Authentication method and device of Internet of Things equipment and related equipment
The authentication needs are initiated through business application devices, reducing signaling interactions of passive IoT devices and encrypting their identity information, solving the problem of poor security for passive IoT devices and achieving higher security and privacy protection.
Patent Information
- Application Number
- CN202510470346.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-04-15
AI Technical Summary
Passive IoT devices have problems with identity forgery and privacy leakage in the air interface, resulting in poor security of device access.
The authentication requirement is initiated through business application devices, reduce the signaling transmission and authentication steps of passive IoT devices, and encrypt the identity information after the passive IoT device completes identity authentication and protects it.
It improves the security of access to passive IoT devices, reduces signaling interaction between the two parties involved in communication, avoids privacy leakage, and meets the limitations of the device's own power and computing resources.
Smart Images

Figure CN120018134A_ABST
Abstract
Description
Background Art
[0002] Passive IoT communicates by collecting energy such as light, heat, mechanical vibration, and electromagnetic waves from the environment. It is suitable for low-cost, low-maintenance IoT devices. The fifth generation mobile communication technology (5G) passive IoT service is a cellular IoT communication system. Devices use the collected energy to generate radio frequency signals for two-way information transmission, but their functions are limited and only require small and infrequent data transmission.
[0003] The 3rd Generation Partnership Project (3GPP) standard is conducting research on the Ambient Internet of Things (AIoT), defining terminals and exploring various networking topologies to achieve "100 billion IoTs". TR 23.700-13 (a technical report focusing on 5G system architecture enhancements to support a wide range of vertical and horizontal industry applications) explicitly mentions the authentication and certification of AIoT devices; TS 22.369 (a technical specification focused on supporting the service needs of vertical industries, which defines the specific requirements of different vertical industries for communication networks and provides corresponding functional enhancement recommendations and solutions) defines privacy-related requirements: 5G systems should be able to provide a mechanism to protect the privacy of information exchanged during communication between AIoT devices and 5G networks / terminals supporting the passive Internet of Things, such as location and identity.
[0004] In the related technology, in the air interface, attackers can impersonate devices and report false identities to the network side. Attackers can take advantage of this and steal AIoT devices by replacing them with fake devices, which may cause losses to the owners of the devices. At the same time, the identifiers of AIoT devices are used to identify the devices. If the identifiers associated with the devices are not privacy protected, attackers can identify and track AIoT devices based on the identifiers.
[0005] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention
[0006] The present disclosure provides an authentication method, device and related equipment for an Internet of Things device, which at least to a certain extent overcomes the problem of poor network access security of the Internet of Things device in the related art.
[0007] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by the practice of the present disclosure.
[0008] According to one aspect of the present disclosure, there is provided an authentication method for an Internet of Things device, which is applied to a passive Internet of Things device, and includes: receiving an authentication service request forwarded by an authentication network element, wherein the authentication service request includes encrypted identity information of the Internet of Things device that meets the business requirements of a connected business application device, and the authentication network element is used to forward the authentication service request sent by the business application device; decrypting the identity information of the Internet of Things device to verify whether the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device; if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, generating a first authentication message according to a pre-set first key and the encrypted identity information of the Internet of Things device that meets the business requirements of the business application device, and forwarding the first authentication message to the authentication network element, and the authentication network element authenticates the identity information of the passive Internet of Things device according to the first authentication message, and sends the authentication result to the business application device to be accessed.
[0009] In some exemplary embodiments of the present disclosure, based on the aforementioned scheme, the IoT device identity information is decrypted to verify whether the IoT device identity information is equivalent to the identity information of the passive IoT device, including: obtaining a first random number and a second random number sent by the authentication network element; obtaining a pre-set first key; generating a first verification code based on the first key and the first random number; decrypting the IoT device identity information through the first verification code to verify whether the IoT device identity information is equivalent to the identity information of the passive IoT device.
[0010] In some exemplary embodiments of the present disclosure, based on the aforementioned scheme, if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, a first authentication message is generated according to a pre-set first key and the encrypted identity information of the Internet of Things device that meets the business requirements of the business application device, including: generating a first authentication message according to the first key, the encrypted identity information of the Internet of Things device and the second random number.
[0011] According to another aspect of the present disclosure, a method for authenticating an Internet of Things device is also provided, which is applied to an authentication network element, and includes: receiving an authentication service request sent by a business application device to be authenticated, the authentication service request including a first verification code, a pre-set first random number, and Internet of Things device identity information that meets the business requirements of the business application device; encrypting the Internet of Things device identity information based on the first verification code; forwarding the encrypted Internet of Things device identity information, the first random number, and a pre-acquired second random number to a passive Internet of Things device; receiving the authentication result sent by the passive Internet of Things device, and forwarding the identity information of the passive Internet of Things device to the business application device.
[0012] In some exemplary embodiments of the present disclosure, based on the aforementioned scheme, the authentication result includes: the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, or the identity information of the Internet of Things device is different from the identity information of the passive Internet of Things device, receiving the authentication result sent by the passive Internet of Things device, and forwarding the identity information of the passive Internet of Things device to the business application device, including: if the identity information of the Internet of Things device is different from the identity information of the passive Internet of Things device, determining that the authentication of the business application device to be accessed fails; if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, forwarding the identity information of the passive Internet of Things device to the business application device.
