Authentication method and device of smart home equipment

By using the session key protocol and ECDH protocol in smart home devices, local identity authentication is realized, solving the complexity and cost problems caused by CA dependence in the prior art, and improving the efficiency and security of device authentication.

CN120301622APending Publication Date: 2025-07-11NINGBO FOTILE KITCHEN WARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510261196.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The prior art requires relying on CA (certificate authority) for identity authentication in smart home devices, resulting in complex and costly communication between devices, and it is impossible to achieve efficient and secure identity authentication locally.

Method used

By adopting the session key protocol in smart home devices, short-term identification is encrypted and decrypted between the main device and the auxiliary device, local identity authentication is realized, and shared keys are generated using the ECDH protocol to ensure secure communication between devices.

Benefits of technology

It improves the efficiency and security of device authentication, reduces the number of interactions when the device is reconnected, reduces the communication overhead, and ensures the reliability of identity authentication and fast connection between devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301622A_ABST
    Figure CN120301622A_ABST
Patent Text Reader

Abstract

The invention discloses a smart home device authentication method and device, and the method comprises the steps: obtaining a device matched with a target device carried by a connection instruction under the condition that a smart home device is in a power-on state and receives the connection instruction, and obtaining an auxiliary device; acquiring a locally stored short-term identifier matched with the auxiliary equipment, and encrypting the short-term identifier by using the first session key to obtain first ciphertext information; sending the first ciphertext information to the auxiliary device; sending the first ciphertext information to the auxiliary equipment, so that the auxiliary equipment decrypts the first ciphertext information by using the second session key to obtain a first decryption identifier; if the short-term identifier stored in the auxiliary equipment is matched with the first decryption identifier, the auxiliary equipment determines that the authentication with the main equipment is successful, and sends an authentication passing message to the main equipment; and sending the control instruction to the auxiliary equipment. According to the invention, identity authentication of local communication equipment is realized, and the efficiency and security of equipment authentication are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to an authentication method and device for smart home devices. Background Art

[0002] When devices communicate with each other, in order to avoid attacks caused by identity forgery, identity authentication is performed after the connection is successful. The current mature identity authentication scheme requires a CA (Certificate Authority), which is an independent third-party agency that provides certificate issuance and verification services for each terminal node. When a new device accesses the network, the CA issues a certificate to the device. When authenticating the identity between devices, the certificate of the other party is taken to the CA for verification.

[0003] The prior art must have a CA in the entire system. And all nodes need to have the ability to communicate with the CA. If the nodes are for local communication, the CA in the form of a cloud server cannot be competent, and the CA must be deployed locally, which is complex and increases costs. Summary of the Invention

[0004] This application provides an authentication method and device for smart home devices, which can realize the identity authentication of devices for local communication and improve the efficiency and security of device authentication.

[0005] On the one hand, this application provides an authentication method for smart home devices, and the method includes:

[0006] When the smart home device is in the powered-on state and receives a connection instruction, obtain a device that matches the target device carried in the connection instruction to obtain an auxiliary device; the target device is a smart home device that has been historically authenticated with the master device; the master device is a device among the smart home devices;

[0007] Obtain a short-term identifier stored locally that matches the auxiliary device, and use a first session key to encrypt the short-term identifier to obtain a first ciphertext message; the short-term identifier is an identifier generated by the auxiliary device and sent to the master device when the historical authentication is passed; the first session key is a key generated based on a target key protocol;

[0008] Send the first ciphertext message to the auxiliary device; so that the auxiliary device uses a second session key to decrypt the first ciphertext message to obtain a first decryption identifier; so that if the short-term identifier stored by the auxiliary device matches the first decryption identifier, the auxiliary device determines that the authentication with the master device is successful and sends an authentication passed message to the master device; the second session key is a key generated by the auxiliary device based on the target key protocol;

[0009] Send a control instruction to the auxiliary device.

