Access authentication method, system, equipment and medium

By adopting one device-one key authentication method in IoT device access authentication, the problem of low security in the prior art is solved, and the uniqueness and high security connection of each device are achieved.

CN120200769APending Publication Date: 2025-06-24GUANGDONG ESHORE TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311787063.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-22
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The existing IoT device access authentication method has the problem of low security, which is easily guessed or enumerated to crack, and the authentication method with the same key preset is easily cracked by hackers in batches.

Method used

Using an access authentication method based on one device and one key, the authentication platform receives a key application request for the Internet of Things device, verifies the legitimacy of the unique ID identification, and generates a device-unique key. The device-only key is used to establish a secure connection channel between the IoT platform and the IoT device.

Benefits of technology

By using a different key for authentication for each device, the problem of different devices having a unique and unique trusted root is solved, which significantly improves security and prevents the risk of forgery device attacks and keys being cracked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200769A_ABST
    Figure CN120200769A_ABST
Patent Text Reader

Abstract

The invention provides an access authentication method, system and device and a medium, and the access authentication method comprises the steps that an authentication platform receives a key application request sent by an Internet of Things device, determines a unique ID identifier according to the key application request, and verifies the legality of the unique ID identifier; under the condition that the unique ID identifier is legal, the authentication platform generates an equipment unique key according to the unique ID identifier, and returns the equipment unique key to the Internet of Things equipment; the authentication platform receives a verification request sent by the Internet of Things equipment, and verifies verification information carried by the verification request and a message source of the verification request; and the authentication platform returns a communication connection key to the Internet of Things platform and the Internet of Things equipment under the condition of successful verification, wherein the communication connection key is used for establishing a secure connection channel between the Internet of Things platform and the Internet of Things equipment. According to the invention, each device is authenticated by using different key encryption device identifiers, so that the authentication security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of the Internet of Things, and particularly to an access authentication method based on one device one key. Background Art

[0002] With the rapid growth of the Internet of Things (IoT) device market, device security incidents occur frequently, and security issues such as privacy leakage and illegal device intrusion have become obstacles to development. IoT device access authentication is a key link in IoT services, including the authentication of IoT devices by the IoT service platform and the authentication of the IoT service platform by IoT devices. If the authentication of IoT devices is insufficient, security risks such as device forgery, imitation, and malicious control may occur, and illegal IoT devices may access and attack the IoT service platform or other IoT devices, causing greater security incidents and bringing economic or reputational losses to enterprises and users.

[0003] Device access is the basis for the IoT platform to play its role. Before a device accesses the IoT platform, it needs to pass device identity authentication. There are the following two common implementation forms of device identity authentication:

[0004] 1. Simple authentication based on device identifiers such as MAC and device serial numbers. This authentication method only covers the one-way authentication of the platform to the device, and has extremely low security, and is easily cracked in batches by means such as guessing and enumeration.

[0005] 2. Authentication based on one type one key. Some IoT device manufacturers pre-set the same platform symmetric key or platform public key in all factory-produced devices, and use the pre-set key to encrypt and transmit device identifiers such as MAC and SN. After decryption on the service platform side, the device identifier is obtained and verified, and the platform completes the authentication of the device identity. The platform returns an encrypted authentication result, and the IoT device receives and decrypts the authentication result to complete the entire two-way authentication process. Since all devices pre-set the same key, hackers can obtain the platform key by cracking one device, and then crack other devices in batches. Summary of the Invention

[0006] An embodiment of the present invention provides an access authentication method to solve the problems existing in the related art. The technical solution is as follows:

[0007] In a first aspect, an embodiment of the present invention provides an access authentication method, including:

[0008] The authentication platform receives a key application request sent by an IoT device, determines a unique ID identifier according to the key application request, and verifies the legality of the unique ID identifier;

[0009] When the unique ID identifier is legal, the authentication platform generates a device unique key based on the unique ID identifier and returns the device unique key to the Internet of Things device;

[0010] The authentication platform receives the verification request sent by the Internet of Things device and verifies the verification information carried by the verification request and the message source of the verification request;

[0011] When the verification is successful, the authentication platform returns the communication connection key to the Internet of Things platform and the Internet of Things device. The communication connection key is used to establish a secure connection channel between the Internet of Things platform and the Internet of Things device.

