Business processing method and device, electronic equipment and storage medium

By generating signature information, assisting IOT devices in obtaining business certificates, it solves the problem of security management of IOT devices in the Internet of Things and improves the reliability and security of service request processing.

CN120238291APending Publication Date: 2025-07-01BEIJING X RING TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311868354.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

In the Internet of Things, how to implement security management of IoT devices to improve business security and manufacturer competitiveness, especially security verification during data exchange between devices.

Method used

The first device receives a security evaluation request, generates a security evaluation report based on the configuration information of the second device, and generates signature information using the private key to assist the second device in obtaining a service certificate, so as to realize security verification of the IOT device.

Benefits of technology

Improve the reliability and security of service request processing to ensure the security verification of IOT devices when requesting services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238291A_ABST
    Figure CN120238291A_ABST
Patent Text Reader

Abstract

The invention provides a service processing method and device, electronic equipment and a storage medium, and relates to the technical field of communication. Comprising the following steps: receiving a security assessment request sent by a second device or a server, the security assessment request comprising an identifier of the second device to be assessed; determining a current security assessment report of the second equipment based on the current configuration information of the second equipment; generating second signature information based on the identifier of the second device, the security evaluation report, the current timestamp and the private key of the first device; the second signature information is sent to the second device or the server, and the second signature information is used for assisting the second device in obtaining the service certificate. Therefore, in the Internet of Things, the security of the IOT equipment requesting the service can be further verified, and the reliability and security of service request processing are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the fields of information security and Internet of Things technology, and particularly to a service processing method, apparatus, electronic device, and storage medium. Background Art

[0002] The Internet of Things (IOT) is an information carrier based on the Internet, traditional telecommunication networks, etc., enabling all devices with IOT capabilities to form an interconnected network for data exchange between devices. However, as network security issues have drawn increasing attention, how to achieve secure management of IOT devices on the basis of the Internet of Things to reach the communication form of the Internet of Everything (IOE) has become the key to improving service security and the competitiveness of manufacturers. Summary of the Invention

[0003] The present disclosure aims to at least solve one of the technical problems in the related art to some extent.

[0004] A service processing method according to an embodiment of the first aspect of the present disclosure is executed by a first device and includes:

[0005] Receiving a security assessment request sent by a second device or a server, where the security assessment request includes an identifier of the second device to be evaluated;

[0006] Determining a current security assessment report of the second device based on the current configuration information of the second device;

[0007] Generating second signature information based on the identifier of the second device, the security assessment report, the current timestamp, and the private key of the first device;

[0008] Sending the second signature information to the second device or the server, where the second signature information is used to assist the second device in obtaining a service certificate.

[0009] A service processing method according to an embodiment of the second aspect of the present disclosure is executed by a second device and includes:

[0010] Generating first signature information based on the first private key of the second device and target service information to be executed;

[0011] Sending a service request to a server, where the service request includes the first signature information;

[0012] Upon receiving the service certificate returned by the server, execute the target service corresponding to the target service information, where the service certificate is generated by the server for the first signature information and the second signature information, and the second signature information is the signature information of a first device in the device group to which the second device belongs.

[0013] The third aspect of the present disclosure provides an embodiment of a service processing method, which is executed by a server and includes:

[0014] Receive a security assessment request sent by a first device, where the security assessment request includes an identifier of a second device to be evaluated, and the first device is a server or the second device;

[0015] When the target service corresponding to the target service information is a preset service, send a security assessment request to the first device, where the security assessment request includes the identifier of the second device, and the first device is a device in the device group to which the second device belongs;

[0016] Receive the second signature information returned by the first device.

[0017] The fourth aspect of the present disclosure provides an embodiment of a service processing device, which is configured in a first device and includes:

[0018] A receiving module, configured to receive a security assessment request sent by a second device or a server, where the security assessment request includes an identifier of a second device to be evaluated;

[0019] A determining module, configured to determine a current security assessment report of the second device based on the current configuration information of the second device;

[0020] A first generating module, configured to generate second signature information based on the identifier of the second device, the security assessment report, the current timestamp, and the private key of the first device;

[0021] A first sending module, configured to send the second signature information to the second device or the server, where the second signature information is used to assist the second device in obtaining a service certificate.

[0022] The fifth aspect of the present disclosure provides an embodiment of a service processing device, which is configured in a second device and includes:

[0023] A second generating module, configured to generate first signature information based on the first private key of the second device and the target service information to be executed;

[0024] A second sending module, configured to send a service request to a server, where the service request includes the first signature information;

[0025] An execution module, configured to execute a target service corresponding to the target service information when receiving a service certificate returned by the server, where the service certificate is generated by the server for the first signature information and the second signature information, and the second signature information is the signature information of a first device in a device group to which the second device belongs.

[0026] An embodiment of the sixth aspect of the present disclosure provides a service processing device, configured in a server, including:

[0027] An acquisition module, configured to acquire first signature information, second signature information, and an identifier of a target service based on a service request sent by a second device, where the first signature information is the signature information of the second device, and the second signature information is the signature information of a first device in a device group to which the second device belongs;

[0028] A verification module, configured to verify the first signature information and the second signature information respectively based on a first public key of the second device, a second public key of the first device, and a security policy associated with the identifier of the target service;

[0029] A third sending module, configured to return a service certificate associated with the identifier of the target service to the second device when both the first signature information and the second signature information pass the verification.

