Authentication method, device and related equipment for Internet of Things devices

By using keys and random numbers to generate verification codes in passive IoT devices for authentication, and encrypting the identity information after successful authentication, the problems of security and privacy protection of passive IoT devices are solved, and efficient device authentication and privacy protection are achieved.

CN120018134BActive Publication Date: 2025-08-19CHINA TELECOM CORP LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510470346.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-08-19
Estimated Expiration
2045-04-15

AI Technical Summary

Technical Problem

Passive IoT devices have poor security problems during the Internet access process. Attackers can pretend to be devices and steal devices, and the privacy protection of device identifiers is insufficient, resulting in loss of device owners and privacy leakage.

Method used

By receiving the encrypted information forwarded by the authentication network element, using the pre-set key and random number to generate verification codes, perform device identity verification, and encrypt the identity information after the authentication is successful to generate authentication messages to ensure the legality and privacy of the device.

Benefits of technology

It reduces the signaling transmission and authentication steps of passive IoT devices, meets the device power and computing resource limitations, improves network access security, prevents privacy leakage, and enhances the security and reliability of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120018134B_ABST
    Figure CN120018134B_ABST
Patent Text Reader

Abstract

The present disclosure provides an authentication method, apparatus, and related equipment for an Internet of Things device, relating to the field of Internet of Things technology, and applied to passive Internet of Things devices. The method comprises: receiving an authentication response request forwarded by an authentication network element, including encrypted Internet of Things device identity information that meets the business requirements of a business application device; decrypting the Internet of Things device identity information, and verifying whether the Internet of Things device identity information is equivalent to the identity information of the passive Internet of Things device; if the Internet of Things device identity information is equivalent to the identity information of the passive Internet of Things device, generating a first authentication message based on a pre-set first key and the encrypted Internet of Things device identity information, and forwarding the first authentication message to the authentication network element, which authenticates the identity information of the passive Internet of Things device based on the first authentication message, and sends the authentication result to the business application device to be connected. The present disclosure can ensure the security of business application devices accessing the network and avoid privacy leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of Internet of Things, and in particular to an authentication method, apparatus, and related equipment for Internet of Things devices. Background Art

[0002] Passive IoT communicates by collecting energy such as light, heat, mechanical vibration, and electromagnetic waves from the environment. It is suitable for low-cost, low-maintenance IoT devices. The fifth-generation mobile communication technology (5G) passive IoT service is a cellular IoT communication system. Devices use the collected energy to generate radio frequency signals for two-way information transmission. However, its functions are limited and only small and infrequent data transmission is required.

[0003] The 3rd Generation Partnership Project (3GPP) is conducting research on the Ambient Internet of Things (AIoT), defining terminals and exploring various networking topologies to achieve the "connection of 100 billion things." TR 23.700-13 (a technical report focusing on enhancing the 5G system architecture to support a wide range of vertical and horizontal industry applications) explicitly mentions the authentication and certification of AIoT devices; TS 22.369 (a technical specification focused on supporting the service needs of vertical industries, which defines the specific requirements of different vertical industries for communication networks and provides corresponding functional enhancement recommendations and solutions) defines privacy-related requirements: the 5G system should be able to provide a mechanism to protect the privacy of information exchanged during communication between AIoT devices and 5G networks / terminals supporting the Passive Internet of Things, such as location and identity.

[0004] In related technologies, in the air interface, attackers can impersonate devices and report false identities to the network side. Attackers can take advantage of this and steal AIoT devices by replacing them with fake devices, which may cause losses to the owners of the devices. At the same time, the identifiers of AIoT devices are used to identify the devices. If the identifiers associated with the devices are not privacy protected, attackers can identify and track AIoT devices based on the identifiers.

[0005] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute prior art known to ordinary technicians in the field. Summary of the Invention

[0006] The present disclosure provides an authentication method, apparatus, and related equipment for an Internet of Things device, which, at least to a certain extent, overcome the problem of poor network security of Internet of Things devices in related technologies.

[0007] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by practice of the present disclosure.

[0008] According to one aspect of the present disclosure, a method for authenticating an Internet of Things device is provided, which is applied to a passive Internet of Things device, comprising: receiving an authentication service request forwarded by an authentication network element, wherein the authentication service request includes encrypted identity information of the Internet of Things device that meets the business requirements of the accessed business application device, and the authentication network element is used to forward the authentication service request sent by the business application device; decrypting the identity information of the Internet of Things device to verify whether the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device; if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, generating a first authentication message based on a pre-set first key and the encrypted identity information of the Internet of Things device that meets the business requirements of the business application device, and forwarding the first authentication message to the authentication network element, which authenticates the identity information of the passive Internet of Things device based on the first authentication message, and sends the authentication result to the business application device to be accessed.

[0009] In some exemplary embodiments of the present disclosure, based on the aforementioned scheme, the identity information of the Internet of Things device is decrypted to verify whether the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, including: obtaining a first random number and a second random number sent by the authentication network element; obtaining a pre-set first key; generating a first verification code based on the first key and the first random number; decrypting the identity information of the Internet of Things device through the first verification code to verify whether the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device.

[0010] In some exemplary embodiments of the present disclosure, based on the aforementioned scheme, if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, a first authentication message is generated according to a pre-set first key and the encrypted identity information of the Internet of Things device that meets the business requirements of the business application device, including: generating a first authentication message according to the first key, the encrypted identity information of the Internet of Things device and the second random number.

[0011] According to another aspect of the present disclosure, a method for authenticating an Internet of Things device is also provided, which is applied to an authentication network element, including: receiving an authentication service request sent by a business application device to be authenticated, the authentication service request including a first verification code, a pre-set first random number, and Internet of Things device identity information that meets the business requirements of the business application device; encrypting the Internet of Things device identity information based on the first verification code; forwarding the encrypted Internet of Things device identity information, the first random number, and a pre-acquired second random number to a passive Internet of Things device; receiving the authentication result sent by the passive Internet of Things device, and forwarding the identity information of the passive Internet of Things device to the business application device.