[0012] In one implementation, the method for verifying legality is:

[0013] Determine whether the unique ID identifier exists in the pre-stored device identifier list, and the device ID batch-synchronized by the Internet of Things platform is recorded in the device identifier list;

[0014] When the unique ID identifier exists in the device identifier list, the unique ID identifier is legal.

[0015] In one implementation, the method for generating the verification request is:

[0016] When the Internet of Things device is in the state of online activation or use, verification information is generated based on the device unique key, and the verification information includes a device verification code;

[0017] The Internet of Things device generates a verification request according to the verification information, sends the verification request to the Internet of Things platform for device trust verification, and the Internet of Things platform forwards the verification request to the authentication platform for verification.

[0018] In one implementation, the method for verifying the verification information is:

[0019] The authentication platform generates a verification key in real time according to the Internet of Things device information and the Internet of Things device production line information, verifies the verification information according to the verification key, and obtains a verification result.

[0020] In one implementation, it further includes:

[0021] The authentication platform returns the verification result and the communication connection key to the Internet of Things platform. The Internet of Things platform records the device verification success result and saves the communication connection key, and returns the verification result and the communication connection key to the Internet of Things device. The Internet of Things device retains the communication connection key.

[0022] In one implementation, it further includes:

[0023] The authentication platform receives the device authentication credential and verifies whether the Internet of Things device has the access right according to the device authentication credential; wherein, the device authentication credential is generated by decrypting the device key preset by the built-in security chip of the Internet of Things device;

[0024] In the case of passing the authentication, the authentication platform generates an encrypted working key and returns it to the Internet of Things device, decrypts the working key based on the decrypted device key, and completes the device security authentication.

[0025] In a second aspect, an embodiment of the present invention provides an access authentication system that executes the access authentication method as described above.

[0026] In a third aspect, an embodiment of the present invention provides an electronic device, which includes: a memory and a processor. Wherein, the memory and the processor communicate with each other through an internal connection path, the memory is used to store instructions, the processor is used to execute the instructions stored in the memory, and when the processor executes the instructions stored in the memory, the processor is caused to execute the method in any one of the above aspects.

[0027] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program. When the computer program runs on a computer, the method in any one of the above aspects is executed.

[0028] The advantages or beneficial effects in the above technical solutions at least include:

[0029] The present invention proposes an access authentication method based on one device one key, allowing each device to use a different key to encrypt the device identifier for authentication. This authentication method solves the problem of different devices having a unique and trusted root, and has high security.

[0030] The above summary is only for the purpose of the specification and is not intended to be limiting in any way. In addition to the above-described illustrative aspects, embodiments, and features, further aspects, embodiments, and features of the present invention will be readily apparent by reference to the drawings and the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In the drawings, unless otherwise specified, the same reference numerals throughout the several views denote the same or similar components or elements. These drawings are not necessarily drawn to scale. It should be understood that these drawings only depict some embodiments disclosed according to the present invention and should not be regarded as limiting the scope of the present invention.

[0032] Figure 1 It is a schematic flowchart of the access authentication method implemented by the authentication platform, the Internet of Things platform, and the Internet of Things device of the present invention;

[0033] Figure 2 Schematic diagram of the security authentication process of the present invention through a preset key

[0034] Figure 3 Block diagram of the structure of an electronic device according to an embodiment of the present invention Detailed implementation manners

[0035] In the following, only some exemplary embodiments are simply described. As those skilled in the art can recognize, the described embodiments can be modified in various different ways without departing from the spirit or scope of the present invention. Therefore, the drawings and the description are regarded as exemplary in nature rather than restrictive

[0036] Embodiment 1

[0037] This embodiment provides an access authentication method, which belongs to a security authentication method and can improve the security of device security authentication and solve the problem that different devices have a unique and trusted root

[0038] Among them, the access authentication method is mainly implemented through the interaction of three parts: an authentication platform, an Internet of Things platform, and Internet of Things devices; the security authentication method executed by the authentication platform in this embodiment includes the following steps