[0030] An embodiment of the seventh aspect of the present disclosure provides an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the program, it implements the service processing method provided in the embodiments of the first, second, and third aspects of the present disclosure.

[0031] An embodiment of the eighth aspect of the present disclosure provides a service processing system, including a first device, a second device, and a server, where the first device is configured to implement the service processing method provided in the embodiment of the first aspect of the present disclosure, the second device is configured to implement the service processing method provided in the embodiment of the second aspect of the present disclosure, and the server is configured to implement the service processing method provided in the embodiment of the third aspect of the present disclosure.

[0032] An embodiment of the ninth aspect of the present disclosure provides a computer-readable storage medium, storing a computer program, where when the computer program is executed by a processor, it implements the service processing method provided in the embodiments of the first, second, and third aspects of the present disclosure.

[0033] The service processing method, device, electronic device, and storage medium provided by the present disclosure have the following beneficial effects:

[0034] In the embodiments of the present disclosure, a security assessment report related to the second device is generated based on the configuration information of the second device, and then signature information of the first device is generated based on information such as the security assessment report, assisting the second device in obtaining a service certificate, so that when an IOT device requests a service, the security of the IOT device can be further verified, improving the reliability and security of service request processing.

[0035] Additional aspects and advantages of the present disclosure will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] The above and / or additional aspects and advantages of the present disclosure will become apparent and be readily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0037] Figure 1 is a schematic diagram of the architecture composed of the device and the server provided by the present disclosure;

[0038] Figure 2 is a schematic flowchart of a service processing method provided by an embodiment of the present disclosure;

[0039] Figure 3 is a schematic flowchart of a service processing method provided by another embodiment of the present disclosure;

[0040] Figure 4 is a schematic flowchart of a service processing method provided by another embodiment of the present disclosure;

[0041] Figure 5 is a schematic diagram of signaling interaction of a service processing method provided by an embodiment of the present disclosure;

[0042] Figure 6 is a schematic diagram of signaling interaction of a service processing method provided by another embodiment of the present disclosure;

[0043] Figure 7 is a schematic diagram of the structure of a service processing apparatus provided by an embodiment of the present disclosure;

[0044] Figure 8 is a schematic diagram of the structure of a service processing apparatus provided by another embodiment of the present disclosure;

[0045] Figure 9 is a schematic diagram of the structure of a service processing apparatus provided by another embodiment of the present disclosure;

[0046] Figure 10 shows a block diagram of an exemplary electronic device suitable for implementing the embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0047] Embodiments of the present disclosure will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to explain the present disclosure, and should not be construed as a limitation of the present disclosure.

[0048] The service processing method, device, electronic device, and storage medium according to the embodiments of the present disclosure will be described below with reference to the accompanying drawings.

[0049] In the embodiments of the present disclosure, the service processing method is exemplified by being configured in a service processing device. The service processing device can be applied to any electronic device so that the electronic device can perform functions such as data interaction, data processing, and information verification during the service processing.

[0050] The service processing method proposed in the present disclosure is implemented by signaling interaction among a cloud server, a first device, and a second device. The second device can communicate with the first device and the server through a network.

[0051] The following will be combined with Figure 1 to schematically illustrate the organizational structure among the first device, the second device, and the server. Figure 1 The master device in Figure 1 is the first device, and IOT device 1, ……, IOT device k are the second devices. As

[0052] shown, the first device can establish connection relationships with multiple second devices to form an interconnected device group. In the device group, the first device can monitor and control the second devices by issuing certificates. Different users can each correspond to a device group and perform services by communicating with the cloud server.

[0053] The service processing method proposed by the present disclosure is that the first device first receives a security assessment request sent by the second device or the server, then determines the current security assessment report of the second device based on the current configuration information of the second device, and then generates a second signature information based on the identifier of the second device, the security assessment report, the current timestamp, and the private key of the first device, and sends the second signature information to the second device or the server. Thus, by generating a security assessment report related to the second device based on the configuration information of the second device, and then generating the signature information of the first device based on information such as the security assessment report, it assists the second device in obtaining a service certificate, so that when an IOT device requests a service, the security of the IOT device can be further verified, improving the reliability and security of service request processing.

[0054] Figure 2 It is a schematic flowchart of a service processing method provided by an embodiment of the present disclosure.

[0055] As Figure 2 shown, this service processing method is executed by the first device and may include the following steps:

[0056] Step 201, receive a security assessment request sent by the second device or the server.

[0057] Among them, the security assessment request contains the identifier of the second device to be evaluated, which is used to instruct the first device to check the security characteristics and health status of the second device within the device group to which it belongs.

[0058] Step 202, determine the current security assessment report of the second device based on the current configuration information of the second device.

[0059] Among them, the current configuration information of the second device may include information such as whether the second device supports secure boot, whether it supports debug card control shutdown, whether the second device obtains root user privileges, whether the second device supports trustzone, and the code currently executed by the second device. The present disclosure does not limit this. The security assessment report is the inspection result generated after checking the security characteristics and health status of the second device.