[0012] In some exemplary embodiments of the present disclosure, based on the aforementioned scheme, the authentication result includes: the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, or the identity information of the Internet of Things device is different from the identity information of the passive Internet of Things device, receiving the authentication result sent by the passive Internet of Things device, and forwarding the identity information of the passive Internet of Things device to the business application device, including: if the identity information of the Internet of Things device is different from the identity information of the passive Internet of Things device, determining that the authentication of the business application device to be accessed has failed; if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, forwarding the identity information of the passive Internet of Things device to the business application device.

[0013] According to another aspect of the present disclosure, a method for authenticating an Internet of Things device is also provided, which is applied to a business application device, including: generating a first verification code based on a pre-set first key and a first random number; sending an authentication service request containing the first verification code to an authentication network element, and the authentication network element encrypting the Internet of Things device identity information in the authentication service request and forwarding it to a passive Internet of Things device so that the passive Internet of Things device is authenticated; and receiving an authentication result from the passive Internet of Things device forwarded by the authentication network element.

[0014] According to another aspect of the present disclosure, an authentication device for an Internet of Things device is also provided, which is applied to a passive Internet of Things device, including: a first authentication response request receiving module, used to receive an authentication response request forwarded by an authentication network element, wherein the authentication response request includes encrypted Internet of Things device identity information that meets the business requirements of the business application device, and the authentication network element is used to forward the authentication service request sent by the business application device; a first identity information verification module, used to decrypt the Internet of Things device identity information and verify whether the Internet of Things device identity information is equivalent to the identity information of the passive Internet of Things device; a first authentication message forwarding module, used to generate a first authentication message based on a pre-set first key and the encrypted Internet of Things device identity information that meets the business requirements of the business application device if the Internet of Things device identity information is equivalent to the identity information of the passive Internet of Things device, and forward the first authentication message to the authentication network element, and the authentication network element authenticates the identity information of the passive Internet of Things device based on the first authentication message, and sends the authentication result to the business application device to be connected.

[0015] According to another aspect of the present disclosure, an authentication device for an Internet of Things device is also provided, which is applied to an authentication network element and includes: a second authentication service request receiving module, used to receive an authentication service request sent by a business application device to be authenticated, the authentication service request including a first verification code, a pre-set first random number and Internet of Things device identity information that meets the business requirements of the business application device; an identity information encryption module, used to encrypt the Internet of Things device identity information based on the first verification code; a second identity information verification module, used to forward the encrypted Internet of Things device identity information, the first random number and the pre-acquired second random number to a passive Internet of Things device; an identity information forwarding module, used to receive the authentication result sent by the passive Internet of Things device, and forward the identity information of the passive Internet of Things device to the business application device.

[0016] According to another aspect of the present disclosure, an authentication device for an Internet of Things device is also provided, which is applied to a business application device, including: a first verification code generation module, used to generate a first verification code based on a pre-set first key and a first random number; an authentication service request forwarding module, used to send an authentication service request containing the first verification code to an authentication network element, and the authentication network element encrypts the Internet of Things device identity information in the authentication service request and forwards it to a passive Internet of Things device, so that the passive Internet of Things device is authenticated; an authentication result receiving module, used to receive the authentication result from the passive Internet of Things device forwarded by the authentication network element.

[0017] According to another aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any one of the above-mentioned authentication methods for an Internet of Things device by executing the executable instructions.

[0018] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, any of the above-mentioned authentication methods for an Internet of Things device is implemented.

[0019] According to another aspect of the present disclosure, a computer program product is provided, including: a computer program or instructions, which implements any of the above-mentioned authentication methods for an Internet of Things device when executed by a processor.

[0020] An authentication method, apparatus, and related equipment for an IoT device are provided in the embodiments of the present disclosure. The authentication requirement is initiated by a business application device. Compared with traditional authentication schemes, the embodiments of the present disclosure greatly reduce the signaling and authentication steps of the passive IoT device to meet the limitations of the device's own power and computing resources. Moreover, after the passive IoT device completes identity authentication, the identity information of the passive IoT device is encrypted, and the passive IoT device is hidden and protected, which not only ensures the security of the passive IoT device's access to the network, but also further reduces the signaling interaction between the communicating parties.

[0021] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The accompanying drawings are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification, are used to explain the principles of the present disclosure. Obviously, the drawings described below are only some embodiments of the present disclosure, and those skilled in the art can derive other drawings based on these drawings without inventive effort.

[0023] Figure 1 A schematic diagram illustrating an exemplary application system architecture of an authentication method for an IoT device according to an embodiment of the present disclosure is provided;

[0024] Figure 2 A schematic diagram of an authentication method for an IoT device applied to a passive IoT device according to an embodiment of the present disclosure is shown;

[0025] Figure 3 A schematic diagram of an authentication method for an Internet of Things device applied to an authentication network element according to an embodiment of the present disclosure is shown;

[0026] Figure 4A schematic diagram of an authentication method for an Internet of Things device applied to a business application device in an embodiment of the present disclosure is shown;

[0027] Figure 5 A schematic diagram of an interaction flow of an authentication method for an IoT device according to an embodiment of the present disclosure is shown;

[0028] Figure 6 A schematic diagram of an authentication device for an Internet of Things device applied to a passive Internet of Things device according to an embodiment of the present disclosure is shown;

[0029] Figure 7 A schematic diagram of an authentication device for an Internet of Things device used to authenticate a network element in an embodiment of the present disclosure is shown;

[0030] Figure 8 A schematic diagram of an authentication device for an Internet of Things device applied to a business application device in an embodiment of the present disclosure is shown;

[0031] Figure 9 A schematic diagram of an electronic device using an authentication method for an IoT device according to an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0032] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be embodied in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0033] In addition, the described features, structures or characteristics may be combined in any suitable manner in one or more embodiments. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present disclosure. However, those skilled in the art will appreciate that the technical solutions of the present disclosure can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, well-known methods, devices, implementations or operations are not shown or described in detail to avoid blurring various aspects of the present disclosure.

[0034] The flowcharts shown in the accompanying drawings are for illustrative purposes only and do not necessarily include all contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps may be decomposed, while others may be combined or partially combined. Therefore, the actual execution order may vary depending on the actual situation.