[0010] On the other hand, an authentication method for a smart home device is provided. The method includes:

[0011] Receive the first ciphertext information sent by the master device; the first ciphertext information is the ciphertext information obtained by the master device by acquiring the short-term identifier stored locally and matching the auxiliary device, and encrypting the short-term identifier using the first session key; the short-term identifier is the identifier generated and sent to the master device when the historical authentication is passed; the first session key is the key generated by the master device based on the target key protocol; the auxiliary device is the device obtained by the master device when the smart home device is in the powered-on state and the master device receives a connection instruction, and matches the target device carried in the connection instruction; the target device is a smart home device that has been historically authenticated with the master device; the master device is a device in the smart home device;

[0012] Decrypt the first ciphertext information using the second session key to obtain a first decrypted identifier; the second session key is the key generated based on the target key protocol;

[0013] If the short-term identifier stored in the auxiliary device matches the first decrypted identifier, determine that the authentication with the master device is successful, and send an authentication passed message to the master device;

[0014] Receive the control instruction sent by the master device.

[0015] On the other hand, an authentication device for a smart home device is provided, which is applied to the master device. The device includes:

[0016] Auxiliary device determination module, configured to obtain a device that matches the target device carried in the connection instruction when the smart home device is in the powered-on state and receives a connection instruction, so as to obtain an auxiliary device; the target device is a smart home device that has been historically authenticated with the master device; the master device is a device in the smart home device;

[0017] First ciphertext information determination module, configured to acquire the short-term identifier stored locally and matching the auxiliary device, and encrypt the short-term identifier using the first session key to obtain the first ciphertext information; the short-term identifier is the identifier generated by the auxiliary device and sent to the master device when the historical authentication is passed; the first session key is the key generated based on the target key protocol;

[0018] A first ciphertext information sending module, configured to send the first ciphertext information to the auxiliary device, so that the auxiliary device decrypts the first ciphertext information by using a second session key to obtain a first decryption identifier, and so that if the short-term identifier stored in the auxiliary device matches the first decryption identifier, the auxiliary device determines successful authentication with the master device and sends an authentication passed message to the master device; the second session key is a key generated by the auxiliary device based on the target key protocol;

[0019] A control instruction sending module, configured to send a control instruction to the auxiliary device.

[0020] On the other hand, an authentication device for a smart home device is provided, which is applied to an auxiliary device. The device includes:

[0021] A first receiving module, configured to receive the first ciphertext information sent by the master device; the first ciphertext information is ciphertext information obtained by the master device acquiring a short-term identifier stored locally and matching the auxiliary device, and encrypting the short-term identifier by using a first session key; the short-term identifier is an identifier generated and sent to the master device in the case of successful historical authentication; the first session key is a key generated by the master device based on the target key protocol; the auxiliary device is a device matched with the target device carried in the connection instruction acquired by the master device when the smart home device is in a powered-on state and the master device receives the connection instruction; the target device is a smart home device that has been historically authenticated with the master device; the master device is a device in the smart home device;

[0022] A decryption module, configured to decrypt the first ciphertext information by using a second session key to obtain a first decryption identifier; the second session key is a key generated based on the target key protocol;

[0023] An authentication module, configured to determine successful authentication with the master device and send an authentication passed message to the master device if the short-term identifier stored in the auxiliary device matches the first decryption identifier;

[0024] A second receiving module, configured to receive the control instruction sent by the master device.

[0025] On the other hand, an electronic device is provided. The device includes a processor and a memory. At least one instruction or at least one program segment is stored in the memory. The at least one instruction or the at least one program segment is loaded and executed by the processor to perform the authentication method of the smart home device as described above.

[0026] On the other hand, a computer-readable storage medium is provided, in which at least one instruction or at least one program segment is stored, and the at least one instruction or at least one program segment is loaded and executed by a processor to implement the authentication method of the smart home device as described above.

[0027] On the other hand, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions so that the computer device executes to implement the authentication method of the smart home device as described above.