[0060] In an embodiment of the present disclosure, the first device obtains the current configuration information from the second device according to the identifier of the second device to be evaluated included in the received security assessment request. Then, it can compare the current configuration information with the original configuration information stored in the first device to generate the current security assessment report of the second device. For example, the security assessment report may include information indicating that the second device supports secure boot and the closing of the debug card control, determining that the security of the second device is relatively high; or, when the code currently executed by the second device is different from the original execution code of the second device stored in the first device, information such as the tampering of the execution code of the second device may be included in the security assessment report. The present disclosure does not limit this.

[0061] Optionally, when the first device does not include the original configuration information of the second device, it can receive a registration request sent by the second device, where the registration request includes the configuration information of the second device.

[0062] It should be noted that when the configuration information of the second device is updated, the second device can actively synchronize the updated configuration information to the first device, or the first device can also send a configuration information synchronization instruction to the second device as needed to obtain the latest configuration information. The present disclosure does not limit this.

[0063] Step 203: Generate second signature information based on the identifier of the second device, the security assessment report, the current timestamp, and the private key of the first device.

[0064] In an embodiment of the present disclosure, the first device can first calculate the digest value of the identifier of the second device, the security assessment report, and the current timestamp, and then sign the digest value using the private key of the first device to obtain the second signature information.

[0065] Step 204: Send the second signature information to the second device or the server.

[0066] Among them, the second signature information is used to assist the second device in obtaining a service certificate.

[0067] In an embodiment of the present disclosure, the first device first receives a security assessment request sent by the second device or the server, then determines the current security assessment report of the second device based on the current configuration information of the second device, and then generates second signature information based on the identifier of the second device, the security assessment report, the current timestamp, and the private key of the first device, and sends the second signature information to the second device or the server. Thus, by generating a security assessment report related to the second device based on the configuration information of the second device, and then generating the signature information of the first device based on information such as the security assessment report, to assist the second device in obtaining a service certificate, it is possible to further verify the security of the IOT device when the IOT device requests a service, improving the reliability and security of service request processing.

[0068] Figure 3 A schematic flowchart of a service processing method provided by another embodiment of the present disclosure is shown as Figure 3 shown. The service processing method is executed by a second device and may include the following steps:

[0069] Step 301: Generate first signature information based on the first private key of the second device and the target service information to be executed.

[0070] In an embodiment of the present disclosure, the second device may first calculate a digest value of the target service information to be executed using an algorithm (such as a hash algorithm, a Message Authentication Code (MAC) algorithm, etc.), and then sign the digest value with the first private key to generate the first signature information.

[0071] It should be noted that the signature algorithm used may be an Elliptic Curve Digital Signature Algorithm (ECDSA), a public key cryptography algorithm RSA (Rivest Shamir Adleman), etc. The present disclosure does not limit the algorithm used.

[0072] Step 302: Send a service request to the server, where the service request includes the first signature information.

[0073] In an embodiment of the present disclosure, after generating the first signature information, the second device may directly send a service request to the server based on the first signature information. Alternatively, according to the security requirements of the target request service of the second device, the second device may also obtain the second signature information of the first device in the device group where the second device is located and send it to the server together with the first signature information to facilitate the server to further verify the security of the service request.

[0074] Optionally, when the target service corresponding to the target service information is a preset service, a security assessment request may be sent to the first device, and then the second signature information returned by the first device is received.

[0075] The security assessment request includes the identifier of the second device, and the first device is a device in the device group to which the second device belongs.

[0076] In the present disclosure, a preset service refers to a service with high security requirements determined based on service maintenance policies, etc. The service requires the signature information of the first device to further verify the security of the second device that requests the service during the request, and can be determined in advance according to various service requirements related to the server.

[0077] In an embodiment of the present disclosure, before the second device sends a service request to the server, it may first query a preset service table according to the target service. When the target service corresponding to the target service information is a preset service, the second device requests the first device to perform a security assessment on the second device to obtain second signature information related to the second device generated by the first device.

[0078] Optionally, since the first device needs to judge the security characteristics and health status of the second device based on the configuration information of the second device when performing a security assessment on the second device. Therefore, before sending a security assessment request to the first device, the second device may send a registration request to the first device, where the registration request includes the configuration information of the second device.

[0079] In addition, the configuration information may include information such as whether the second device supports secure boot, whether it supports debug card control shutdown, whether the second device obtains root permission, whether the second device supports trustzone, and the code executed by the second device. The present disclosure does not limit this.

[0080] Step 303, when receiving the service certificate returned by the server, perform the target service corresponding to the target service information.

[0081] The service certificate is generated by the server for the first signature information and the second signature information.

[0082] It should be noted that due to the timeliness of verification, the service certificate usually has a certain expiration date. When the service certificate expires, the current service certificate will become invalid, and the second device needs to send a request to the server again to update the service certificate in order to continue to perform the service.

[0083] In an embodiment of the present disclosure, the second device first generates first signature information based on the first private key of the second device and the target service information to be executed, then sends a service request to the server, and when receiving the service certificate returned by the server, performs the target service corresponding to the target service information. Thus, by obtaining the service certificate returned after the server passes the verification through the signature information generated based on the private key and the target service information to perform the target service, the reliability of service request processing can be improved, and the security of the second device performing the service can be enhanced.

