Access verification method and device for offline device and storage medium
By displaying the QR code on the device and scanning the code with the mobile device to apply for access, combined with the verification mechanism of the USB key and the cloud service system, the problem of insufficient security of offline verification of the device is solved, and efficient, flexible and secure access control is achieved.
Patent Information
- Application Number
- CN202510197681.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-05-27
AI Technical Summary
In the prior art, the security of offline verification of equipment is insufficient, and the use of static passwords for access control has problems such as leakage and management.
By displaying the QR code on the device, the user scans the code to apply for access using a mobile device with a network connection. The device is verified through the USB key and cloud service system, and a feature authorization code is generated and verified to activate access permissions.
It realizes secure and flexible access control for offline devices, authorizes user roles in real time, and removes access permissions from the background at any time, improving the security and efficiency of device usage verification.
Smart Images

Figure CN120050095A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of device verification, and in particular to an access verification method, device, and storage medium for offline devices. Background Art
[0002] Currently, the need for access control for various electronic devices used offline is very common. Existing permission control means are generally based on built-in static accounts and passwords. This method requires logging in with the account passwords of different default roles set in advance. Once the password is leaked, unauthorized use of the device will occur. If each device uses different default accounts and passwords, it will also be very complicated from a management perspective, and a dedicated database and system background have to be built to register and save all the account passwords.
[0003] Existing optimization methods generally adopt user account password login based on network connection and MFA multi-factor authorization login methods, both of which require the device to be network-connected. Therefore, due to the insufficient security of device offline verification in the prior art, a new technology is needed to solve the current technical problems. Summary of the Invention
[0004] The main objective of the present invention is to solve the technical problem of insufficient security in device offline verification in the prior art.
[0005] The first aspect of the present invention provides an access verification method for an offline device. The access verification method for the offline device is applied to the access verification system of the offline device. The access verification system of the offline device includes: a device control system, an intelligent code scanning system, and a cloud service system. The access verification method for the offline device includes:
[0006] The device control system receives a USB key injected externally based on a USB interface;
[0007] Determine whether the USB key is a qualified key;
[0008] When it is a qualified key, display a login QR code on a preset device interface;
[0009] The intelligent code scanning system scans the login QR code, obtains a device token based on the login QR code, and activates and displays a login interface based on the login QR code, and receives a personal token input by a user on the login interface;
[0010] Send the device token and the personal token to the cloud service system;
[0011] The cloud service system receives the device token and the personal token, and determines whether the personal token exists in a preset configuration database;
[0012] When it exists in the configuration database, query the feature authorization code corresponding to the combination of the personal token and the device token, and send the feature authorization code to the intelligent code scanning system;
[0013] The device control system receives an externally input feature authorization code and analyzes whether the feature authorization code is a valid authorization code;
[0014] When it is a valid authorization code, activate the device access permission.
[0015] Optionally, in the first implementation manner of the first aspect of the present invention, the querying the feature authorization code corresponding to the combination of the personal token and the device token includes:
[0016] Use the personal token as the key identifier to retrieve the first value identifier in the configuration database;
[0017] Use the device token as the key identifier to retrieve the second value identifier in the first value identifier;
[0018] Confirm the second value identifier as the feature authorization code.
[0019] Optionally, in the second implementation manner of the first aspect of the present invention, the USB key includes: a USB device unique identification serial number and a key string, and the judging whether the USB key is a qualified key includes:
[0020] Judge whether the USB device unique identification serial number is registered in the preset device database;
[0021] When it is not registered in the preset device database, display the unqualified data of the USB key on the preset device interface;
[0022] When it is registered in the preset device database, query the paired public key corresponding to the USB device unique identification serial number from the device database;
[0023] According to the paired public key, decrypt the key string to obtain decryption data;
[0024] Judge whether the decryption data is legal data.
[0025] Optionally, in the third implementation manner of the first aspect of the present invention, after querying the feature authorization code corresponding to the combination of the personal token and the device token and sending the feature authorization code to the intelligent code scanning system, it includes:
[0026] The intelligent code scanning system receives the feature authorization code and generates an authorization two-dimensional code according to the feature authorization code.
[0027] Optionally, in the fourth implementation manner of the first aspect of the present invention, the device control system is connected to a camera lens, and the device control system receiving an externally input feature authorization code includes:
[0028] The device control system scans the authorization two-dimensional code through the camera lens, and obtains a feature authorization code according to the authorization two-dimensional code.