[0013] According to another aspect of the present disclosure, a method for authenticating an Internet of Things device is also provided, which is applied to a business application device, and includes: generating a first verification code based on a pre-set first key and a first random number; sending an authentication service request containing the first verification code to an authentication network element, and the authentication network element encrypting the Internet of Things device identity information in the authentication service request and forwarding it to a passive Internet of Things device, so that the passive Internet of Things device is authenticated; and receiving an authentication result from the passive Internet of Things device forwarded by the authentication network element.
[0014] According to another aspect of the present disclosure, an authentication device for an Internet of Things device is also provided, which is applied to a passive Internet of Things device, including: a first authentication response request receiving module, used to receive an authentication response request forwarded by an authentication network element, wherein the authentication response request includes encrypted Internet of Things device identity information that meets the business requirements of a business application device, and the authentication network element is used to forward the authentication service request sent by the business application device; a first identity information verification module, used to decrypt the Internet of Things device identity information and verify whether the Internet of Things device identity information is equivalent to the identity information of the passive Internet of Things device; a first authentication message forwarding module, used to generate a first authentication message according to a pre-set first key and the encrypted Internet of Things device identity information that meets the business requirements of the business application device if the Internet of Things device identity information is equivalent to the identity information of the passive Internet of Things device, and forward the first authentication message to the authentication network element, and the authentication network element authenticates the identity information of the passive Internet of Things device according to the first authentication message, and sends the authentication result to the business application device to be connected.
[0015] According to another aspect of the present disclosure, an authentication device for an Internet of Things device is also provided, which is applied to an authentication network element, and includes: a second authentication service request receiving module, used to receive an authentication service request sent by a business application device to be authenticated, the authentication service request including a first verification code, a pre-set first random number, and identity information of the Internet of Things device that meets the business requirements of the business application device; an identity information encryption module, used to encrypt the identity information of the Internet of Things device based on the first verification code; a second identity information verification module, used to forward the encrypted identity information of the Internet of Things device, the first random number, and the pre-acquired second random number to a passive Internet of Things device; an identity information forwarding module, used to receive the authentication result sent by the passive Internet of Things device, and forward the identity information of the passive Internet of Things device to the business application device.
[0016] According to another aspect of the present disclosure, an authentication device for an Internet of Things device is also provided, which is applied to a business application device, including: a first verification code generation module, used to generate a first verification code according to a pre-set first key and a first random number; an authentication service request forwarding module, used to send an authentication service request containing the first verification code to an authentication network element, and the authentication network element encrypts the Internet of Things device identity information in the authentication service request and forwards it to a passive Internet of Things device, so that the passive Internet of Things device is authenticated; an authentication result receiving module, used to receive the authentication result from the passive Internet of Things device forwarded by the authentication network element.
[0017] According to another aspect of the present disclosure, an electronic device is provided, including: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any one of the above-mentioned authentication methods for an Internet of Things device by executing the executable instructions.
[0018] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, any one of the above-mentioned authentication methods for an Internet of Things device is implemented.
[0019] According to another aspect of the present disclosure, a computer program product is also provided, including: a computer program or instructions, which implement any of the above-mentioned authentication methods for an Internet of Things device when executed by a processor.
[0020] An authentication method, device and related equipment for an Internet of Things device provided in the embodiments of the present disclosure, in which the authentication requirement is initiated by a business application device. Compared with the traditional authentication scheme, the embodiments of the present disclosure greatly reduce the signaling and authentication steps of the passive Internet of Things device to meet the limitations of the device's own power and computing resources; and after the passive Internet of Things device completes the identity authentication, the identity information of the passive Internet of Things device is encrypted, and the passive Internet of Things device is hidden and protected, which not only ensures the security of the passive Internet of Things device's access to the network, but also further reduces the signaling interaction between the communicating parties.
[0021] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. Obviously, the accompanying drawings described below are only some embodiments of the present disclosure, and for ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without creative work.
[0023] Figure 1 A schematic diagram showing an exemplary application system architecture of an authentication method for an Internet of Things device in an embodiment of the present disclosure; Figure 2 A schematic diagram of an authentication method for an Internet of Things device applied to a passive Internet of Things device in an embodiment of the present disclosure is shown; Figure 3 A schematic diagram of an authentication method for an Internet of Things device applied to an authentication network element in an embodiment of the present disclosure is shown; Figure 4 A schematic diagram of an authentication method for an Internet of Things device applied to a business application device in an embodiment of the present disclosure is shown; Figure 5 A schematic diagram of an interactive process of an authentication method for an Internet of Things device in an embodiment of the present disclosure is shown; Figure 6 A schematic diagram of an authentication device for an Internet of Things device applied to a passive Internet of Things device in an embodiment of the present disclosure is shown; Figure 7 A schematic diagram of an authentication device for an Internet of Things device applied to an authentication network element in an embodiment of the present disclosure is shown; Figure 8 A schematic diagram of an authentication device for an Internet of Things device applied to a business application device in an embodiment of the present disclosure is shown; Fig. 9 A schematic diagram of an electronic device using an authentication method for an Internet of Things device in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0024] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that the disclosure will be more comprehensive and complete and to fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0025] In addition, the described features, structures or characteristics may be combined in one or more embodiments in any suitable manner. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present disclosure. However, those skilled in the art will appreciate that the technical solutions of the present disclosure may be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. may be adopted. In other cases, known methods, devices, implementations or operations are not shown or described in detail to avoid blurring the various aspects of the present disclosure.
[0026] The flowcharts shown in the accompanying drawings are only exemplary and do not necessarily include all the contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps can be decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may change according to actual conditions.
[0027] Figure 1 FIG. 1 shows an exemplary application system architecture diagram to which the authentication method for an IoT device in an embodiment of the present disclosure can be applied. Figure 1 As shown, the system architecture may include passive IoT devices, a core network, and business application devices.