[0039] Step S1: The authentication platform receives a key application request sent by an Internet of Things device, determines a unique ID identifier according to the key application request, and verifies the legality of the unique ID identifier

[0040] Step S2: When the unique ID identifier is legal, the authentication platform generates a device unique key according to the unique ID identifier and returns the device unique key to the Internet of Things device

[0041] Step S3: The authentication platform receives a verification request sent by the Internet of Things device and verifies the verification information carried in the verification request and the message source of the verification request

[0042] Step S4: When the verification is successful, the authentication platform returns a communication connection key to the Internet of Things platform and the Internet of Things device, and the communication connection key is used to establish a secure connection channel between the Internet of Things platform and the Internet of Things device

[0043] Reference Figure 1 As shown, in the production stage of the Internet of Things device production line, first, the authentication platform adds a whitelist of the Internet of Things device production line network, and the Internet of Things platform synchronizes the unique ID identifiers of the Internet of Things devices to the authentication platform in batches. The synchronized batch of unique ID identifiers forms a device identifier list

[0044] When the Internet of Things device applies for the device unique key to the authentication platform with its unique ID identifier, the authentication platform can verify the legitimacy of the request of the Internet of Things device. The Internet of Things device applies for the device unique key to the authentication platform with the unique ID identifier and encrypts the request using the authentication platform key; the authentication platform first verifies whether the source of the request is trustworthy and decrypts the encrypted request using the platform key of the authentication platform to verify the manufacturer information and the source; after the source verification is successful, the authentication platform checks whether the device unique ID identifier exists in the device identifier list. If the unique ID identifier exists in the device identifier list, the unique ID identifier is legal; if the unique ID identifier does not exist in the device identifier list, it means that the Internet of Things device sending the request is illegal, and the subsequent authentication process will no longer continue.

[0045] After the authentication platform successfully verifies the request sent by the Internet of Things device, it generates the device unique key for the physical network device and returns it to the Internet of Things device. At this time, the authentication platform does not save the device unique key.

[0046] When the Internet of Things device is in the online activation or usage stage, verification information is generated based on the device unique key. This verification information can be a device verification code, and the verification information is carried and sent to the Internet of Things platform for device trust verification. Device trust verification is to verify whether the Internet of Things device is a trusted device. The Internet of Things platform pre-records the unique ID identifiers of trusted Internet of Things devices and can determine whether the Internet of Things device is a trusted device by identifying the unique ID identifier.

[0047] Subsequently, the Internet of Things platform forwards the verification request carrying the device verification code to the authentication platform for verification. The authentication platform verifies based on the Internet of Things platform source information and the device verification code. The verification key required for verification is generated in real time by the hardware encryption machine based on the Internet of Things device information and the Internet of Things device production line information (manufacturer information). The verification information is verified according to the verification key to obtain the verification result.

[0048] The device verification code can be set as a one-time verification code and becomes invalid after being verified by the authentication platform.

[0049] After the verification is successful, the authentication platform returns the verification success information and the communication connection key to the Internet of Things platform. The Internet of Things platform records the device verification success result according to the verification success information, saves the communication connection key, and returns the verification success result and the communication connection key to the Internet of Things device.

[0050] At the same time, after the Internet of Things platform performs device trust verification, if the verification is successful, it returns the verification success result to the Internet of Things device, realizes the authentication of the Internet of Things device to the Internet of Things platform and retains the communication connection key, and finally establishes a secure connection channel between the Internet of Things device and the Internet of Things platform through the communication connection key.

[0051] In some embodiments, a security authentication SDK is installed and deployed on the IoT device. The security authentication SDK implements device security authentication and secure distribution of working keys through the above-mentioned one-device-one-key. The SDK is provided to the IoT device in the form of a linked library file to achieve installation and deployment on the IoT device.

[0052] In some embodiments, the IoT device may also be built with a security chip. The security chip is burned with keys, and the key burning operation is implemented based on the production line key burning component, that is, the production line key burning component is provided to the device manufacturer. As a part of the device production line, the key is directly burned into the device during the production process without passing through any third party to ensure the security of the burning process.