[0029] Optionally, in the fifth implementation manner of the first aspect of the present invention, after determining whether the personal token exists in the preset configuration database, it further includes:
[0030] When it does not exist in the preset configuration database, a login verification failure message is sent to the intelligent code scanning system.
[0031] Optionally, in the sixth implementation manner of the first aspect of the present invention, analyzing whether the feature authorization code is a valid authorization code includes:
[0032] Determine whether the feature authorization code exists in the preset authorization registry;
[0033] When it exists in the preset authorization registry, confirm that the feature authorization code is a valid authorization code;
[0034] When it does not exist in the preset authorization registry, confirm that the feature authorization code is not a valid authorization code.
[0035] Optionally, in the seventh implementation manner of the first aspect of the present invention, the device control system receiving an externally input feature authorization code further includes:
[0036] Based on the Bluetooth protocol, the device control system receives the feature authorization code transmitted from the intelligent code scanning system.
[0037] The second aspect of the present invention provides an access verification device for an offline device, including: a memory and at least one processor, wherein instructions are stored in the memory, and the memory and the at least one processor are interconnected by a line; the at least one processor calls the instructions in the memory to enable the access verification device for the offline device to execute the above-mentioned access verification method for the offline device.
[0038] The third aspect of the present invention provides a computer-readable storage medium, in which instructions are stored, and when it runs on a computer, it enables the computer to execute the above-mentioned access verification method for the offline device.
[0039] In an embodiment of the present invention, a two-dimensional code is displayed on an electronic device with a display screen, and at the same time, a user connects a pre-applied key to the device through the device's USB interface. The user scans the code with a mobile device with a network connection to apply for access to this device. The device access request is reported to the server through the network. The server determines whether the role of this user can access this device. If the determination passes, the server sends a string of authorization codes to the user's mobile device. The user fills the authorization codes back into the device. After the device verifies the authorization codes, it confirms the login, and the user obtains the access permission. This solves the problem that the use of static passwords for offline device access control is insecure, authorizes the user role in real time, and can remove the user access permission from the background at any time. The verification of the device usage is more flexible, efficient, and secure. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 FIG. is a schematic diagram of an embodiment of the access verification method for an offline device in an embodiment of the present invention;
[0041] Figure 2 FIG. is a schematic diagram of a specific embodiment of step 102 in an embodiment of the present invention;
[0042] Figure 3 FIG. is a schematic diagram of a specific embodiment of step 107 in an embodiment of the present invention;
[0043] Figure 4 FIG. is a schematic diagram of a specific embodiment of step 108 in an embodiment of the present invention;
[0044] Figure 5 FIG. is a schematic diagram of an embodiment of the access verification device for an offline device in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0045] The embodiments of the present invention provide an access verification method, device, and storage medium for an offline device.
[0046] The embodiments disclosed by the present invention will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the accompanying drawings and embodiments of the present invention are only for exemplary purposes and are not used to limit the protection scope of the present invention.
[0047] In the description of the embodiments disclosed in the present invention, the term "including" and its similar terms should be understood as open inclusion, that is, "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "an embodiment" or "the embodiment" should be understood as "at least one embodiment". The terms "first", "second", etc. may refer to different or the same objects. There may also be other explicit and implicit definitions hereinafter.
[0048] For ease of understanding, the specific process of the embodiments of the present invention will be described below. Please refer to Figure 1 , a schematic diagram of an embodiment of the access verification method for an offline device in an embodiment of the present invention. The access verification method for the offline device is applied to the access verification system for the offline device. The access verification system for the offline device includes: a device control system, an intelligent code scanning system, and a cloud service system. The access verification method for the offline device includes:
[0049] 101. The device control system receives a USB key injected externally based on the USB interface.
[0050] In this embodiment, the device control system is a device that needs offline access. The device is provided with a USB interface. The user can insert a USB flash drive into the USB interface and inject the USB key into the device control system using the USB flash drive. Each USB flash drive is a device registered in the management system of the device control system, and the USB flash drive stores a bound USB key. The bound USB keys are randomly generated respectively.
[0051] 102. Determine whether the USB key is a qualified key.
[0052] In this embodiment, the data encryption key is pre-configured in the USB medium, and it is determined whether the USB key is a registered qualified key.