[0028] First of all, in response to the above-mentioned problems, an authentication method for IoT devices is provided in the embodiments of the present disclosure, which can be applied to but not limited to the IoT scenarios of hundreds of billions of IoTs in 5G / 6G networks, and a device authentication method between wide connections of the full process and all elements. Moreover, the authentication and protection scheme in the embodiments of the present disclosure can be applied to other lightweight user / device identity authentication scenarios, such as satellite-ground integration. Compared with the related technology, in the air interface, an attacker can impersonate a device and report a false identity to the network side. An attacker can take advantage of this and steal the passive IoT device by replacing the passive IoT device with a fake device, which may cause losses to the owner of the device. At the same time, the identifier of the passive IoT device is used to identify the device. If the identifier associated with the device is not privacy protected, the attacker can identify and track the passive IoT device based on the identifier. The embodiments of the present disclosure propose a method for mutual authentication between a passive IoT device and an authentication network element, and hide the identity information of the passive IoT device to ensure the security of the device access to the network and avoid privacy leakage.
[0029] Figure 2 A schematic diagram of an authentication method for an IoT device in an embodiment of the present disclosure is shown, which is applied to a passive IoT device. The method includes the following steps: S202, receiving an authentication response request forwarded by an authentication network element, wherein the authentication response request includes encrypted IoT device identity information that meets the business requirements of the business application device, and the authentication network element is used to forward the authentication service request sent by the business application device.
[0030] It should be noted that the authentication network element in the embodiment of the present disclosure refers to a component or system responsible for verifying the identity of a user or device in communication and network technology. Its main function is to ensure that the user or device connected to the network is legal and authorized, thereby maintaining network security and preventing unauthorized access. In more detail, the authentication network element in the embodiment of the present disclosure can reuse the Unified Data Management (UDM) network element in the existing 5G network or select other network elements; in addition, the authentication service request in the embodiment of the present disclosure can be a request initiated by any device that needs to be authenticated to another service entity responsible for identity authentication, and the user or device sends an authentication service request to the authentication network element, which is usually completed by submitting credentials such as a user name and password, a digital certificate, and biometric information. In more detail, in mobile communication networks, such as 5G networks, authentication service requests are a key process used to ensure that business application devices connected to the network are legal and authorized for use.
[0031] S204, decrypting the IoT device identity information, and verifying whether the IoT device identity information is equivalent to the passive IoT device identity information.
[0032] It should be noted that the IoT device identity information in the embodiments of the present disclosure refers to a series of identifiers and attributes used to uniquely identify and verify IoT devices. Common types of IoT device identity information include: device ID, MAC address, IP address, digital certificate, IMEI number, etc. In addition, the passive IoT devices in the embodiments of the present disclosure refer to IoT devices that do not require external power or battery power to operate. Such devices usually work by collecting energy from the surrounding environment, such as through radio frequency identification, light energy, thermal energy or other forms of energy collection technology. For the convenience of subsequent explanation, the embodiments of the present disclosure take the case where the device ID is the IoT device identity information as an example. Of course, the embodiments of the present disclosure do not specifically limit the IoT device identity information. Those skilled in the art can flexibly set the IoT device identity information in the embodiments of the present disclosure according to actual conditions.
[0033] S206: If the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, a first authentication message is generated based on the pre-set first key and the encrypted identity information of the Internet of Things device that meets the business requirements of the business application device, and the first authentication message is forwarded to the authentication network element. The authentication network element authenticates the identity information of the passive Internet of Things device based on the first authentication message, and sends the authentication result to the business application device to be connected.
[0034] It should be noted that the first authentication message in the embodiment of the present disclosure is generated by a key derivation function (KeyDerivation Function, KDF), and the key derivation function can have different implementation methods, such as Password-Based Key Derivation Function 2 (Password-Based Key Derivation Function 2, PBKDF2), HMAC-based Key Derivation Function (HMAC-based Key Derivation Function, HKDF), Bcrypt (an algorithm specially designed for password hashing, based on the Blowfish block cipher), where, when KDF is HMAC-SHA-256, the hash-based message authentication code (Hash-based Message Authentication Code, HMAC) is combined with SHA-256 (Secure HashAlgorithm 256-bit version) to generate the key; in addition, the embodiment of the present disclosure represents the first key by K; the IoT device identity information that meets the business requirements of the business application device after encryption is represented by AIoT ID_En; the first authentication message is represented by MAC.
[0035] The authentication method for an Internet of Things device provided in an embodiment of the present disclosure first receives an authentication response request forwarded by an authentication network element, including encrypted identity information of the Internet of Things device that meets the business requirements of a business application device; then, the identity information of the Internet of Things device is decrypted to verify whether the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device; finally, if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, a first authentication message is generated based on a pre-set first key and the encrypted identity information of the Internet of Things device for the business requirements, and the first authentication message is forwarded to the authentication network element, which authenticates the identity information of the passive Internet of Things device based on the first authentication message, and sends the authentication result to the business application device to be connected. Compared with the related art of stealing passive IoT devices by replacing them with fake devices, and the problem of poor security of passive IoT devices in accessing the network, the embodiment of the present disclosure initiates the authentication requirement by the business application device. Compared with the traditional authentication scheme, it greatly reduces the signaling and authentication steps of the passive IoT device to meet the power and computing resource limitations of the device itself; and after the passive IoT device completes the identity authentication, the identity information of the passive IoT device is encrypted, and the passive IoT device is hidden and protected, which not only ensures the security of the passive IoT device in accessing the network, but also further reduces the signaling interaction between the communicating parties to avoid privacy leakage.