[0084] Figure 4 It is a schematic flowchart of a service processing method provided by another embodiment of the present disclosure.

[0085] As Figure 4 shown, when the service processing method is executed in the server, it may include the following steps:

[0086] Step 401: Based on the service request sent by the second device, obtain the first signature information, the second signature information, and the identifier of the target service.

[0087] Among them, the first signature information is the signature information of the second device, and the second signature information is the signature information of the first device in the device group to which the second device belongs.

[0088] It should be noted that when the service request contains the first signature information, the second signature information, and the identifier of the target service, the server can directly extract the first signature information, the second signature information, and the identifier of the target service from the service request. Alternatively, the service request may only include the first signature information and the identifier of the target service, then the server needs to determine whether to obtain the second signature information from the first device according to the identifier of the target service.

[0089] Optionally, the service request sent by the second device can be parsed to obtain the first signature information, the second signature information, and the identifier of the target service included in the service request.

[0090] In the embodiments of the present disclosure, the service request can be generated according to a certain format and convention. Therefore, the server can extract the first signature information, the second signature information, and the identifier of the target service included in the service request by parsing the service request.

[0091] Optionally, the service request sent by the second device can be parsed to obtain the first signature information and the identifier of the target service included in the service request, and then when the identifier of the target service is a preset identifier, a security assessment request is sent to the first device in the device group to which the second device belongs, and then the second signature information sent by the first device is received.

[0092] Among them, the security assessment request contains the identifier of the second device. The preset identifier refers to the identifier corresponding to a service with high security requirements determined by the service maintenance policy of the server.

[0093] In the embodiments of the present disclosure, after parsing the received service request, when it is determined that the service request only contains the first signature information and the identifier of the target service, the server can determine whether to verify the signature information of the first device in the device group to which the second device belongs during the process of processing the service request based on the identifier of the target service to ensure high security of service processing. Therefore, the preset identifier table can be queried based on the identifier of the target service, and when the identifier of the target service is a preset identifier, a request is sent to the first device to perform a security assessment on the second device to obtain the second signature information related to the second device generated by the first device.

[0094] It can be understood that when the target service identifier is not the preset identifier, it indicates that the security requirements for the target service requested by the second device are relatively low. In this case, the server may not obtain the second signature information of the first device and only needs to verify the first signature information.

[0095] Step 402: Based on the first public key of the second device, the second public key of the first device, and the security policy associated with the identifier of the target service, verify the first signature information and the second signature information respectively.

[0096] It should be noted that the service request may also include the certificates of the second device and the first device. The server can obtain the first public key of the second device and the second public key of the first device respectively based on the certificates.

[0097] In the embodiments of the present disclosure, the server can use the first public key to decrypt the first signature information. When the decrypted message is consistent with the target service message in the service request, it is determined that the verification of the first signature information passes. Use the second public key to decrypt the second signature information. When the decrypted message is consistent with the received original security assessment report information, it is determined that the verification of the second signature information passes. And, according to the security policy associated with the identifier of the target service, it can also be checked whether the second device meets the security requirements of the service. When the security requirements are met, it is determined that the security verification of the second device passes.

[0098] It should be noted that the server can simultaneously verify the first signature information and the second signature information using the first public key, the second public key, and the security policy respectively. Or the verification process can also be completed step by step. When the current verification item passes, the next verification is carried out. The present disclosure does not make any limitations in this regard.

[0099] Optionally, the second signature information can be verified first based on the second public key. Then, when the verification of the second signature information passes, according to the security policy, the security characteristics of the second device included in the second signature information are verified. After that, when the verification of the security characteristics of the second device passes, the first signature information is verified based on the first public key. Thus, during the information verification process, when the verification of any step fails, the verification operation can be terminated in a timely manner to avoid resource waste caused by invalid verification and make the verification process more efficient.

[0100] Optionally, when at least one of the first signature information and the second signature information fails the verification, a service failure request message can be returned to the second device.

[0101] Step 403: When both the first signature information and the second signature information pass the verification, return the service certificate associated with the identifier of the target service to the second device.

[0102] In the embodiments of the present disclosure, when both the first signature information and the second signature information pass the verification, the server may consider that the target service request sent by the second device is legal, and the security of the second device executing the target service is relatively high. Then, the server can return the service certificate associated with the identifier of the target service to the second device, forming a secure and effective certificate chain between the server and the second device. The second device can execute the target service based on the service certificate, ensuring the security of service implementation.

[0103] In the embodiments of the present disclosure, the server first obtains the first signature information, the second signature information, and the identifier of the target service based on the service request sent by the second device. Then, the server respectively verifies the first signature information and the second signature information based on the first public key of the second device, the second public key of the first device, and the security policy associated with the identifier of the target service. After both the first signature information and the second signature information pass the verification, the server returns the service certificate associated with the identifier of the target service to the second device. Thus, based on the verification results of the signature information of the second device requesting the service and the signature information of the first device in the device group to which the second device belongs, issuing a service certificate to the second device that passes the verification can improve the rigor and reliability of service certificate issuance, implement the control of IoT devices in service access, and improve the security of service execution in IoT devices.