[0053] For encrypted burning of the device key, the device key issued by the key distribution center is burned into the security chip after being encrypted by the root key, ensuring that even if an attacker reads the device key, it cannot be used.

[0054] Based on the security chip as a carrier, secure storage of the key is achieved. The key is encrypted by the security chip and stored in the hardware, realizing physical and logical isolation from the IoT device, and the data cannot be stolen.

[0055] Reference Figure 2 As shown, the device security authentication process can also be implemented through the following method:

[0056] The security chip can be pre-burned with keys, decrypt the keys to generate a device authentication credential. The device authentication credential is used to determine whether the IoT device has the right to access. The device authentication credential is transmitted to the IoT platform, and the IoT platform sends the device authentication credential and the working key to the authentication platform. The authentication platform verifies whether the IoT device has the right to access according to the device authentication credential; among them, the device authentication credential is generated by decrypting the device key preset by the security chip built in the IoT device;

[0057] In the case of passing the device authentication, the authentication platform generates an encrypted working key and returns it to the IoT device. The IoT device decrypts the working key based on the decrypted device key to complete device security authentication.

[0058] The method of this embodiment can help the IoT device achieve the ability of two-way identity authentication between the device and the IoT platform and establish a secure channel, effectively preventing attack means such as forged device attacks, device key cracking, forged server instructions, eavesdropping or tampering with key information, and stealing keys through device production line security vulnerabilities.

[0059] Embodiment Two

[0060] This embodiment provides an access authentication system that executes the access authentication method as in Embodiment One. The system includes:

[0061] A legality verification module, configured to receive a key application request sent by an Internet of Things device, determine a unique ID identifier according to the key application request, and verify the legality of the unique ID identifier;

[0062] A key generation module, configured to generate a device unique key according to the unique ID identifier when the unique ID identifier is legal, and return the device unique key to the Internet of Things device;

[0063] A request verification module, configured to receive a verification request sent by an Internet of Things device, and verify the verification information carried in the verification request and the message source of the verification request;

[0064] A channel connection module, configured to return a communication connection key to the Internet of Things platform and the Internet of Things device when the verification is successful, and establish a secure connection channel between the Internet of Things platform and the Internet of Things device according to the communication connection key.

[0065] This embodiment proposes an access authentication system based on one device one key, which allows each device to use a different key to encrypt the device identifier for authentication. This authentication method solves the problem that different devices have a unique and trusted root, and has high security.

[0066] The functions of the modules in the system of the embodiment of the present invention can refer to the corresponding descriptions in the above method, and will not be elaborated here.

[0067] Embodiment Three

[0068] Figure 3 The structural block diagram of an electronic device according to an embodiment of the present invention is shown. As Figure 3 shown, the electronic device includes: a memory 100 and a processor 200, and a computer program that can run on the processor 200 is stored in the memory 100. When the processor 200 executes the computer program, the access authentication method in the above embodiment is implemented. The number of the memory 100 and the processor 200 can be one or more.

[0069] The electronic device further includes:

[0070] A communication interface 300, configured to communicate with external devices and perform data interaction and transmission.

[0071] If the memory 100, the processor 200, and the communication interface 300 are implemented independently, the memory 100, the processor 200, and the communication interface 300 can be interconnected through a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 3 only a thick line is used to represent it in Figure 3 , but it does not mean that there is only one bus or one type of bus.

[0072] Optionally, in specific implementation, if the memory 100, the processor 200, and the communication interface 300 are integrated on a single chip, the memory 100, the processor 200, and the communication interface 300 can communicate with each other through an internal interface.

[0073] An embodiment of the present invention provides a computer-readable storage medium storing a computer program, which when executed by a processor implements the method provided in the embodiment of the present invention.

[0074] An embodiment of the present invention further provides a chip, which includes a processor for calling and running an instruction stored in a memory, so that a communication device installed with the chip executes the method provided in the embodiment of the present invention.

[0075] An embodiment of the present invention further provides a chip, including: an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected through an internal connection path. The processor is configured to execute code in the memory, and when the code is executed, the processor is configured to execute the method provided in the embodiment of the invention.