[0035] Figure 1 FIG. 1 shows an exemplary application system architecture diagram to which the authentication method for an IoT device according to an embodiment of the present disclosure can be applied. Figure 1 As shown, the system architecture may include passive IoT devices, a core network, and business application devices.

[0036] First, in response to the above-mentioned problems, an authentication method for IoT devices is provided in the embodiments of the present disclosure, which can be applied to but not limited to the hundreds of billions of IoT scenarios in 5G / 6G networks, and a device authentication method between wide connections of full processes and all elements. Moreover, the authentication and protection scheme in the embodiments of the present disclosure can be applied to other lightweight user / device identity authentication scenarios, such as satellite-ground integration. Compared with related technologies, in the air interface, attackers can impersonate devices and report false identities to the network side. Attackers can take advantage of this and steal passive IoT devices by replacing them with fake devices, which may cause losses to the owners of the devices. At the same time, the identifier of the passive IoT device is used to identify the device. If the identifier associated with the device is not privacy protected, the attacker can identify and track the passive IoT device based on the identifier. The embodiments of the present disclosure propose a method for mutual authentication between a passive IoT device and an authentication network element, and hide the identity information of the passive IoT device to ensure the security of the device access to the network and avoid privacy leakage.

[0037] Figure 2 A schematic diagram of an authentication method for an IoT device according to an embodiment of the present disclosure is shown, which is applied to a passive IoT device. The method includes the following steps:

[0038] S202: Receive an authentication response request forwarded by an authentication network element, wherein the authentication response request includes encrypted IoT device identity information that meets the business requirements of the business application device. The authentication network element is used to forward the authentication service request sent by the business application device.

[0039] It should be noted that the authentication network element in the embodiment of the present disclosure refers to a component or system responsible for verifying the identity of a user or device in communication and network technology. Its main function is to ensure that the user or device connected to the network is legal and authorized, thereby maintaining network security and preventing unauthorized access. In more detail, the authentication network element in the embodiment of the present disclosure can reuse the Unified Data Management (UDM) network element in the existing 5G network or select other network elements; in addition, the authentication service request in the embodiment of the present disclosure can be a request initiated by any device that needs to be authenticated to another service entity responsible for identity authentication, and the user or device sends an authentication service request to the authentication network element, which is usually completed by submitting credentials such as a user name and password, a digital certificate, and biometric information. In more detail, in mobile communication networks, such as 5G networks, the authentication service request is a key process used to ensure that the business application devices connected to the network are legal and authorized for use.

[0040] S204: Decrypt the IoT device identity information to verify whether the IoT device identity information is identical to the passive IoT device identity information.

[0041] It should be noted that the IoT device identity information in the embodiments of the present disclosure refers to a series of identifiers and attributes used to uniquely identify and verify IoT devices. Common types of IoT device identity information include: device ID, MAC address, IP address, digital certificate, IMEI number, etc. In addition, the passive IoT devices in the embodiments of the present disclosure refer to IoT devices that do not require external power or battery power to operate. Such devices usually work by collecting energy from the surrounding environment, such as through radio frequency identification, light energy, thermal energy or other forms of energy collection technology. For the convenience of subsequent explanation, the embodiments of the present disclosure take the case where the device ID is the IoT device identity information as an example. Of course, the embodiments of the present disclosure do not specifically limit the IoT device identity information. Those skilled in the art can flexibly set the IoT device identity information in the embodiments of the present disclosure according to actual conditions.

[0042] S206. If the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, a first authentication message is generated based on the pre-set first key and the encrypted identity information of the Internet of Things device that meets the business requirements of the business application device, and the first authentication message is forwarded to the authentication network element. The authentication network element authenticates the identity information of the passive Internet of Things device based on the first authentication message, and sends the authentication result to the business application device to be connected.

[0043] It should be noted that the first authentication message in the embodiment of the present disclosure is generated by a key derivation function (KDF). The key derivation function can be implemented in different ways, such as Password-Based Key Derivation Function 2 (PBKDF2), HMAC-based Key Derivation Function (HKDF), and Bcrypt (an algorithm specially designed for password hashing, based on the Blowfish block cipher). When the KDF is HMAC-SHA-256, the hash-based message authentication code (Hash-based Message Authentication Code, HMAC) is combined with SHA-256 (Secure Hash Algorithm 256-bit version) to generate the key; in addition, the embodiment of the present disclosure represents the first key as K; the encrypted IoT device identity information that meets the business requirements of the business application device is represented by AIoT ID_En; and the first authentication message is represented by MAC.

[0044] The authentication method for an Internet of Things device provided in an embodiment of the present disclosure first receives an authentication response request forwarded by an authentication network element, including encrypted identity information of the Internet of Things device that meets the business requirements of the business application device; then, the Internet of Things device identity information is decrypted to verify whether the Internet of Things device identity information is equivalent to the identity information of the passive Internet of Things device; finally, if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, a first authentication message is generated based on a pre-set first key and the encrypted identity information of the Internet of Things device for the business requirements, and the first authentication message is forwarded to the authentication network element, which authenticates the identity information of the passive Internet of Things device based on the first authentication message and sends the authentication result to the business application device to be connected. Compared with the related art in which passive IoT devices are replaced with fake devices to steal passive IoT devices, and the problem of poor network security of passive IoT devices, the embodiment of the present disclosure initiates the authentication requirement by the business application device. Compared with the traditional authentication scheme, it greatly reduces the signaling and authentication steps of the passive IoT device to meet the limitations of the device's own power and computing resources; and after the passive IoT device completes the identity authentication, the identity information of the passive IoT device is encrypted and the passive IoT device is hidden and protected, which not only ensures the security of the passive IoT device's network access, but also further reduces the signaling interaction between the communicating parties to avoid privacy leakage.