[0036] In some embodiments, the disclosed embodiment decrypts the IoT device identity information and verifies whether the IoT device identity information is equivalent to the passive IoT device identity information, including: obtaining the first random number and the second random number sent by the authentication network element; obtaining the first key set in advance; generating a first verification code based on the first key and the first random number; decrypting the IoT device identity information through the first verification code to verify whether the IoT device identity information is equivalent to the passive IoT device identity information. Specifically, the first random number (RAND1) and the second random number (RAND2) in the disclosed embodiment are usually generated by the authentication network element and sent to the passive IoT device through a secure channel. These random numbers are used to increase the security of communication and prevent replay attacks. Each authentication request generates a new random number so that each interaction is unique; and the disclosed embodiment uses the shared first key and the first random number to generate the first verification code to ensure that only devices holding the correct key can pass the authentication; in addition, the disclosed embodiment encrypts and decrypts the identity information provided by the device to verify the authenticity of the device and ensure that only legitimate devices can access the network. In the entire process, sensitive information (such as keys and identity information) is transmitted and processed in an encrypted manner to avoid leakage.
[0037] In some embodiments, if the IoT device identity information is equivalent to the identity information of the passive IoT device in the embodiments of the present disclosure, a first authentication message is generated according to a pre-set first key and the encrypted IoT device identity information, including: generating the first authentication message according to the first key, the encrypted IoT device identity information and the second random number. Specifically, the first authentication message in the embodiments of the present disclosure can also be expressed as: MAC=KDF(K, AIoT ID_En, RAND2). By introducing the second random number (RAND2), each authentication request becomes unique. Even if the same device and key are used multiple times, the generated verification key will be different, thereby effectively preventing replay attacks; and the generated first authentication message can be used to further verify the integrity and authenticity of the encrypted device identity information, further enhancing the security and reliability of the entire authentication mechanism.
[0038] In some embodiments, the disclosed embodiments generate a first authentication message based on a first key, encrypted IoT device identity information, and a second random number. This makes the entire authentication process not only more secure, but also effectively prevents a variety of common attack methods (such as replay attacks and man-in-the-middle attacks). In addition, this method also provides higher flexibility and dynamism, and is suitable for various complex IoT application scenarios. It can not only ensure secure access to the device, but also protect the privacy and integrity of the device identity information.
[0039] Figure 3 A schematic diagram of an authentication method for an IoT device in an embodiment of the present disclosure is shown, which is applied to an authentication network element. The method includes the following steps: S302, receiving an authentication service request sent by a business application device to be authenticated, where the authentication service request includes a first verification code, a preset first random number, and IoT device identity information that meets business requirements of the business application device.
[0040] S304: Encrypt the IoT device identity information based on the first verification code.
[0041] S306: forward the encrypted IoT device identity information, the first random number, and the pre-acquired second random number to the passive IoT device.
[0042] S308, receiving the authentication result sent by the passive IoT device, and forwarding the identity information of the passive IoT device to the business application device.
[0043] The authentication method for an Internet of Things device provided in an embodiment of the present disclosure first receives an authentication service request sent by a business application device to be authenticated, wherein the authentication service request includes a first verification code, a pre-set first random number, and identity information of the Internet of Things device that meets the business requirements of the business application device; secondly, encrypts the identity information of the Internet of Things device based on the first verification code; then, forwards the encrypted identity information of the Internet of Things device, the first random number, and the pre-acquired second random number to a passive Internet of Things device; finally, receives an authentication result sent by the passive Internet of Things device, and forwards the identity information of the passive Internet of Things device to the business application device. Compared with the related art of stealing passive IoT devices by replacing them with fake devices, and the problem of poor security of passive IoT devices in accessing the network, the embodiment of the present disclosure initiates the authentication requirement by the business application device. Compared with the traditional authentication scheme, it greatly reduces the signaling and authentication steps of the passive IoT device to meet the power and computing resource limitations of the device itself; and after the passive IoT device completes the identity authentication, the identity information of the passive IoT device is encrypted, and the passive IoT device is hidden and protected, which not only ensures the security of the passive IoT device in accessing the network, but also further reduces the signaling interaction between the communicating parties to avoid privacy leakage.
[0044] In some embodiments, the authentication results in the embodiments of the present disclosure include: the IoT device identity information is equal to the passive IoT device identity information, or the IoT device identity information is different from the passive IoT device identity information, receiving the authentication result sent by the passive IoT device, and forwarding the passive IoT device identity information to the business application device, including: if the IoT device identity information is different from the passive IoT device identity information, then it is determined that the authentication of the business application device to be accessed has failed; if the IoT device identity information is equal to the passive IoT device identity information, then the passive IoT device identity information is forwarded to the business application device. Specifically, if the IoT device identity information does not match the expected passive IoT device identity information, then the device is denied access to the network or business applications, which can effectively prevent unauthorized devices from entering the system and avoid potential security threats; if the IoT device identity information matches the passive IoT device identity information, then the device is allowed to access the network normally, and its identity information is forwarded to the corresponding business application device, thereby ensuring that legitimate devices can smoothly perform data transmission and business operations.
[0045] Figure 4 A schematic diagram of an authentication method for an IoT device in an embodiment of the present disclosure is shown, which is applied to a business application device. The method includes the following steps: S402: Generate a first verification code according to a preset first key and a first random number.
[0046] S404: Send the authentication service request including the first verification code to the authentication network element, which encrypts the IoT device identity information in the authentication service request and forwards it to the passive IoT device, so that the passive IoT device performs authentication.