[0053] Specifically, please refer to Figure 2 , Figure 2 , which is a schematic diagram of a specific embodiment of step 102 in an embodiment of the present invention. The USB key includes: a unique identification serial number of the USB device and a key string. The following specific implementation manners are included in step 102:
[0054] 1021. Determine whether the unique identification serial number of the USB device is registered in the preset device database.
[0055] 1022. When it is not registered in the preset device database, display the unqualified data of the USB key on the preset device interface.
[0056] 1023. When it is registered in the preset device database, query the paired public key corresponding to the unique identification serial number of the USB device from the device database.
[0057] 1024. Decrypt the key string according to the paired public key to obtain decrypted data;
[0058] 1025. Determine whether the decrypted data is legal data.
[0059] In steps 1021 - 1025, first, decompose the USB device unique identification serial number from the USB key, and determine whether the hardware device with the USB device unique identification serial number is registered in the internal database of the device. If it is not registered in the internal database of the device, it means that the USB key is unqualified, and the notification information of the unqualified USB key is displayed on the device interface of the device control system connected to the display screen.
[0060] If the USB device unique identification serial number has been registered in the database, query the paired public key corresponding to the USB device unique identification serial number from the device database. The paired public keys for different identification serial numbers are different. Another string in the symmetric encryption during the encryption process is randomly generated, and the paired public keys must be different.
[0061] Based on this public key, decrypt the key string to obtain decrypted data. This decrypted data is the password of the input verification device, and this password should be consistent with the password stored corresponding to the USB device unique identification serial number.
[0062] 103. When it is a qualified key, display the login QR code on the preset device interface;
[0063] In this embodiment, the login QR code required for verification is displayed on the device interface.
[0064] 104. The intelligent code scanning system scans the login QR code, obtains the device token based on the login QR code, and activates and displays the login interface based on the login QR code, and receives the personal token input by the user on the login interface;
[0065] In this embodiment, the intelligent code scanning system can be a smart phone or other devices with a shooting function. Scan the login QR code to identify the device token, and activate the login interface on the intelligent code scanning system when scanning the login QR code. The user inputs the personal token on the login interface.
[0066] 105. Send the device token and the personal token to the cloud service system;
[0067] In this embodiment, the device token and the personal token are packaged and transmitted to the cloud service system.
[0068] 106. The cloud service system receives the device token and the personal token, and determines whether the personal token exists in the preset configuration database;
[0069] In this embodiment, the cloud service system receives the device token and the personal token, and first determines whether the personal token is registered in the configuration data of the cloud service system.
[0070] Further, after determining whether the personal token exists in the preset configuration database, it further includes:
[0071] 1061. When it does not exist in the preset configuration database, a login verification failure message is sent to the intelligent code scanning system.
[0072] In step 1061, if the personal token does not exist in the configuration data, the cloud service system sends a login verification failure message to the intelligent code scanning system so that the user can see the login failure message in time and readjust the data input in time.
[0073] 107. When it exists in the configuration database, the characteristic authorization code corresponding to the combination of the personal token and the device token is queried, and the characteristic authorization code is sent to the intelligent code scanning system;
[0074] In this embodiment, if the personal token exists in the configuration database, it means that the personal user has registered an account in the cloud server. Then, based on the personal token, the characteristic authorization code corresponding to the device token is found from the user's account, and the characteristic authorization code is sent to the intelligent code scanning system.
[0075] Specifically, please refer to Figure 3 , Figure 3 which is a schematic diagram of a specific embodiment of step 107 in the embodiment of the present invention. The following specific implementation manners are included in step 107:
[0076] 1071. Use the personal token as the key identifier to retrieve the first value identifier in the configuration database;
[0077] 1072. Use the device token as the key identifier to retrieve the second value identifier in the first value identifier;
[0078] 1073. Confirm the second value identifier as the characteristic authorization code.
[0079] In steps 1071 - 1073, the database stores data in the form of nested key - value pairs, with the format like {a:{b:123}, d:{e:933}, m:{l:693}}. First, the personal token retrieves the first value identifier {b:123} from the configuration database, then based on the device token b, retrieves the second value identifier 123 from the first value identifier {b:123}, and then confirms the second value identifier as the feature authorization code.
[0080] Specifically, after querying the feature authorization code corresponding to the combination of the personal token and the device token and sending the feature authorization code to the intelligent code - scanning system, it includes:
[0081] 1074. The intelligent code - scanning system receives the feature authorization code and generates an authorization QR code according to the feature authorization code.