[0045] In some embodiments, the present disclosure decrypts IoT device identity information and verifies whether the IoT device identity information is identical to the identity information of a passive IoT device. This includes: obtaining a first random number and a second random number sent by an authentication network element; obtaining a pre-set first key; generating a first verification code based on the first key and the first random number; and decrypting the IoT device identity information using the first verification code to verify whether the IoT device identity information is identical to the identity information of the passive IoT device. Specifically, the first random number (RAND1) and the second random number (RAND2) in the present disclosure are typically generated by the authentication network element and sent to the passive IoT device via a secure channel. These random numbers are used to increase communication security and prevent replay attacks. A new random number is generated for each authentication request, ensuring that each interaction is unique. Furthermore, the present disclosure utilizes the shared first key and the first random number to generate the first verification code, ensuring that only devices holding the correct key can pass authentication. Furthermore, the present disclosure encrypts and decrypts the identity information provided by the device to verify the device's authenticity, ensuring that only legitimate devices can access the network. Throughout the entire process, sensitive information (such as the key and identity information) is transmitted and processed in an encrypted manner to prevent leakage.

[0046] In some embodiments, if the identity information of the IoT device is equivalent to the identity information of the passive IoT device in the embodiments of the present disclosure, a first authentication message is generated based on a pre-set first key and the encrypted IoT device identity information, including: generating the first authentication message based on the first key, the encrypted IoT device identity information, and a second random number. Specifically, the first authentication message in the embodiments of the present disclosure can also be expressed as: MAC=KDF(K, AIoT ID_En, RAND2). By introducing the second random number (RAND2), each authentication request becomes unique. Even if the same device and key are used multiple times, the generated verification key will be different, thereby effectively preventing replay attacks. In addition, the generated first authentication message can be used to further verify the integrity and authenticity of the encrypted device identity information, further enhancing the security and reliability of the entire authentication mechanism.

[0047] In some embodiments, the disclosed embodiments generate a first authentication message based on a first key, encrypted IoT device identity information, and a second random number. This makes the entire authentication process not only more secure, but also effectively prevents a variety of common attack methods (such as replay attacks and man-in-the-middle attacks). In addition, this method also provides greater flexibility and dynamism, and is suitable for various complex IoT application scenarios. It not only ensures secure access to the device, but also protects the privacy and integrity of the device identity information.

[0048] Figure 3 A schematic diagram of an authentication method for an IoT device according to an embodiment of the present disclosure is shown, which is applied to an authentication network element. The method includes the following steps:

[0049] S302: Receive an authentication service request sent by a service application device to be authenticated, where the authentication service request includes a first verification code, a preset first random number, and IoT device identity information that meets the service requirements of the service application device.

[0050] S304: Encrypt the IoT device identity information based on the first verification code.

[0051] S306: Forward the encrypted IoT device identity information, the first random number, and the pre-acquired second random number to the passive IoT device.

[0052] S308: Receive the authentication result sent by the passive IoT device, and forward the identity information of the passive IoT device to the service application device.

[0053] An authentication method for an Internet of Things device provided in an embodiment of the present disclosure first receives an authentication service request sent by a business application device to be authenticated, where the authentication service request includes a first verification code, a pre-set first random number, and identity information of the Internet of Things device that meets the business requirements of the business application device; secondly, the identity information of the Internet of Things device is encrypted based on the first verification code; then, the encrypted identity information of the Internet of Things device, the first random number, and the pre-acquired second random number are forwarded to the passive Internet of Things device; finally, the authentication result sent by the passive Internet of Things device is received, and the identity information of the passive Internet of Things device is forwarded to the business application device. Compared with the related art in which passive IoT devices are replaced with fake devices to steal passive IoT devices, and the problem of poor network security of passive IoT devices, the embodiment of the present disclosure initiates the authentication requirement by the business application device. Compared with the traditional authentication scheme, it greatly reduces the signaling and authentication steps of the passive IoT device to meet the limitations of the device's own power and computing resources; and after the passive IoT device completes the identity authentication, the identity information of the passive IoT device is encrypted and the passive IoT device is hidden and protected, which not only ensures the security of the passive IoT device's network access, but also further reduces the signaling interaction between the communicating parties to avoid privacy leakage.

[0054] In some embodiments, the authentication results in the embodiments of the present disclosure include: the identity information of the IoT device is equal to the identity information of the passive IoT device, or the identity information of the IoT device is different from the identity information of the passive IoT device, receiving the authentication result sent by the passive IoT device, and forwarding the identity information of the passive IoT device to the business application device, including: if the identity information of the IoT device is different from the identity information of the passive IoT device, determining that the authentication of the business application device to be accessed has failed; if the identity information of the IoT device is equal to the identity information of the passive IoT device, forwarding the identity information of the passive IoT device to the business application device. Specifically, if the identity information of the IoT device does not match the identity information of the expected passive IoT device, the device is denied access to the network or access to the business application, which can effectively prevent unauthorized devices from entering the system and avoid potential security threats; if the identity information of the IoT device matches the identity information of the passive IoT device, the device is allowed to access the network normally, and its identity information is forwarded to the corresponding business application device, thereby ensuring that legitimate devices can smoothly perform data transmission and business operations.

[0055] Figure 4 A schematic diagram of an authentication method for an IoT device according to an embodiment of the present disclosure is shown, which is applied to a business application device. The method includes the following steps:

[0056] S402: Generate a first verification code according to a preset first key and a first random number.

[0057] S404: Send the authentication service request including the first verification code to the authentication network element, which encrypts the IoT device identity information in the authentication service request and forwards it to the passive IoT device, so that the passive IoT device performs authentication.

[0058] S406: Receive the authentication result from the passive IoT device forwarded by the authentication network element.

[0059] The embodiment of the present disclosure provides an authentication method for an IoT device. First, a first verification code is generated based on a pre-set first key and a first random number. Then, an authentication service request containing the first verification code is sent to an authentication network element. The authentication network element encrypts the IoT device identity information in the authentication service request and forwards it to the passive IoT device so that the passive IoT device can be authenticated. Finally, the authentication result forwarded by the authentication network element from the passive IoT device is received. Compared with the related art of stealing passive IoT devices by replacing them with fake devices, which has the problem of poor network security for passive IoT devices, the embodiment of the present disclosure initiates the authentication request by the service application device. Compared with the traditional authentication scheme, the signaling and authentication steps of the passive IoT device are greatly reduced to meet the power and computing resource limitations of the device itself. Moreover, after the passive IoT device completes the identity authentication, the identity information of the passive IoT device is encrypted and the passive IoT device is hidden and protected. This not only ensures the network security of the passive IoT device, but also further reduces the signaling interaction between the communicating parties and avoids privacy leakage.