[0047] S406, receiving the authentication result from the passive IoT device forwarded by the authentication network element.
[0048] The authentication method of the Internet of Things device provided in the embodiment of the present disclosure, first, generates a first verification code according to a pre-set first key and a first random number; then, sends an authentication service request containing the first verification code to an authentication network element, and the authentication network element encrypts the Internet of Things device identity information in the authentication service request and forwards it to the passive Internet of Things device, so that the passive Internet of Things device is authenticated; finally, receives the authentication result from the passive Internet of Things device forwarded by the authentication network element. Compared with the related art of stealing passive Internet of Things devices by replacing passive Internet of Things devices with fake devices, the problem of poor network security of passive Internet of Things devices, the embodiment of the present disclosure initiates the authentication requirement by the business application device, and compared with the traditional authentication scheme, the signaling sending and authentication steps of the passive Internet of Things device are greatly reduced to meet the power and computing resource limitations of the device itself; and after the passive Internet of Things device completes the identity authentication, the identity information of the passive Internet of Things device is encrypted, and the passive Internet of Things device is hidden and protected, which not only ensures the network security of the passive Internet of Things device, but also further reduces the signaling interaction between the two communicating parties to avoid privacy leakage.
[0049] In some embodiments, Figure 5 As shown, the specific implementation process of the authentication method for the Internet of Things device in the embodiment of the present disclosure includes: S502, presetting a first key in the passive IoT device and the business application device, the business application device connects to a random number generator (such as a quantum random number generator, etc.) to generate a first random number for subsequent encryption links, and the business application device is responsible for storing and managing the identity information of the IoT device (for example: the ID of the IoT device).
[0050] S504, the business application device searches for the identity information of the IoT device that intends to establish a connection, and generates a first verification code based on the first key and the first random number, where the first verification code = KDF (first key, first random number), (KDF can be HMAC-SHA-256).
[0051] S506, the service application device forwards the authentication service request (including the first random number, the first verification code, and the identity information of the IoT device) to the authentication network element through the authentication network element.
[0052] S508, the authentication network element (which can reuse the UDM in the existing 5G network or select other units) uses the first verification code to encrypt the identity information of the IoT device, generates the encrypted identity information of the IoT device to protect the privacy and security of the device, and connects to the random number generator to generate a second random number for subsequent authentication.
[0053] S510, the authentication network element sends an authentication response request (including the first random number, the second random number, and the encrypted identity information of the IoT device) to the IoT device.
[0054] S512, the IoT device calculates a first verification code using a first key and a first random number, the first verification code = KDF (first key, first random number), and uses the first verification code to decrypt the identity information of the IoT device to verify whether it is its own ID. If correct, continue to calculate the first authentication message, otherwise the verification fails, wherein the first authentication message = KDF (first key, encrypted identity information of the IoT device, second random number).
[0055] S514, the IoT device forwards the verification result and the first authentication message to the authentication network element.
[0056] S516, the authentication network element determines the authentication result according to the first key, the encrypted identity information of the IoT device, and the second random number.
[0057] S518, if the identity information of the Internet of Things device is different from the identity information of the passive Internet of Things device, it is determined that the authentication of the service application device to be connected has failed; if they are the same, the identity information of the passive Internet of Things device is forwarded to the service application device.
[0058] In some embodiments, Figure 5 As shown, the embodiment of the present disclosure adopts a one-way, one-time lightweight identity authentication method, in which the authentication requirement is initiated by the application party. Compared with the traditional authentication scheme, the signaling and authentication steps of the passive IoT device are greatly reduced to meet the power and computing resource limitations of the device itself.
[0059] In some embodiments, the disclosed embodiments encrypt the identity information of the passive IoT device while completing identity authentication, thereby further reducing the signaling interaction between the communicating parties while completing the privacy protection function.
[0060] In more detail, the authentication network element of the embodiment of the present disclosure can be connected to a random number generator, generate random numbers in real time, and encrypt the identity information of the IoT device to achieve a one-time one-key security effect; and, designed based on the existing 5G network, the authentication network element in the embodiment of the present disclosure can reuse the UDM in the existing 5G network or select other units, and the cost of network transformation is low.
[0061] Based on the same inventive concept, the present disclosure also provides an authentication device for an IoT device, such as the following embodiment. Since the principle of solving the problem in the device embodiment is similar to that in the above method embodiment, the implementation of the device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.
[0062] Figure 6 A schematic diagram of an authentication device for an IoT device in an embodiment of the present disclosure is shown, which is applied to a passive IoT device. The device includes: The first authentication response request receiving module 601 is used to receive the authentication response request forwarded by the authentication network element, wherein the authentication response request includes the encrypted IoT device identity information that meets the business requirements of the business application device, and the authentication network element is used to forward the authentication service request sent by the business application device; The first identity information verification module 602 is used to decrypt the IoT device identity information and verify whether the IoT device identity information is equivalent to the passive IoT device identity information; The first authentication message forwarding module 603 is used to generate a first authentication message according to a pre-set first key and the encrypted identity information of the Internet of Things device if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, and forward the first authentication message to the authentication network element. The authentication network element authenticates the identity information of the passive Internet of Things device according to the first authentication message, and sends the authentication result to the business application device to be connected.