[0104] Figure 5 is a signaling interaction schematic diagram of a service processing method provided by an embodiment of the present disclosure; as Figure 5 shown, the service processing method may include the following steps:

[0105] Step 501, the second device generates first signature information based on the first private key and the target service information to be executed.

[0106] Step 502, when the target service corresponding to the target service information is a preset service, send a security assessment request to the first device. The security assessment request includes the identifier of the second device.

[0107] Step 503, the first device determines the current security assessment report of the second device based on the current configuration information of the second device.

[0108] Step 504, generate second signature information based on the identifier of the second device, the security assessment report, the current timestamp, and the private key of the first device.

[0109] Step 505, send the second signature information to the second device.

[0110] Step 506, after receiving the second signature information, the second device sends a service request to the server. The service request includes the first signature information, the second signature information, and the identifier of the target service.

[0111] Step 507: The server parses the service request to obtain the first signature information, the second signature information, and the identifier of the target service included in the service request.

[0112] Step 508: Based on the first public key of the second device, the second public key of the first device, and the security policy associated with the identifier of the target service, the server verifies the first signature information and the second signature information respectively.

[0113] Step 509: When both the first signature information and the second signature information pass the verification, the server returns the service certificate associated with the identifier of the target service to the second device.

[0114] Step 510: The second device executes the target service corresponding to the target service information.

[0115] In the embodiments of the present disclosure, the second device first generates the first signature information and obtains the second signature information of the first device in the device group to which it belongs. Then, the second device sends a service request containing the first signature information and the second signature information to the server. The server uses the public key to verify the signature information. When the verification passes, the server issues a service certificate to the second device to allow the second device to execute the target service. Thus, dual control of the service request by the master device and the server is achieved, making the service processing more reliable, improving the security of service execution, and further ensuring the integrity and credibility of the communication data of IOT devices.

[0116] Figure 6 FIG. is a signaling interaction diagram of a service processing method provided by an embodiment of the present disclosure; as Figure 6 shown, the service processing method may include the following steps:

[0117] Step 601: The second device generates the first signature information based on the first private key and the target service information to be executed.

[0118] Step 602: The second device sends a service request to the server. The service request includes the first signature information and the identifier of the target service.

[0119] Step 603: The server parses the service request to obtain the first signature information and the identifier of the target service.

[0120] Step 604: When the identifier of the target service is a preset identifier, the server sends a security assessment request to the first device in the device group to which the second device belongs.

[0121] The security assessment request includes the identifier of the second device.

[0122] Step 605, the first device determines the current security assessment report of the second device based on the current configuration information of the second device.

[0123] Step 606, generate the second signature information based on the identifier of the second device, the security assessment report, the current timestamp, and the private key of the first device.

[0124] Step 607, send the second signature information to the server.

[0125] Step 608, the server verifies the first signature information and the second signature information respectively based on the first public key of the second device, the second public key of the first device, and the security policy associated with the identifier of the target service.

[0126] Step 609, when both the first signature information and the second signature information pass the verification, return the service certificate associated with the identifier of the target service to the second device.

[0127] Step 610, the second device executes the target service corresponding to the target service information.

[0128] In the embodiments of the present disclosure, the second device first sends a service request containing the first signature information to the server. The server obtains the second signature information sent by the first device of the device group to which the second device belongs according to the identifier of the target service in the service request, and then uses the public key to verify the signature information. When the verification passes, the server issues a service certificate to the second device to allow the second device to execute the target service. Thus, through a business processing flow different from Figure 5 the above, the dual control of the service request by the master device and the server can be realized, making the service processing more reliable, improving the security of service execution, and further ensuring the integrity and credibility of the communication data of the IOT device.

[0129] To implement the above embodiments, the present disclosure also proposes a service processing apparatus.

[0130] Figure 7 It is a schematic structural diagram of the service processing apparatus provided by an embodiment of the present disclosure. As Figure 7 shown, the service processing apparatus 700 is configured at the first device end and may include:

[0131] A receiving module 701, configured to receive a security assessment request sent by the second device or the server, where the security assessment request includes the identifier of the second device to be evaluated;

[0132] A determining module 702, configured to determine the current security assessment report of the second device based on the current configuration information of the second device;

[0133] The first generation module 703 is configured to generate second signature information based on the identifier of the second device, the security assessment report, the current timestamp, and the private key of the first device;

[0134] The first sending module 704 is configured to send the second signature information to the second device or the server, where the second signature information is used to assist the second device in obtaining a service certificate.

[0135] In some embodiments, the determination module 702 is further configured to:

[0136] Receive a registration request sent by the second device, where the registration request includes the configuration information of the second device.

[0137] In some embodiments, the first generation module 703 is specifically configured to:

[0138] Calculate a digest value based on the identifier of the second device, the security assessment report, and the current timestamp;

[0139] Sign the digest value based on the private key of the first device to obtain the second signature information.

[0140] For the functions and specific implementation principles of the above-mentioned modules in the embodiments of the present disclosure, reference may be made to the above-mentioned method embodiments, and details are not described herein again.