[0060] In some embodiments, as Figure 5 As shown, the specific implementation process of the authentication method for the Internet of Things device in the embodiment of the present disclosure includes:

[0061] S502: Preset a first key in the passive IoT device and the business application device. The business application device connects to a random number generator (such as a quantum random number generator) to generate a first random number for use in subsequent encryption steps. The business application device is responsible for storing and managing the identity information of the IoT device (for example, the ID of the IoT device).

[0062] S504: The service application device searches for the identity information of the IoT device with which the connection is to be established, and generates a first verification code based on the first key and the first random number, where the first verification code = KDF(first key, first random number) (KDF may be HMAC-SHA-256).

[0063] S506 , the service application device forwards the authentication service request (including the first random number, the first verification code, and the identity information of the IoT device) to the authentication network element through the authentication network element.

[0064] S508, the authentication network element (which can reuse the UDM in the existing 5G network or select other units) uses the first verification code to encrypt the identity information of the IoT device, generates the encrypted identity information of the IoT device to protect the privacy and security of the device, and connects to the random number generator to generate a second random number for subsequent authentication.

[0065] S510: The authentication network element sends an authentication response request (including the first random number, the second random number, and the encrypted identity information of the IoT device) to the IoT device.

[0066] S512: The IoT device calculates a first verification code using the first key and the first random number, where the first verification code = KDF(first key, first random number). The IoT device uses the first verification code to decrypt the IoT device's identity information to verify whether it is its own ID. If correct, the IoT device continues to calculate the first authentication message; otherwise, the verification fails. The first authentication message = KDF(first key, encrypted IoT device identity information, second random number).

[0067] S514, the IoT device forwards the verification result and the first authentication message to the authentication network element.

[0068] S516: The authentication network element determines an authentication result based on the first key, the encrypted identity information of the IoT device, and the second random number.

[0069] S518, if the identity information of the Internet of Things device is different from the identity information of the passive Internet of Things device, it is determined that the authentication of the service application device to be connected has failed; if they are the same, the identity information of the passive Internet of Things device is forwarded to the service application device.

[0070] In some embodiments, as Figure 5 As shown, the embodiment of the present disclosure adopts a one-way, one-time lightweight identity authentication method, in which the application party initiates the authentication requirement. Compared with the traditional authentication scheme, it greatly reduces the signaling and authentication steps of the passive IoT device to meet the limitations of the device's own power and computing resources.

[0071] In some embodiments, the disclosed embodiments encrypt the identity information of the passive IoT device while completing identity authentication, thereby further reducing the signaling interaction between the communicating parties while completing the privacy protection function.

[0072] In more detail, the authentication network element of the embodiment of the present disclosure can be connected to a random number generator to generate random numbers in real time, and encrypt the identity information of the IoT device to achieve a one-time-one-key security effect; and, designed based on the existing 5G network, the authentication network element in the embodiment of the present disclosure can reuse the UDM in the existing 5G network or select other units, and the cost of network transformation is low.

[0073] Based on the same inventive concept, the present disclosure also provides an authentication device for an IoT device, as shown in the following embodiment. Since the principle of solving the problem in this device embodiment is similar to that in the above method embodiment, the implementation of this device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0074] Figure 6 A schematic diagram of an authentication device for an IoT device according to an embodiment of the present disclosure is shown, which is applied to a passive IoT device. The device includes:

[0075] A first authentication response request receiving module 601 is configured to receive an authentication response request forwarded by an authentication network element, wherein the authentication response request includes encrypted IoT device identity information that meets the service requirements of the service application device, and the authentication network element is configured to forward the authentication service request sent by the service application device;

[0076] The first identity information verification module 602 is used to decrypt the IoT device identity information and verify whether the IoT device identity information is identical to the passive IoT device identity information;

[0077] The first authentication message forwarding module 603 is used to generate a first authentication message based on a pre-set first key and the encrypted identity information of the Internet of Things device if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, and forward the first authentication message to the authentication network element. The authentication network element authenticates the identity information of the passive Internet of Things device based on the first authentication message, and sends the authentication result to the business application device to be connected.

[0078] An authentication device for an Internet of Things device provided in an embodiment of the present disclosure receives, through an authentication service request acquisition module, an authentication response request forwarded by an authentication network element, including encrypted identity information of the Internet of Things device that meets the business requirements of a business application device; through an identity information verification module, decrypts the identity information of the Internet of Things device to verify whether the identity information of the Internet of Things device is equivalent to the identity information of a passive Internet of Things device; through a first authentication message forwarding module, if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, a first authentication message is generated based on a pre-set first key and the encrypted identity information of the Internet of Things device for business requirements, and the first authentication message is forwarded to the authentication network element, which authenticates the identity information of the passive Internet of Things device based on the first authentication message, and sends the authentication result to the business application device to be connected. Compared with the related art of stealing AIoT devices by replacing them with fake devices, and the problem of poor security of AIoT devices accessing the network, the embodiment of the present disclosure initiates the authentication requirement by the business application device. Compared with the traditional authentication scheme, it greatly reduces the signaling and authentication steps of the passive IoT device to meet the limitations of the device's own power and computing resources; and, after the passive IoT device completes the identity authentication, the identity information of the passive IoT device is encrypted and the passive IoT device is hidden and protected, which not only ensures the security of the passive IoT device accessing the network, but also further reduces the signaling interaction between the communicating parties to avoid privacy leakage.

[0079] In some embodiments, the identity information verification module in the embodiment of the present disclosure is also used to obtain a first random number and a second random number sent by the authentication network element; obtain a pre-set first key; generate a first verification code based on the first key and the first random number; decrypt the Internet of Things device identity information through the first verification code, and verify whether the Internet of Things device identity information is equivalent to the identity information of the passive Internet of Things device.

[0080] In some embodiments, the first authentication message forwarding module in the embodiments of the present disclosure is further used to generate a first authentication message based on the first key, the encrypted IoT device identity information and the second random number.