[0063] An authentication device for an Internet of Things device provided in an embodiment of the present disclosure receives, through an authentication service request acquisition module, an authentication response request forwarded by an authentication network element, including encrypted identity information of the Internet of Things device that meets the business requirements of a business application device; through an identity information verification module, decrypts the identity information of the Internet of Things device to verify whether the identity information of the Internet of Things device is equivalent to the identity information of a passive Internet of Things device; through a first authentication message forwarding module, if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, a first authentication message is generated according to a pre-set first key and the encrypted identity information of the Internet of Things device for the business requirements, and the first authentication message is forwarded to the authentication network element, which authenticates the identity information of the passive Internet of Things device according to the first authentication message, and sends the authentication result to the business application device to be connected. Compared with the related art of stealing AIoT devices by replacing them with fake devices, and the problem of poor security of AIoT devices accessing the network, the embodiment of the present disclosure initiates the authentication requirement by the business application device. Compared with the traditional authentication scheme, it greatly reduces the signaling and authentication steps of the passive IoT device to meet the power and computing resource limitations of the device itself; and, after the passive IoT device completes the identity authentication, the identity information of the passive IoT device is encrypted, and the passive IoT device is hidden and protected, which not only ensures the security of the passive IoT device accessing the network, but also further reduces the signaling interaction between the communicating parties to avoid privacy leakage.
[0064] In some embodiments, the identity information verification module in the disclosed embodiments is also used to obtain a first random number and a second random number sent by an authentication network element; obtain a pre-set first key; generate a first verification code based on the first key and the first random number; decrypt the IoT device identity information through the first verification code to verify whether the IoT device identity information is equivalent to the identity information of the passive IoT device.
[0065] In some embodiments, the first authentication message forwarding module in the embodiments of the present disclosure is also used to generate a first authentication message based on the first key, the encrypted IoT device identity information and the second random number.
[0066] Based on the same inventive concept, the present disclosure also provides an authentication device for an IoT device, such as the following embodiment. Since the principle of solving the problem in the device embodiment is similar to that in the above method embodiment, the implementation of the device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.
[0067] Figure 7 A schematic diagram of an authentication device for an IoT device in an embodiment of the present disclosure is shown, which is applied to an authentication network element. The device includes: The second authentication service request receiving module 701 is used to receive an authentication service request sent by a service application device to be authenticated, where the authentication service request includes a first verification code, a preset first random number, and IoT device identity information that meets the service requirements of the service application device; The identity information encryption module 702 is used to encrypt the IoT device identity information based on the first verification code; The second identity information verification module 703 is used to forward the encrypted IoT device identity information, the first random number, and the pre-acquired second random number to the passive IoT device; The identity information forwarding module 704 is used to receive the authentication result sent by the passive IoT device and forward the identity information of the passive IoT device to the business application device.
[0068] In some embodiments, an authentication device for an Internet of Things device in an embodiment of the present disclosure receives, through an authentication service request receiving module, an authentication service request sent by a business application device to be authenticated, the authentication service request including a first verification code, a pre-set first random number, and identity information of the Internet of Things device that meets the business requirements of the business application device; encrypts the identity information of the Internet of Things device based on the first verification code through an identity information encryption module; forwards the encrypted identity information of the Internet of Things device, the first random number, and the pre-acquired second random number to a passive Internet of Things device through an identity information verification module; receives, through an identity information forwarding module, an authentication result sent by the passive Internet of Things device, and forwards the identity information of the passive Internet of Things device to the business application device. Compared with the related art of stealing passive IoT devices by replacing them with fake devices, and the problem of poor security of passive IoT devices in accessing the network, the embodiment of the present disclosure initiates the authentication requirement by the business application device. Compared with the traditional authentication scheme, it greatly reduces the signaling and authentication steps of the passive IoT device to meet the power and computing resource limitations of the device itself; and after the passive IoT device completes the identity authentication, the identity information of the passive IoT device is encrypted, and the passive IoT device is hidden and protected, which not only ensures the security of the passive IoT device in accessing the network, but also further reduces the signaling interaction between the communicating parties to avoid privacy leakage.
[0069] In some embodiments, the authentication results in the embodiments of the present disclosure include: the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, or the identity information of the Internet of Things device is different from the identity information of the passive Internet of Things device. The identity information forwarding module in the embodiments of the present disclosure is also used to determine that the authentication of the business application device to be accessed fails if the identity information of the Internet of Things device is different from the identity information of the passive Internet of Things device; if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, the identity information of the passive Internet of Things device is forwarded to the business application device.
[0070] Based on the same inventive concept, the present disclosure also provides an authentication device for an IoT device, such as the following embodiment. Since the principle of solving the problem in the device embodiment is similar to that in the above method embodiment, the implementation of the device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.
[0071] Figure 8 A schematic diagram of an authentication device for an IoT device in an embodiment of the present disclosure is shown, which is applied to a business application device. The device includes: A first verification code generation module 801 is used to generate a first verification code according to a preset first key and a first random number; The authentication service request forwarding module 802 is used to send the authentication service request containing the first verification code to the authentication network element, and the authentication network element encrypts the IoT device identity information in the authentication service request and forwards it to the passive IoT device, so that the passive IoT device performs authentication; The authentication result receiving module 803 is used to receive the authentication result from the passive IoT device forwarded by the authentication network element.