[0141] The first device in the embodiments of the present disclosure first receives a security assessment request sent by the second device or the server, then determines the current security assessment report of the second device based on the current configuration information of the second device, and then generates second signature information based on the identifier of the second device, the security assessment report, the current timestamp, and the private key of the first device, and sends the second signature information to the second device or the server. Thus, by generating a security assessment report related to the second device based on the configuration information of the second device, and then generating the signature information of the first device based on information such as the security assessment report, to assist the second device in obtaining a service certificate, it is possible to further verify the security of the IOT device when the IOT device requests a service, improving the reliability and security of service request processing.

[0142] Figure 8 It is a schematic structural diagram of a service processing apparatus provided by an embodiment of the present disclosure. As Figure 8 shown, the service processing apparatus 800 is configured at the second device end and may include:

[0143] The second generation module 801 is configured to generate first signature information based on the first private key of the second device and the target service information to be executed;

[0144] The second sending module 802 is configured to send a service request to the server, where the service request includes the first signature information;

[0145] An execution module 803, configured to execute a target service corresponding to target service information when receiving a service certificate returned by a server, where the service certificate is generated by the server for the first signature information and the second signature information, and the second signature information is the signature information of a first device in a device group to which the second device belongs.

[0146] In some embodiments, the second sending module 802 is further configured to:

[0147] When the target service corresponding to the target service information is a preset service, send a security assessment request to the first device, where the security assessment request includes an identifier of the second device, and the first device is a device in a device group to which the second device belongs;

[0148] Receive the second signature information returned by the first device.

[0149] In some embodiments, the second sending module 802 is further configured to:

[0150] Send a registration request to the first device, where the registration request includes configuration information of the second device

[0151] For the functions and specific implementation principles of the above modules in the embodiments of the present disclosure, reference may be made to the above method embodiments, and details are not described herein again.

[0152] In the second device in the embodiments of the present disclosure, first, based on the first private key of the second device and the target service information to be executed, generate first signature information, then send a service request to the server, and when receiving the service certificate returned by the server, execute the target service corresponding to the target service information. Thus, by using the signature information generated based on the private key and the target service information to obtain the service certificate returned after passing the server verification to execute the target service, the reliability of service request processing can be improved, and the security of the IOT device executing the service can be improved.

[0153] Figure 9 It is a schematic structural diagram of a service processing device provided by an embodiment of the present disclosure. As Figure 9 shown, the service processing device 900 is configured on the server side and may include:

[0154] An acquisition module 901, configured to acquire first signature information, second signature information, and an identifier of a target service based on a service request sent by a second device, where the first signature information is the signature information of the second device, and the second signature information is the signature information of a first device in a device group to which the second device belongs;

[0155] A verification module 902 is configured to verify the first signature information and the second signature information respectively based on the first public key of the second device, the second public key of the first device, and the security policy associated with the identifier of the target service.

[0156] A third sending module 903 is configured to, when both the first signature information and the second signature information pass the verification, return a service certificate associated with the identifier of the target service to the second device.

[0157] In some embodiments, the obtaining module 901 is specifically configured to:

[0158] Parse the service request sent by the second device to obtain the first signature information, the second signature information, and the identifier of the target service included in the service request.

[0159] In some embodiments, the obtaining module 901 is specifically configured to:

[0160] Parse the service request sent by the second device to obtain the first signature information and the identifier of the target service included in the service request.

[0161] When the identifier of the target service is a preset identifier, send a security assessment request to the first device in the device group to which the second device belongs, where the security assessment request includes the identifier of the second device.

[0162] Receive the second signature information sent by the first device.

[0163] In some embodiments, the verification module 902 is specifically configured to:

[0164] Verify the second signature information based on the second public key.

[0165] When the second signature information passes the verification, verify the security characteristics of the second device included in the second signature information according to the security policy.

[0166] When the security characteristics of the second device pass the verification, verify the first signature information based on the first public key.

[0167] In some embodiments, the verification module 902 is further configured to:

[0168] When at least one of the first signature information and the second signature information fails to pass the verification, return a service failure request message to the second device.

[0169] For the functions and specific implementation principles of the above modules in the embodiments of the present disclosure, reference may be made to the above method embodiments, and details are not described herein again.

[0170] The server in the embodiments of the present disclosure first obtains the first signature information, the second signature information, and the identifier of the target service based on the service request sent by the second device, and then respectively verifies the first signature information and the second signature information based on the first public key of the second device, the second public key of the first device, and the security policy associated with the identifier of the target service. After that, when both the first signature information and the second signature information pass the verification, the server returns the service certificate associated with the identifier of the target service to the second device. Thus, based on the verification results of the signature information of the second device requesting the service and the signature information of the first device in the device group to which the second device belongs, issuing a service certificate to the second device that passes the verification can improve the rigor and reliability of the issuance of the service certificate, realize the control of IOT devices in service access, and improve the security of service execution in IOT devices.

[0171] To implement the above embodiments, the present disclosure also proposes an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the service processing method proposed in the foregoing embodiments of the present disclosure.

[0172] To implement the above embodiments, the present disclosure also proposes a service processing system, including a first device, a second device, and a server. Among them, the first device, the second device, and the server are respectively configured to implement the service processing methods proposed in the foregoing embodiments of the present disclosure.