[0081] Based on the same inventive concept, the present disclosure also provides an authentication device for an IoT device, as shown in the following embodiment. Since the principle of solving the problem in this device embodiment is similar to that in the above method embodiment, the implementation of this device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0082] Figure 7 A schematic diagram of an authentication device for an IoT device according to an embodiment of the present disclosure is shown, which is applied to an authentication network element. The device includes:

[0083] The second authentication service request receiving module 701 is configured to receive an authentication service request sent by a service application device to be authenticated, the authentication service request including a first verification code, a preset first random number, and IoT device identity information that meets the service requirements of the service application device;

[0084] The identity information encryption module 702 is used to encrypt the IoT device identity information based on the first verification code;

[0085] The second identity information verification module 703 is used to forward the encrypted IoT device identity information, the first random number, and the pre-acquired second random number to the passive IoT device;

[0086] The identity information forwarding module 704 is configured to receive the authentication result sent by the passive IoT device and forward the identity information of the passive IoT device to the service application device.

[0087] In some embodiments, an authentication device for an Internet of Things device in an embodiment of the present disclosure receives an authentication service request sent by a business application device to be authenticated through an authentication service request receiving module, where the authentication service request includes a first verification code, a pre-set first random number, and Internet of Things device identity information that meets the business requirements of the business application device; encrypts the Internet of Things device identity information based on the first verification code through an identity information encryption module; forwards the encrypted Internet of Things device identity information, the first random number, and the pre-acquired second random number to a passive Internet of Things device through an identity information verification module; receives the authentication result sent by the passive Internet of Things device through an identity information forwarding module, and forwards the identity information of the passive Internet of Things device to the business application device. Compared with the related art in which passive IoT devices are replaced with fake devices to steal passive IoT devices, and the problem of poor network security of passive IoT devices, the embodiment of the present disclosure initiates the authentication requirement by the business application device. Compared with the traditional authentication scheme, it greatly reduces the signaling and authentication steps of the passive IoT device to meet the limitations of the device's own power and computing resources; and after the passive IoT device completes the identity authentication, the identity information of the passive IoT device is encrypted and the passive IoT device is hidden and protected, which not only ensures the security of the passive IoT device's network access, but also further reduces the signaling interaction between the communicating parties to avoid privacy leakage.

[0088] In some embodiments, the authentication results in the embodiments of the present disclosure include: the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, or the identity information of the Internet of Things device is different from the identity information of the passive Internet of Things device. The identity information forwarding module in the embodiments of the present disclosure is also used to determine that the authentication of the business application device to be accessed fails if the identity information of the Internet of Things device is different from the identity information of the passive Internet of Things device; if the identity information of the Internet of Things device is equivalent to the identity information of the passive Internet of Things device, the identity information of the passive Internet of Things device is forwarded to the business application device.

[0089] Based on the same inventive concept, the present disclosure also provides an authentication device for an IoT device, as shown in the following embodiment. Since the principle of solving the problem in this device embodiment is similar to that in the above method embodiment, the implementation of this device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0090] Figure 8 A schematic diagram of an authentication device for an IoT device according to an embodiment of the present disclosure is shown, which is applied to a business application device. The device includes:

[0091] A first verification code generation module 801 is configured to generate a first verification code according to a preset first key and a first random number;

[0092] An authentication service request forwarding module 802 is configured to send an authentication service request including a first verification code to an authentication network element, which encrypts the IoT device identity information in the authentication service request and forwards it to the passive IoT device, so that the passive IoT device performs authentication.

[0093] The authentication result receiving module 803 is used to receive the authentication result from the passive IoT device forwarded by the authentication network element.

[0094] The embodiment of the present disclosure provides an authentication device for an Internet of Things device. The first verification code generation module generates a first verification code according to a pre-set first key and a first random number. The authentication service request forwarding module sends an authentication service request containing the first verification code to an authentication network element. The authentication network element encrypts the Internet of Things device identity information in the authentication service request and forwards it to the passive Internet of Things device so that the passive Internet of Things device performs authentication. The authentication result receiving module receives the authentication result forwarded by the authentication network element from the passive Internet of Things device. Compared with the related art of stealing passive Internet of Things devices by replacing them with fake devices, which has the problem of poor network security for passive Internet of Things devices, the embodiment of the present disclosure initiates the authentication request by the service application device. Compared with the traditional authentication scheme, the signaling and authentication steps of the passive Internet of Things device are greatly reduced to meet the power and computing resource limitations of the device itself. Moreover, after the passive Internet of Things device completes the identity authentication, the identity information of the passive Internet of Things device is encrypted and the passive Internet of Things device is hidden and protected. This not only ensures the network security of the passive Internet of Things device, but also further reduces the signaling interaction between the communicating parties and avoids privacy leakage.

[0095] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods, or program products. Therefore, various aspects of the present disclosure may be implemented in the following forms: entirely in hardware, entirely in software (including firmware, microcode, etc.), or in a combination of hardware and software, collectively referred to herein as "circuits," "modules," or "systems."

[0096] Based on the same inventive concept, an embodiment of the present disclosure further provides an electronic device, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any of the aforementioned methods for authenticating an IoT device by executing the executable instructions. Because the principles for solving the problems in this electronic device embodiment are similar to those in the aforementioned method embodiment, the implementation of this electronic device embodiment can refer to the implementation of the aforementioned method embodiment, and any repetitions will not be repeated.

[0097] Refer to the following Figure 9 hereinafter, an electronic device 900 according to this embodiment of the present disclosure is described. Figure 9 The electronic device 900 shown is merely an example and should not limit the functions and scope of use of the embodiments of the present disclosure.

[0098] like Figure 9As shown, electronic device 900 is implemented as a general-purpose computing device. Components of electronic device 900 may include, but are not limited to, at least one processing unit 901, at least one storage unit 902, and a bus 903 connecting different system components (including storage unit 902 and processing unit 901).

[0099] The storage unit stores program codes, which can be executed by the processing unit 901, so that the processing unit 901 executes the steps according to various exemplary embodiments of the present disclosure described in the above “Exemplary Method” section of this specification.