[0072] The authentication device of the Internet of Things device provided in the embodiment of the present disclosure generates a first verification code according to a pre-set first key and a first random number through a first verification code generation module; sends the authentication service request containing the first verification code to the authentication network element through an authentication service request forwarding module, and the authentication network element encrypts the Internet of Things device identity information in the authentication service request and forwards it to the passive Internet of Things device, so that the passive Internet of Things device is authenticated; and receives the authentication result forwarded from the passive Internet of Things device by the authentication network element through an authentication result receiving module. Compared with the problem of poor network security of passive Internet of Things devices by replacing passive Internet of Things devices with fake devices in the related art, the authentication requirement is initiated by the business application device in the embodiment of the present disclosure, and compared with the traditional authentication scheme, the signaling sending and authentication steps of the passive Internet of Things device are greatly reduced to meet the power and computing resource limitations of the device itself; and after the passive Internet of Things device completes the identity authentication, the identity information of the passive Internet of Things device is encrypted, and the passive Internet of Things device is hidden and protected, which not only ensures the network security of the passive Internet of Things device, but also further reduces the signaling interaction between the two communicating parties to avoid privacy leakage.
[0073] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods or program products. Therefore, various aspects of the present disclosure may be specifically implemented in the following forms, namely: complete hardware implementation, complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software, which may be collectively referred to herein as "circuits", "modules" or "systems".
[0074] Based on the same inventive concept, an electronic device is also provided in an embodiment of the present disclosure, the electronic device comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any one of the above-mentioned authentication methods for an IoT device by executing the executable instructions. Since the principle of solving the problem in the electronic device embodiment is similar to that in the above-mentioned method embodiment, the implementation of the electronic device embodiment can refer to the implementation of the above-mentioned method embodiment, and the repeated parts will not be repeated.
[0075] Refer to the following Fig. 9 The electronic device 900 according to this embodiment of the present disclosure is described. Fig. 9 The electronic device 900 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0076] like Fig. 9 As shown, the electronic device 900 is in the form of a general computing device. The components of the electronic device 900 may include but are not limited to: at least one processing unit 901, at least one storage unit 902, and a bus 903 connecting different system components (including the storage unit 902 and the processing unit 901).
[0077] The storage unit stores program codes, which can be executed by the processing unit 901, so that the processing unit 901 executes the steps described in the above “exemplary method” section of this specification according to various exemplary embodiments of the present disclosure.
[0078] In some embodiments, when the electronic device is used to control the authentication method of the IoT device disclosed above, the processing unit 901 may perform the following steps of the above method embodiment: Receive an authentication response request forwarded by an authentication network element, wherein the authentication response request includes encrypted IoT device identity information that meets the business requirements of the business application device, and the authentication network element is used to forward the authentication service request sent by the business application device; decrypt the IoT device identity information to verify whether the IoT device identity information is equivalent to the identity information of the passive IoT device; if the IoT device identity information is equivalent to the identity information of the passive IoT device, generate a first authentication message based on a pre-set first key and the encrypted IoT device identity information, and forward the first authentication message to the authentication network element, which authenticates the identity information of the passive IoT device based on the first authentication message, and sends the authentication result to the business application device to be connected.
[0079] The storage unit 902 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 9021 and / or a cache storage unit 9022 , and may further include a read-only storage unit (ROM) 9023 .
[0080] The storage unit 902 may also include a program / utility 9024 having a set (at least one) of program modules 9025, such program modules 9025 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.
[0081] Bus 903 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.
[0082] The electronic device 900 may also communicate with one or more external devices 904 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 900, and / or communicate with any device that enables the electronic device 900 to communicate with one or more other computing devices (e.g., routers, modems, etc.). This communication may be performed through an input / output (I / O) interface 905. In addition, the electronic device 900 may also communicate with one or more networks (e.g., local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) through a network adapter 906. As shown, the network adapter 906 communicates with other modules of the electronic device 900 through a bus 903. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 900, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0083] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes a number of instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the implementation of the present disclosure.
[0084] Based on the same inventive concept, a computer-readable storage medium is also provided in the embodiment of the present disclosure, on which a computer program is stored, and when the computer program is executed by a processor, any of the above-mentioned authentication methods for IoT devices is implemented. Since the principle of solving the problem in the embodiment of the computer-readable storage medium is similar to that in the above-mentioned method embodiment, the implementation of the embodiment of the computer-readable storage medium can refer to the implementation of the above-mentioned method embodiment, and the repeated parts will not be repeated.
[0085] More specific examples of computer-readable storage media in the present disclosure may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0086] In the present disclosure, a computer readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, wherein a readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A readable signal medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0087] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the foregoing.
[0088] In specific implementation, the program code for performing the operation of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and conventional procedural programming languages such as "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., using an Internet service provider to connect through the Internet).
[0089] Based on the same inventive concept, a computer program product is also provided in the embodiments of the present disclosure, including a computer program product, including: a computer program or an instruction, which implements the authentication method of the Internet of Things device in any one of the above method embodiments when the computer program or the instruction is executed by the processor. Since the principle of solving the problem in the computer program product embodiment is similar to that in the above method embodiment, the implementation of the computer program product embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.
[0090] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into multiple modules or units to be embodied.
[0091] In addition, although the steps of the method in the present disclosure are described in a specific order in the drawings, this does not require or imply that the steps must be performed in this specific order, or that all the steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps, etc.
[0092] Through the description of the above implementation modes, it is easy for those skilled in the art to understand that the example implementation modes described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation mode of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the implementation mode of the present disclosure.
[0093] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure, which follow the general principles of the present disclosure and include common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The description and examples are intended to be exemplary only, and the true scope and spirit of the present disclosure are indicated by the appended claims.