[0082] In this embodiment, the intelligent code - scanning system receives the feature authorization code 123 and generates an authorization QR code based on the conversion of the feature authorization code 123.
[0083] In step 1074, the device control system is connected to the camera lens. In step 108, "the device control system receives an externally input feature authorization code" includes the following specific implementation:
[0084] 1081. The device control system scans the authorization QR code through the camera lens and obtains the feature authorization code according to the authorization QR code.
[0085] In step 1081, the device control system scans the authorization QR code based on the camera lens and directly obtains the feature authorization code by parsing the QR code. In the case where the feature authorization code is relatively complex, there is no need for the user to input values on the keyboard.
[0086] 108. The device control system receives an externally input feature authorization code and analyzes whether the feature authorization code is a valid authorization code;
[0087] In step 108, the device control system can receive the externally input feature authorization code through its own display interface and analyze whether the feature authorization code is a valid authorization code.
[0088] In one embodiment, step 108 further includes the following specific implementation:
[0089] 1082. Based on the Bluetooth protocol, the device control system receives the feature authorization code transmitted from the intelligent code - scanning system.
[0090] In step 1082, the device control system is set to support the Bluetooth protocol. Based on the Bluetooth protocol, the control system of the device is connected to the mobile phone, and the feature authorization code is directly transmitted and imported from the mobile phone.
[0091] Specifically, please refer to Figure 4 , Figure 4 which is a schematic diagram of a specific embodiment of step 108 in the embodiments of the present invention. The "analyzing whether the feature authorization code is a valid authorization code" in step 108 includes the following specific implementations:
[0092] 1083. Determine whether the feature authorization code exists in the preset authorization registry;
[0093] 1084. When it exists in the preset authorization registry, confirm that the feature authorization code is a valid authorization code;
[0094] 1085. When it does not exist in the preset authorization registry, confirm that the feature authorization code is not a valid authorization code.
[0095] In steps 1083 - 1085, a registry of dictionary type is set inside the device control system to query the feature authorization code, and based on the true or false result returned, it is judged whether the feature authorization code exists in the preset authorization registry. When it exists in the preset authorization registry, confirm that the feature authorization code is a valid authorization code; when it does not exist in the preset authorization registry, confirm that the feature authorization code is not a valid authorization code.
[0096] 109. When it is a valid authorization code, activate the device access permission.
[0097] In this embodiment, when the authorization code is a valid authorization code, the offline device has authenticated the user identity and activated the device access permission, and the user can operate the offline device after the permission is activated.
[0098] In the embodiments of the present invention, by displaying a QR code on an electronic device with a display screen, and at the same time the user connects the previously applied key to the device through the device USB interface. The user scans the code with a mobile device with a network connection to apply for access to this device. The device access request is reported to the server through the network. The server judges whether the role of this user can access this device. If the judgment passes, the server issues a string of authorization codes to the user's mobile device. The user fills the authorization code back into the device. After the device verifies the authorization code, it confirms the login and the user obtains the access permission. This solves the problem that using static passwords for offline device access control is not secure, authorizes the user role in real time and can remove the user access permission from the background at any time, and is more flexible, efficient and secure for the use verification of the device.
[0099] Figure 5FIG. 0 is a schematic structural diagram of an access verification device for an offline device provided by an embodiment of the present invention. The access verification device 500 for the offline device may vary greatly due to different configurations or performances, and may include one or more central processing units (CPUs) 510 (for example, one or more processors) and a memory 520, and one or more storage media 530 (for example, one or more mass storage devices) storing application programs 533 or data 532. Among them, the memory 520 and the storage media 530 may be transient storage or persistent storage. The program stored in the storage media 530 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the access verification device 500 for the offline device. Further, the processor 510 may be configured to communicate with the storage media 530 and execute a series of instruction operations in the storage media 530 on the access verification device 500 for the offline device.
[0100] Based on the access verification device 500 for the offline device may further include one or more power supplies 540, one or more wired or wireless network interfaces 550, one or more input / output interfaces 560, and / or, one or more operating systems 531, such as Windows Server, Mac OS X, Unix, Linux, FreeBSD, and so on. Those skilled in the art can understand that Figure 5 The shown structural diagram of the access verification device for the offline device does not constitute a limitation on the access verification device for the offline device, and may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0101] The present invention also provides a computer-readable storage medium. The computer-readable storage medium may be a non-volatile computer-readable storage medium, or may also be a volatile computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When the instructions run on a computer, the computer is caused to execute the steps of the access verification method for the offline device.