[0100] In some embodiments, when an electronic device is used to control the authentication method of the IoT device disclosed above, the processing unit 901 may perform the following steps of the above method embodiment:

[0101] Receive an authentication response request forwarded by an authentication network element, wherein the authentication response request includes encrypted IoT device identity information that meets the business requirements of the business application device, and the authentication network element is used to forward the authentication service request sent by the business application device; decrypt the IoT device identity information to verify whether the IoT device identity information is equivalent to the identity information of the passive IoT device; if the IoT device identity information is equivalent to the identity information of the passive IoT device, generate a first authentication message based on a pre-set first key and the encrypted IoT device identity information, and forward the first authentication message to the authentication network element, which authenticates the identity information of the passive IoT device based on the first authentication message, and sends the authentication result to the business application device to be connected.

[0102] The storage unit 902 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 9021 and / or a cache memory unit 9022 , and may further include a read-only memory unit (ROM) 9023 .

[0103] The storage unit 902 may also include a program / utility 9024 having a set (at least one) of program modules 9025, such program modules 9025 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0104] Bus 903 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0105] The electronic device 900 may also communicate with one or more external devices 904 (e.g., a keyboard, pointing device, Bluetooth device, etc.), one or more devices that enable a user to interact with the electronic device 900, and / or any device that enables the electronic device 900 to communicate with one or more other computing devices (e.g., a router, modem, etc.). This communication may occur via an input / output (I / O) interface 905. Furthermore, the electronic device 900 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network such as the Internet) via a network adapter 906. As shown, the network adapter 906 communicates with other modules of the electronic device 900 via a bus 903. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 900, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0106] Through the description of the above embodiments, it will be readily understood by those skilled in the art that the example embodiments described herein can be implemented via software or via a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or mobile hard drive) or on a network and includes several instructions for enabling a computing device (such as a personal computer, server, terminal device, or network device) to execute the methods according to the embodiments of the present disclosure.

[0107] Based on the same inventive concept, embodiments of the present disclosure also provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements any of the aforementioned methods for authenticating an IoT device. Because the principles underlying the problems solved by this computer-readable storage medium embodiment are similar to those of the aforementioned method embodiment, the implementation of this computer-readable storage medium embodiment can be referenced to the implementation of the aforementioned method embodiment, and any repetitions will not be repeated.

[0108] More specific examples of computer-readable storage media in the present disclosure may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0109] In the present disclosure, a computer-readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, which carries readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0110] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.

[0111] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, and conventional procedural programming languages such as C or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0112] Based on the same inventive concept, embodiments of the present disclosure further provide a computer program product, including a computer program or instructions. When executed by a processor, the computer program or instructions implement the IoT device authentication method described in any of the aforementioned method embodiments. Because the principles underlying the problems solved by this computer program product embodiment are similar to those of the aforementioned method embodiments, the implementation of this computer program product embodiment can be referenced to the implementation of the aforementioned method embodiments, and any repetitions will not be repeated.

[0113] It should be noted that although several modules or units of the device for action execution are mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be concretized in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units to be concretized.

[0114] Furthermore, although the steps of the method of the present disclosure are described in a particular order in the accompanying drawings, this does not require or imply that the steps must be performed in this particular order, or that all steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.

[0115] Through the description of the above embodiments, it will be readily understood by those skilled in the art that the example embodiments described herein can be implemented via software or via a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or mobile hard drive) or on a network and includes several instructions for enabling a computing device (such as a personal computer, server, mobile terminal, or network device) to execute the methods according to the embodiments of the present disclosure.

[0116] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the appended claims.

Claims

1. A method for authenticating an Internet of Things device, characterized in that: Applied to passive IoT devices, including: Receive an authentication response request forwarded by an authentication network element, wherein the authentication response request includes encrypted IoT device identity information that meets the service requirements of the service application device, and the authentication network element is used to forward the authentication service request sent by the service application device; Decrypting the IoT device identity information to verify whether the IoT device identity information is identical to the identity information of the passive IoT device; If the IoT device identity information is identical to the passive IoT device identity information, a first authentication message is generated based on a preset first key and the encrypted IoT device identity information, and the first authentication message is forwarded to an authentication network element. The authentication network element authenticates the passive IoT device identity information based on the first authentication message, and sends the authentication result to the service application device to be connected. The authentication network element is connected to a random number generator to generate a random number in real time, and a first verification code is generated based on the random number to encrypt the identity information of the IoT device; Decrypting the IoT device identity information and verifying whether the IoT device identity information is equivalent to the identity information of the passive IoT device, including: obtaining a first random number and a second random number sent by the authentication network element; obtaining a pre-set first key; generating a first verification code based on the first key and the first random number; decrypting the IoT device identity information through the first verification code, and verifying whether the IoT device identity information is equivalent to the identity information of the passive IoT device.

2. The authentication method for an Internet of Things device according to claim 1, wherein: If the IoT device identity information is identical to the identity information of the passive IoT device, generating a first authentication message according to a preset first key and the encrypted IoT device identity information includes: A first authentication message is generated according to the first key, the encrypted IoT device identity information, and the second random number.

3. A method for authenticating an IoT device, characterized in that: Applied to authentication network elements, including: Receive an authentication service request sent by a business application device to be authenticated, the authentication service request including a first verification code, a preset first random number, and identity information of an Internet of Things device that meets the business requirements of the business application device; Encrypting the IoT device identity information based on the first verification code; Forwarding the encrypted IoT device identity information, the first random number, and the pre-acquired second random number to the passive IoT device; receiving a first authentication message sent by the passive IoT device, and forwarding the identity information of the passive IoT device to the service application device; The authentication network element is connected to a random number generator to generate a random number in real time, and generates a first verification code based on the random number; Receiving a first authentication message sent by the passive Internet of Things device includes: the passive Internet of Things device decrypting the Internet of Things device identity information, verifying whether the Internet of Things device identity information is equivalent to the identity information of the passive Internet of Things device; if the Internet of Things device identity information is equivalent to the identity information of the passive Internet of Things device, generating a first authentication message based on a pre-set first key and the encrypted Internet of Things device identity information, and forwarding the first authentication message to an authentication network element; the authentication network element authenticates the identity information of the passive Internet of Things device based on the first authentication message, and sends the authentication result to the service application device to be accessed.