Claims
1. A method for authenticating an Internet of Things device, characterized in that: Applied to passive IoT devices, including: Receive an authentication response request forwarded by an authentication network element, wherein the authentication response request includes encrypted IoT device identity information that meets the business requirements of the business application device, and the authentication network element is used to forward the authentication service request sent by the business application device; Decrypting the IoT device identity information to verify whether the IoT device identity information is equivalent to the identity information of the passive IoT device; If the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, a first authentication message is generated based on the pre-set first key and the encrypted identity information of the Internet of Things device, and the first authentication message is forwarded to the authentication network element. The authentication network element authenticates the identity information of the passive Internet of Things device based on the first authentication message, and sends the authentication result to the business application device to be accessed.
2. The authentication method for an Internet of Things device according to claim 1, characterized in that: Decrypting the IoT device identity information and verifying whether the IoT device identity information is equal to the identity information of the passive IoT device includes: Obtaining a first random number and a second random number sent by the authentication network element; Obtaining a preset first key; Generate a first verification code based on the first key and the first random number; The IoT device identity information is decrypted using the first verification code to verify whether the IoT device identity information is equivalent to the identity information of the passive IoT device.
3. The authentication method for an Internet of Things device according to claim 2, characterized in that: If the IoT device identity information is equal to the identity information of the passive IoT device, a first authentication message is generated according to a preset first key and the encrypted IoT device identity information, including: A first authentication message is generated according to the first key, the encrypted IoT device identity information and the second random number.
4. A method for authenticating an Internet of Things device, characterized in that: Applied to authentication network elements, including: Receive an authentication service request sent by a business application device to be authenticated, wherein the authentication service request includes a first verification code, a preset first random number, and Internet of Things device identity information that meets the business requirements of the business application device; Encrypting the IoT device identity information based on the first verification code; Forwarding the encrypted IoT device identity information, the first random number, and the pre-acquired second random number to a passive IoT device; Receive the authentication result sent by the passive Internet of Things device, and forward the identity information of the passive Internet of Things device to the business application device.
5. The authentication method for an Internet of Things device according to claim 4, characterized in that: The authentication result includes: the identity information of the Internet of Things device is equal to the identity information of the passive Internet of Things device, or the identity information of the Internet of Things device is different from the identity information of the passive Internet of Things device, receiving the authentication result sent by the passive Internet of Things device, and forwarding the identity information of the passive Internet of Things device to the business application device, including: If the IoT device identity information is different from the passive IoT device identity information, it is determined that the authentication of the service application device to be accessed fails; If the identity information of the Internet of Things device is equal to the identity information of the passive Internet of Things device, the identity information of the passive Internet of Things device is forwarded to the business application device.
6. A method for authenticating an Internet of Things device, characterized in that: Applied to business application equipment, including: Generate a first verification code according to a preset first key and a first random number; Sending the authentication service request including the first verification code to the authentication network element, which encrypts the IoT device identity information in the authentication service request and forwards it to the passive IoT device, so that the passive IoT device performs authentication; Receive the authentication result from the passive IoT device forwarded by the authentication network element.
7. An authentication device for an Internet of Things device, characterized in that: Applied to passive IoT devices, including: A first authentication response request receiving module, configured to receive an authentication response request forwarded by an authentication network element, wherein the authentication response request includes encrypted IoT device identity information that meets the service requirements of the service application device, and the authentication network element is configured to forward the authentication service request sent by the service application device; A first identity information verification module, used to decrypt the IoT device identity information and verify whether the IoT device identity information is equivalent to the identity information of the passive IoT device; The first authentication message forwarding module is used to generate a first authentication message according to a pre-set first key and the encrypted identity information of the Internet of Things device if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, and forward the first authentication message to the authentication network element. The authentication network element authenticates the identity information of the passive Internet of Things device according to the first authentication message, and sends the authentication result to the business application device to be accessed.
8. An authentication device for an Internet of Things device, characterized in that: Applied to authentication network elements, including: A second authentication service request receiving module is used to receive an authentication service request sent by a business application device to be authenticated, wherein the authentication service request includes a first verification code, a preset first random number, and an Internet of Things device identity information that meets the business requirements of the business application device; An identity information encryption module, used to encrypt the IoT device identity information based on the first verification code; A second identity information verification module, used to forward the encrypted IoT device identity information, the first random number, and the pre-acquired second random number to a passive IoT device; The identity information forwarding module is used to receive the authentication result sent by the passive Internet of Things device and forward the identity information of the passive Internet of Things device to the business application device.
9. An authentication device for an Internet of Things device, characterized in that: Applied to business application equipment, including: A first verification code generation module, used to generate a first verification code according to a preset first key and a first random number; An authentication service request forwarding module, used for sending the authentication service request containing the first verification code to the authentication network element, and the authentication network element encrypts the IoT device identity information in the authentication service request and forwards it to the passive IoT device, so that the passive IoT device performs authentication; The authentication result receiving module is used to receive the authentication result from the passive IoT device forwarded by the authentication network element.
10. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; The processor is configured to execute the authentication method for an Internet of Things device according to any one of claims 1 to 6 by executing the executable instructions.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the authentication method for an Internet of Things device according to any one of claims 1 to 6 is implemented.
12. A computer program product comprising: A computer program or instruction, characterized in that when the computer program or instruction is executed by a processor, it implements the authentication method of the Internet of Things device described in any one of claims 1 to 6.
Citation Information
Patent Citations
Method, device and system for obtaining cellular Internet of things terminal information
CN107306394A
Cloud key SaaS autonomous AIoT control system and method
CN110839044A
Low-cost RFID tag authentication method and system
CN115169373A
Method for accessing internet-of-things platform, internet-of-things platform, and internet-of-things device
WO2018153362A1
Elevator accessory authentication method and system, and server and storage medium
WO2022166775A1