[0076] It should be understood that the above-mentioned processor may be a Central Processing Unit (CPU), or it may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor that supports the advanced RISC machines (ARM) architecture.

[0077] Further, optionally, the above-mentioned memory may include a read-only memory and a random access memory, and may also include a non-volatile random access memory. The memory may be a volatile memory or a non-volatile memory, or may include both a volatile and a non-volatile memory. Among them, the non-volatile memory may include a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may include a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available. For example, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0078] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium.

[0079] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0080] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" can explicitly or implicitly include at least one of the features. In the description of the present invention, "a plurality" means two or more unless otherwise specifically defined.

[0081] Any process or method description shown in the flowchart or described in other ways herein can be understood as representing a module, segment, or part of code including one or more executable instructions for implementing a specific logical function or process. And the scope of the preferred embodiments of the present invention includes additional implementations, where the functions can be executed in a substantially simultaneous manner or in the reverse order according to the functions involved, rather than in the order shown or discussed.

[0082] The logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a sequenced list of executable instructions for implementing a logical function, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or in combination with these instruction execution systems, apparatuses, or devices.

[0083] It should be understood that each part of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. All or part of the steps of the method in the above embodiments can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.

[0084] In addition, each functional unit in various embodiments of the present invention can be integrated into a processing module, or each unit can exist physically alone, or two or more units can be integrated into one module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. When the above integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. The storage medium can be a read-only memory, a magnetic disk or an optical disc, etc.

[0085] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various changes or substitutions, and these should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. An access authentication method, characterized in that, Including: The authentication platform receives a key application request sent by the Internet of Things device, determines a unique ID identifier according to the key application request, and verifies the legality of the unique ID identifier; When the unique ID identifier is legal, the authentication platform generates a device unique key according to the unique ID identifier and returns the device unique key to the Internet of Things device; The authentication platform receives the verification request sent by the Internet of Things device, and verifies the verification information carried in the verification request and the message source of the verification request; When the verification is successful, the authentication platform returns a communication connection key to the Internet of Things platform and the Internet of Things device, and the communication connection key is used to establish a secure connection channel between the Internet of Things platform and the Internet of Things device.

2. The access authentication method according to claim 1, wherein The method for verifying the legality is: Judge whether the unique ID identifier exists in the pre-stored device identifier list, and the device ID batch-synchronized by the Internet of Things platform is recorded in the device identifier list; When the unique ID identifier exists in the device identifier list, the unique ID identifier has the legality.

3. The access authentication method according to claim 1, wherein The method for generating the verification request is: When the Internet of Things device is in the state of online activation or use, verification information is generated based on the device unique key, and the verification information includes a device verification code; The Internet of Things device generates the verification request according to the verification information, sends the verification request to the Internet of Things platform for device trust verification, and the Internet of Things platform forwards the verification request to the authentication platform for verification.

4. The access authentication method according to claim 1, wherein The method for verifying the verification information is: The authentication platform generates a verification key in real time according to the Internet of Things device information and the Internet of Things device production line information, and verifies the verification information according to the verification key to obtain a verification result.

5. The access authentication method according to claim 4, wherein Also including: The authentication platform returns the verification result and the communication connection key to the Internet of Things platform, the Internet of Things platform records the device verification success result and saves the communication connection key, and returns the verification result and the communication connection key to the Internet of Things device, and the Internet of Things device retains the communication connection key.

6. The access authentication method according to claim 1, characterized in that Also including: The authentication platform receives a device authentication credential, and verifies whether the Internet of Things device has access rights according to the device authentication credential; wherein, the device authentication credential is generated by decrypting a device key preset by a built-in security chip of the Internet of Things device; When the authentication is passed, the authentication platform generates an encrypted working key and returns it to the Internet of Things device, and decrypts the working key based on the decrypted device key to complete device security authentication.

7. An access authentication system, characterized in that, Execute the access authentication method according to any one of claims 1 to 6.

8. An electronic device, characterized in that, Including: A processor and a memory, instructions are stored in the memory, and the instructions are loaded and executed by the processor to implement the access authentication method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the access authentication method according to any one of claims 1 to 6 is implemented.