4. The authentication method for an Internet of Things device according to claim 3, wherein: The authentication result includes: the identity information of the Internet of Things device is equal to the identity information of the passive Internet of Things device, or the identity information of the Internet of Things device is different from the identity information of the passive Internet of Things device, receiving the authentication result sent by the passive Internet of Things device, and forwarding the identity information of the passive Internet of Things device to the service application device, including: If the identity information of the IoT device is different from the identity information of the passive IoT device, it is determined that the authentication of the service application device to be accessed has failed; If the identity information of the Internet of Things device is identical to the identity information of the passive Internet of Things device, the identity information of the passive Internet of Things device is forwarded to the business application device.

5. A method for authenticating an Internet of Things device, characterized in that: Applicable to business application equipment, including: Generate a first verification code according to a preset first key and a first random number; Sending an authentication service request including the first verification code to an authentication network element, wherein the authentication network element encrypts the IoT device identity information in the authentication service request and forwards the information to the passive IoT device, so that the passive IoT device performs authentication; Wherein, the passive IoT device is authenticated, including: if the IoT device identity information is identical to the identity information of the passive IoT device, generating a first authentication message according to a preset first key and the encrypted IoT device identity information, and forwarding the first authentication message to an authentication network element, wherein the authentication network element authenticates the identity information of the passive IoT device according to the first authentication message, and sends the authentication result to the service application device to be connected; Receiving an authentication result from the passive IoT device forwarded by the authentication network element; The authentication network element is connected to a random number generator to generate a random number in real time, and a first verification code is generated based on the random number to encrypt the identity information of the IoT device; Generating a first verification code according to a preset first key and a first random number includes: obtaining the first random number sent by the authentication network element; and obtaining the preset first key.

6. An authentication device for an Internet of Things device, characterized in that: Applied to passive IoT devices, including: a first authentication response request receiving module, configured to receive an authentication response request forwarded by an authentication network element, wherein the authentication response request includes encrypted IoT device identity information that meets the service requirements of the service application device, and the authentication network element is configured to forward the authentication service request sent by the service application device; A first identity information verification module is used to decrypt the IoT device identity information and verify whether the IoT device identity information is identical to the identity information of the passive IoT device; A first authentication message forwarding module is configured to generate a first authentication message based on a preset first key and the encrypted identity information of the IoT device if the IoT device identity information is identical to the identity information of the passive IoT device, and forward the first authentication message to an authentication network element, which authenticates the identity information of the passive IoT device based on the first authentication message and sends the authentication result to the service application device to be connected; The authentication network element is connected to a random number generator to generate a random number in real time, and a first verification code is generated based on the random number to encrypt the identity information of the IoT device; The first identity information verification module is also used to obtain the first random number and the second random number sent by the authentication network element; obtain a pre-set first key; generate a first verification code based on the first key and the first random number; decrypt the Internet of Things device identity information through the first verification code to verify whether the Internet of Things device identity information is equivalent to the identity information of the passive Internet of Things device.

7. An authentication device for an Internet of Things device, characterized in that: Applied to authentication network elements, including: A second authentication service request receiving module is configured to receive an authentication service request sent by a service application device to be authenticated, wherein the authentication service request includes a first verification code, a preset first random number, and identity information of an Internet of Things device that meets the service requirements of the service application device; An identity information encryption module, configured to encrypt the IoT device identity information based on the first verification code; A second identity information verification module is configured to forward the encrypted IoT device identity information, the first random number, and the pre-acquired second random number to a passive IoT device; An identity information forwarding module, configured to receive a first authentication message sent by the passive IoT device and forward the identity information of the passive IoT device to the service application device; The authentication network element is connected to a random number generator to generate a random number in real time, and generates a first verification code based on the random number; Among them, the passive Internet of Things device decrypts the Internet of Things device identity information and verifies whether the Internet of Things device identity information is equivalent to the identity information of the passive Internet of Things device. If the Internet of Things device identity information is equivalent to the identity information of the passive Internet of Things device, a first authentication message is generated according to a pre-set first key and the encrypted Internet of Things device identity information, and the first authentication message is forwarded to an authentication network element. The authentication network element authenticates the identity information of the passive Internet of Things device based on the first authentication message, and sends the authentication result to the service application device to be accessed.

8. An authentication device for an Internet of Things device, characterized in that: Applicable to business application equipment, including: A first verification code generation module, configured to generate a first verification code according to a preset first key and a first random number; an authentication service request forwarding module, configured to send the authentication service request containing the first verification code to an authentication network element, wherein the authentication network element encrypts the IoT device identity information in the authentication service request and forwards the encrypted information to the passive IoT device, so that the passive IoT device performs authentication; Wherein, the passive IoT device is authenticated, including: if the IoT device identity information is identical to the identity information of the passive IoT device, generating a first authentication message according to a preset first key and the encrypted IoT device identity information, and forwarding the first authentication message to an authentication network element, wherein the authentication network element authenticates the identity information of the passive IoT device according to the first authentication message, and sends the authentication result to the service application device to be connected; An authentication result receiving module, configured to receive the authentication result from the passive IoT device forwarded by the authentication network element; The authentication network element is connected to a random number generator to generate a random number in real time, and a first verification code is generated based on the random number to encrypt the identity information of the IoT device; The first verification code generation module is further used to obtain a first random number sent by the authentication network element; and obtain a preset first key.

9. An electronic device, characterized in that: include: processor; as well as a memory for storing executable instructions of the processor; The processor is configured to execute the authentication method for an Internet of Things device according to any one of claims 1 to 5 by executing the executable instructions.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the authentication method for an Internet of Things device according to any one of claims 1 to 5 is implemented.

11. A computer program product comprising: A computer program or instruction, characterized in that when the computer program or instruction is executed by a processor, it implements the authentication method of the Internet of Things device according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Method, device and system for obtaining cellular Internet of things terminal information

    CN107306394A

  • Low-cost RFID tag authentication method and system

    CN115169373A