[0173] To implement the above embodiments, the present disclosure also proposes a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the service processing method proposed in the foregoing embodiments of the present disclosure.

[0174] Figure 10 A block diagram of an exemplary electronic device suitable for implementing the embodiments of the present disclosure is shown. Figure 10 The illustrated electronic device 1000 is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.

[0175] As Figure 10 shown, the electronic device 1000 is presented in the form of a general-purpose computing device. The components of the electronic device 1000 may include, but are not limited to: one or more processors or processing units 16, a system memory 28, and a bus 18 connecting different system components (including the system memory 28 and the processing unit 16).

[0176] Bus 18 represents one or more of several types of bus architectures, including a memory bus or memory controller, a peripheral bus, an Accelerated Graphics Port, a processor bus, or a local bus using any of the various bus architectures. By way of example, such architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnection (PCI) bus.

[0177] Electronic device 1000 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by electronic device 1000, including volatile and nonvolatile media, removable and non-removable media.

[0178] Memory 28 can include computer system readable media in the form of volatile memory, such as Random Access Memory (RAM) 30 and / or cache memory 32. Electronic device 1000 may further include other removable / non-removable, volatile / nonvolatile computer system storage media. By way of example only, storage system 34 can be used for reading and writing on non-removable, nonvolatile magnetic media ( Figure 10 not shown and typically called a "hard disk drive"). Although Figure 10 not shown in the figure, a disk drive for reading and writing on a removable nonvolatile disk (such as a "floppy disk") and an optical disk drive for reading and writing on a removable nonvolatile optical disk (such as Compact Disc Read Only Memory (CD-ROM), Digital Video Disc Read Only Memory (DVD-ROM), or other optical media) can be provided. In these cases, each drive can be connected to bus 18 through one or more data media interfaces. Memory 28 can include at least one program product having a set (e.g., at least one) of program modules that are configured to perform the functions of the various embodiments of the present disclosure.

[0179] A program / utilities 40 having a set (at least one) of program modules 42 can be stored, for example, in a memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. The program modules 42 generally execute the functions and / or methods in the embodiments described in this disclosure.

[0180] The electronic device 1000 can also communicate with one or more external devices 14 (such as a keyboard, a pointing device, a display 24, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 1000, and / or communicate with any device that enables the electronic device 1000 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through an input / output (I / O) interface 22. Moreover, the electronic device 900 can also communicate with one or more networks (such as a Local Area Network (LAN), a Wide Area Network (WAN), and / or a public network, such as the Internet) through a network adapter 20. As shown in the figure, the network adapter 20 communicates with other modules of the electronic device 900 through a bus 18. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 900, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0181] The processing unit 16 executes various functional applications and data processing by running programs stored in the system memory 28, such as implementing the methods mentioned in the foregoing embodiments.

[0182] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc., mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this disclosure. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0183] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In the description of the present disclosure, "a plurality of" means at least two, such as two, three, etc., unless otherwise specifically defined.

[0184] Any process or method description represented in a flowchart or otherwise described herein can be understood to represent a module, segment, or portion of code including one or more executable instructions for implementing a customized logical function or process. The scope of the preferred embodiments of the present disclosure includes additional implementations in which functions may be executed in a substantially simultaneous manner or in a reverse order according to the functions involved, rather than in the order shown or discussed, as should be understood by those skilled in the art to which the embodiments of the present disclosure pertain.

[0185] The logic and / or steps represented in a flowchart or otherwise described herein, for example, can be considered a sequenced list of executable instructions for implementing a logical function and can be embodied specifically in any computer-readable medium for use by or in connection with an instruction execution system, apparatus, or device, such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. More specific examples (non-exhaustive list) of the computer-readable medium include the following: an electrical connection portion having one or more wirings (electronic device), a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can even be paper or other suitable medium on which the program can be printed, as the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpretation, or otherwise appropriate processing if necessary, and then storing it in a computer memory.

[0186] It should be understood that various parts of the present disclosure can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, any one of the following techniques known in the art or a combination thereof can be used: discrete logic circuits with logic gate circuits for implementing logical functions on data signals, application specific integrated circuits with appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), and the like.

[0187] Those of ordinary skill in the art can understand that all or part of the steps carried by the methods of the above embodiments can be completed by instructing relevant hardware through a program. The said program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.

[0188] In addition, in each of the embodiments of the present disclosure, the functional units can be integrated into one processing module, or each unit can exist physically alone, or two or more units can be integrated into one module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. When the above integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0189] The above-mentioned storage medium can be a read-only memory, a magnetic disk, an optical disk, or the like. Although the embodiments of the present disclosure have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present disclosure. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present disclosure.

Claims

1. A service processing method, characterized in that, The method is executed by a first device, and the method includes: Receiving a security assessment request sent by a second device or a server, where the security assessment request contains an identifier of the second device to be evaluated; Determining a current security assessment report of the second device based on the current configuration information of the second device; Generating second signature information based on the identifier of the second device, the security assessment report, the current timestamp, and the private key of the first device; Sending the second signature information to the second device or the server, where the second signature information is used to assist the second device in obtaining a service certificate.