[0102] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0103] Moreover, although the operations are depicted in a particular order, this should be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed to achieve the desired result. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, although several specific implementation details are included in the above discussion, these should not be construed as limitations on the scope of the present disclosure. Certain features described in the context of separate embodiments can also be implemented in combination in a single implementation. Conversely, various features described in the context of a single implementation can also be implemented separately or in any suitable sub-combination in multiple implementations.
[0104] Although the subject matter has been described in language specific to structural features and / or methodological acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims.
Claims
1. An access verification method for an offline device, characterized in that: The access verification method of the offline device is applied to the access verification system of the offline device, and the access verification system of the offline device includes: a device control system, an intelligent code scanning system, and a cloud service system. The access verification method of the offline device includes: The device control system receives an externally injected USB key based on a USB interface; Determine whether the USB key is a qualified key; If it is a qualified key, the login QR code will be displayed on the preset device interface; The intelligent code scanning system scans the login QR code, obtains a device token based on the login QR code, activates and displays a login interface based on the login QR code, and receives a personal token input by a user into the login interface; Sending the device token and the personal token to the cloud service system; The cloud service system receives the device token and the personal token, and determines whether the personal token exists in a preset configuration database; If it exists in the configuration database, query the feature authorization code corresponding to the combination of the personal token and the device token, and send the feature authorization code to the smart code scanning system; The device control system receives a feature authorization code input from outside and analyzes whether the feature authorization code is a valid authorization code; When it is a valid authorization code, the device access permission is activated.
2. The access verification method for an offline device according to claim 1, characterized in that: The querying of the feature authorization code corresponding to the combination of the personal token and the device token includes: Using the personal token as a key identifier, retrieve a first value identifier in the configuration database; Using the device token as a key identifier, retrieve a second value identifier from the first value identifier; The second value identifier is confirmed as a feature authorization code.
3. The access verification method for an offline device according to claim 1, characterized in that: The USB key includes: a USB device unique identification serial number and a key string, and the step of determining whether the USB key is a qualified key includes: Determine whether the USB device unique identification serial number is registered in the preset device database; When it is not registered in the preset device database, the USB key unqualified data is displayed on the preset device interface; When registering in the preset device database, the pairing public key corresponding to the unique identification serial number of the USB device is queried from the device database; Decrypting the key string according to the paired public key to obtain decrypted data; Determine whether the decrypted data is legal data.
4. The access verification method for an offline device according to claim 1, characterized in that: After querying the feature authorization code corresponding to the combination of the personal token and the device token, and sending the feature authorization code to the smart code scanning system, the method includes: The intelligent code scanning system receives the feature authorization code and generates an authorization QR code based on the feature authorization code.
5. The access verification method for an offline device according to claim 4, characterized in that: The device control system is connected to a camera lens, and the device control system receives a feature authorization code input from outside, including: The device control system scans the authorization QR code through the camera lens and obtains a feature authorization code based on the authorization QR code.
6. The access verification method for an offline device according to claim 1, characterized in that: After determining whether the personal token exists in the preset configuration database, the method further includes: When it does not exist in the preset configuration database, a login verification failure message is sent to the intelligent code scanning system.
7. The access verification method for an offline device according to claim 1, characterized in that: The analyzing whether the feature authorization code is a valid authorization code comprises: Determine whether the feature authorization code exists in the preset authorization registration table; If it exists in the preset authorization registration table, the feature authorization code is confirmed to be a valid authorization code; When it does not exist in the preset authorization registration table, it is confirmed that the feature authorization code is not a valid authorization code.
8. The access verification method for an offline device according to claim 1, characterized in that: The device control system receiving the external input feature authorization code also includes: Based on the Bluetooth protocol, the device control system receives the feature authorization code transmitted from the smart code scanning system.
9. An access verification device for an offline device, characterized in that: The access verification device of the offline device comprises: a memory and at least one processor, the memory stores instructions, and the memory and the at least one processor are interconnected via a line; The at least one processor calls the instruction in the memory to enable the access verification device of the offline device to execute the access verification method for the offline device according to any one of claims 1 to 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the access verification method for an offline device according to any one of claims 1 to 8 is implemented.