a bus system 83. It is understood that the bus system 83 is used to achieve connection and communication between these components. In addition to the data bus, the bus system 83 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Fig.10 Various buses are labeled as bus system 83.

[0163] It can be understood that the memory 82 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disk, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and direct RAM bus random access memory (DRRAM, Direct Rambus Random Access Memory).The memory 82 described in the embodiments of the present invention is intended to include, but is not limited to, these and any other suitable types of memory.

[0164] The method disclosed in the above embodiment of the present invention can be applied to the processor 81, or implemented by the processor 81. The processor 81 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit in the processor 81 or the instruction in the form of software. The above processor 81 can be a general-purpose processor, a DSP, or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The processor 81 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiment of the present invention. The general-purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiment of the present invention, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in the memory 82. The processor 81 reads the information in the memory 82 and completes the steps of the above method in combination with its hardware.

[0165] In an exemplary embodiment, the communication device may be implemented by one or more application specific integrated circuits (ASIC), DSP, programmable logic device (PLD), complex programmable logic device (CPLD), FPGA, general purpose processor, controller, MCU, microprocessor, or other electronic components to execute the aforementioned method.

[0166] An embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored.

[0167] Optionally, the computer-readable storage medium can be applied to the authentication device of the embodiment of the present invention; when the program is executed by the processor, the steps of the authentication method of the embodiment of the present invention applied to the second device or the third device or the fourth device are implemented.

[0168] The embodiment of the present invention further provides a computer program product, including a computer program, and the computer program can be executed by the processor 81 of the communication device to complete the steps of the authentication method described in the embodiment of the present invention.

[0169] The methods disclosed in several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.

[0170] The features disclosed in several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.

[0171] The features disclosed in several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments or device embodiments.

[0172] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.

[0173] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0174] In addition, all functional units in the embodiments of the present invention may be integrated into one processing unit, or each unit may be separately used as a unit, or two or more units may be integrated into one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.

[0175] A person skilled in the art can understand that: all or part of the steps of implementing the above method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above method embodiment; and the aforementioned storage medium includes: mobile storage devices, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), disks or optical disks, etc. Various media that can store program codes.

[0176] Alternatively, if the above-mentioned integrated unit of the present invention is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present invention can be essentially or partly reflected in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, magnetic disks or optical disks.

[0177] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present invention, which should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.

Claims

1. An authentication method, characterized in that: The method comprises: The second device receives the first information sent by the first device for identifying the first device, and generates first authentication information based on the first information; wherein at least two second devices receive the first information respectively, and the at least two second devices generate the first authentication information respectively; The second device sends the first authentication information to a third device, so that the third device obtains second authentication information of the first device based on the first authentication information, and authenticates the first device based on the second authentication information.

2. The method according to claim 1, characterized in that The generating first authentication information based on the first information includes: The second device generates first authentication information based on a portion of the first information; wherein at least two second devices generate first authentication information based on different portions of the first information, respectively.

3. The method according to claim 1 or 2, characterized in that: The generating first authentication information based on the first information includes: The second device generates first authentication information based on the first information and a pre-stored first key value; wherein the first key value corresponds to the first device, and the first key values ​​stored in the at least two second devices are the same or different.

4. The method according to claim 3, characterized in that The method further comprises: The second device receives second information sent by the third device, where the second information indicates that the first device is authenticated; The first key value is updated, fourth authentication information is generated based on the first information and the updated first key value, and the fourth authentication information is sent to a fourth device for storage by the fourth device.

5. An authentication method, characterized in that: The method comprises: The third device receives first authentication information sent by at least two second devices respectively, and combines at least two of the first authentication information to generate second authentication information; the first authentication information is generated by each second device based on the first information used to identify the first device; The third device obtains third authentication information of the first device from the fourth device, where the third authentication information is authentication information stored by the fourth device after the first device completed authentication last time; The third device compares the second authentication information with the third authentication information, and when the comparison is consistent, determines that the first device authentication is successful.

6. The method according to claim 5, characterized in that The method further comprises: The third device sends second information to each second device, where the second information indicates that the first device has passed authentication.

7. An authentication method, characterized in that: The method comprises: The fourth device sends third authentication information of the first device to the third device, where the third authentication information is authentication information stored by the fourth device after the first device completed authentication last time, and the third authentication information is used by the third device to authenticate the first device.

8. The method according to claim 7, characterized in that The method further comprises: The fourth device receives fourth authentication information sent by at least two second devices respectively, where the fourth authentication information is generated by each second device based on the updated first key value and the first information used to identify the first device; The fourth device generates fifth authentication information based on at least two fourth authentication information, and the fifth authentication information is used for the next authentication process of the first device.

9. An authentication method, characterized in that: The method comprises: The second device receives the first information sent by the first device for identifying the first device, generates first authentication information based on the first information, and sends the first authentication information to a third device; wherein at least two second devices receive the first information respectively, and the at least two second devices generate first authentication information respectively; The third device receives the first authentication information sent by the at least two second devices respectively, and combines at least two of the first authentication information to generate second authentication information; The third device obtains the third authentication information of the first device from the fourth device, compares the second authentication information and the third authentication information, and determines that the first device is authenticated if the comparison is consistent; the third authentication information is the authentication information stored by the fourth device after the first device was last authenticated.

10. An authentication device, characterized in that: The device is applied to a second device, and comprises: a first communication unit and a first processing unit; wherein, The first communication unit is configured to receive first information sent by a first device and used to identify the first device; wherein the first communication units of the two second devices receive the first information respectively; The first processing unit is configured to generate first authentication information based on the first information; wherein the first processing units of the two second devices respectively generate first authentication information based on the first information; The first communication unit is further configured to send the first authentication information to a third device, so that the third device obtains second authentication information of the first device based on the first authentication information, and authenticates the first device based on the second authentication information.

11. An authentication device, characterized in that: The device is applied to a third device, and comprises: a second communication unit and a second processing unit; wherein, The second communication unit is used to receive first authentication information sent by at least two second devices respectively; the first authentication information is generated by each second device based on the first information used to identify the first device; The second processing unit is used to combine at least two of the first authentication information to generate second authentication information; The second communication unit is further used to obtain third authentication information of the first device from a fourth device, where the third authentication information is authentication information stored by the fourth device after the first device completed authentication last time; The second processing unit is further configured to compare the second authentication information with the third authentication information, and determine that the first device authentication is successful when the comparison shows that the second authentication information is consistent with the third authentication information.

12. An authentication device, characterized in that: The device is applied to a fourth device, and includes a third communication unit, which is used to send third authentication information of the first device to the third device, wherein the third authentication information is authentication information stored after the last authentication of the first device is completed, and the third authentication information is used by the third device to authenticate the first device.

13. A communication device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of the method according to any one of claims 1 to 4 are implemented, or; When the processor executes the program, the steps of the method according to claim 5 or 6 are implemented, or; When the processor executes the program, the steps of the method according to claim 7 or 8 are implemented.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method according to any one of claims 1 to 4 are implemented, or; When the program is executed by a processor, the steps of the method according to claim 5 or 6 are implemented, or; When the program is executed by a processor, the steps of the method according to claim 7 or 8 are implemented.

15. A computer program product comprising a computer program, characterized in that The computer program implements the method according to any one of claims 1 to 4 when executed by a processor, or; The computer program implements the method according to claim 5 or 6 when executed by a processor, or; The computer program implements the method according to claim 7 or 8 when executed by a processor.