2. The method according to claim 3, wherein Before determining the current security assessment report of the second device based on the current configuration information of the second device, it further includes: Receiving a registration request sent by the second device, where the registration request includes the configuration information of the second device.

3. The method according to claim 1 or 2, characterized in that, The generating the second signature information based on the identifier of the second device, the security assessment report, the current timestamp, and the private key of the first device includes: Calculating a digest value based on the identifier of the second device, the security assessment report, and the current timestamp; Signing the digest value based on the private key of the first device to obtain the second signature information.

4. A service processing method, characterized in that The method is executed by a second device, and the method includes: Generating first signature information based on the first private key of the second device and target service information to be executed; Sending a service request to a server, where the service request includes the first signature information; Executing a target service corresponding to the target service information when receiving a service certificate returned by the server, where the service certificate is generated by the server for the first signature information and the second signature information, and the second signature information is the signature information of a first device in a device group to which the second device belongs.

5. The method according to claim 4, wherein The service request further includes the second signature information. Before sending the service request to the server, it further includes: When the target service corresponding to the target service information is a preset service, sending a security assessment request to a first device, where the security assessment request contains the identifier of the second device, and the first device is a device in the device group to which the second device belongs; Receiving the second signature information returned by the first device.

6. The method according to claim 5, wherein Before sending a request for obtaining the second signature information to the first device, it further includes: Sending a registration request to the first device, where the registration request includes the configuration information of the second device.

7. A service processing method, characterized in that, The method is executed by a server, and the method includes: Based on a service request sent by a second device, obtaining first signature information, second signature information, and an identifier of a target service, where the first signature information is the signature information of the second device, and the second signature information is the signature information of a first device in a device group to which the second device belongs; Respectively verifying the first signature information and the second signature information based on the first public key of the second device, the second public key of the first device, and a security policy associated with the identifier of the target service; When both the first signature information and the second signature information pass the verification, return the service certificate associated with the identifier of the target service to the second device.

8. The method according to claim 7, wherein The obtaining of the first signature information, the second signature information, and the identifier of the target service based on the service request sent by the second device includes: Parse the service request sent by the second device to obtain the first signature information, the second signature information, and the identifier of the target service included in the service request.

9. The method according to claim 7, wherein The obtaining of the first signature information, the second signature information, and the identifier of the target service based on the service request sent by the second device includes: Parse the service request sent by the second device to obtain the first signature information and the identifier of the target service included in the service request. When the identifier of the target service is a preset identifier, send a security assessment request to the first device in the device group to which the second device belongs, where the security assessment request includes the identifier of the second device. Receive the second signature information sent by the first device.

10. The method according to any one of claims 7-9, characterized in that, The verifying of the first signature information and the second signature information respectively based on the first public key of the second device, the second public key of the first device, and the security policy associated with the identifier of the target service includes: Verify the second signature information based on the second public key. When the second signature information passes the verification, verify the security characteristics of the second device included in the second signature information according to the security policy. When the security characteristics of the second device pass the verification, verify the first signature information based on the first public key.

11. The method according to claim 10, wherein, After verifying the first signature information and the second signature information, it further includes: When at least one of the first signature information and the second signature information fails to pass the verification, return a service failure request message to the second device.

12. A service processing device, characterized in that, The device is configured in the first device, and the device includes: A receiving module, configured to receive a security assessment request sent by the second device or the server, where the security assessment request includes the identifier of the second device to be evaluated. A determining module, configured to determine the current security assessment report of the second device based on the current configuration information of the second device. A first generating module, configured to generate second signature information based on the identifier of the second device, the security assessment report, the current timestamp, and the private key of the first device. A first sending module, configured to send the second signature information to the second device or the server, where the second signature information is used to assist the second device in obtaining a service certificate.

13. A service processing device, characterized in that, The device is configured in the second device, and the device includes: A second generating module, configured to generate first signature information based on the first private key of the second device and the target service information to be executed. A second sending module, configured to send a service request to the server, where the service request includes the first signature information. An execution module, configured to execute a target service corresponding to the target service information when receiving a service certificate returned by the server, where the service certificate is generated by the server for the first signature information and the second signature information, and the second signature information is the signature information of a first device in a device group to which the second device belongs.

14. A service processing device, characterized in that, The device is configured in a server, and the device includes: An acquisition module, configured to acquire first signature information, second signature information, and an identifier of a target service based on a service request sent by a second device, where the first signature information is the signature information of the second device, and the second signature information is the signature information of a first device in a device group to which the second device belongs; A verification module, configured to verify the first signature information and the second signature information respectively based on a first public key of the second device, a second public key of the first device, and a security policy associated with the identifier of the target service; A third sending module, configured to return a service certificate associated with the identifier of the target service to the second device when both the first signature information and the second signature information pass the verification.

15. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the service processing method according to any one of claims 1-11.

16. A service processing system, characterized in that, It includes a first device, a second device, and a server, where the first device is configured to implement the service processing method according to any one of claims 1-3, the second device is configured to implement the service processing method according to any one of claims 4-6, and the server is configured to implement the service processing method according to any one of claims 7-11.

17. A computer-readable storage medium stores a computer program, characterized in that, When the computer program is executed by the processor, it implements the service processing method according to any one of claims 1-11.