[0028] The authentication method and device for a smart home device provided by this application have the following technical effects:

[0029] When the smart home device is in a powered-on state and receives a connection instruction, this application obtains a device that matches the target device carried in the connection instruction to obtain an auxiliary device; the target device is a smart home device that has been historically authenticated with the master device; the master device is a device in the smart home device; obtains a short-term identifier that matches the auxiliary device and stored locally, and uses a first session key to encrypt the short-term identifier to obtain a first ciphertext message; the short-term identifier is an identifier generated by the auxiliary device and sent to the master device when the historical authentication is passed; the first session key is a key generated based on a target key protocol; sends the first ciphertext message to the auxiliary device; so that the auxiliary device uses a second session key to decrypt the first ciphertext message to obtain a first decryption identifier; so that if the short-term identifier stored in the auxiliary device matches the first decryption identifier, the auxiliary device determines that the authentication with the master device is successful and sends an authentication passed message to the master device; the second session key is a key generated by the auxiliary device based on the target key protocol; sends a control instruction to the auxiliary device. By obtaining the first ciphertext message sent by the master device by the auxiliary device, decrypting it to obtain a first decryption identifier, and confirming that the master device and the auxiliary device have achieved authentication when the short-term identifier stored in the auxiliary device matches the first decryption identifier. By using the short-term identifier, and the short-term identifier exists between devices that are continuously powered on and have been successfully authenticated, it can not only achieve identity authentication between locally communicating devices, but also improve the security and reliability of device authentication, significantly reduce the interaction times when the device reconnects, speed up the connection speed between devices, and reduce the communication overhead. Description of the Drawings

[0030] To more clearly illustrate the technical solutions and advantages in the embodiments of this specification or the prior art, the following will briefly introduce the attached drawings required for the description of the embodiments or the prior art. Obviously, the attached drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other attached drawings can be obtained based on these attached drawings.

[0031] Figure 1 It is a schematic diagram of an application environment provided by an embodiment of this specification;

[0032] Figure 2 It is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification;

[0033] Figure 3 It is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification;

[0034] Figure 4 It is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification;

[0035] Figure 5 It is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification;

[0036] Figure 6 It is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification;

[0037] Figure 7 It is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification;

[0038] Figure 8 It is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification;

[0039] Figure 9 It is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification;

[0040] Figure 10 It is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification;

[0041] Figure 11 It is a timing diagram of generating authentication information provided by an embodiment of this specification;

[0042] Figure 12 It is a timing diagram of an identity authentication process provided by an embodiment of this specification;

[0043] Figure 13It is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification;

[0044] Figure 14 It is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification;

[0045] Figure 15 It is a structural block diagram of an authentication device for a smart home device provided by an embodiment of this specification;

[0046] Figure 16 It is a structural block diagram of an authentication device for a smart home device provided by an embodiment of this specification;

[0047] Figure 17 It is a hardware structural block diagram of a server for an authentication method of a smart home device provided by an embodiment of this application; Detailed implementation manners

[0048] Next, the technical solutions in the embodiments of this specification will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this application.

[0049] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above accompanying drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order different from those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or server that includes a series of steps or units does not necessarily have to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0050] Please refer to Figure 1 , Figure 1 It is a schematic diagram of an application environment provided by an embodiment of this specification. As Figure 1 shown, this application environment may at least include a main device 101 and an auxiliary device 102.

[0051] Specifically, in the embodiments of this specification, the master device 101 may include an independently operating server, a distributed server, or a server cluster composed of multiple servers. It may also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The master device 101 may include a network communication unit, a processor, a memory, and so on. Specifically, the master device 101 may send control instructions to the auxiliary device 102.

[0052] Specifically, in the embodiments of this specification, the auxiliary device 102 may include an independently operating server, a distributed server, or a server cluster composed of multiple servers. It may also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The auxiliary device 102 may include a network communication unit, a processor, a memory, and so on. Specifically, the auxiliary device 102 may receive the control instructions sent by the master device 101.

[0053] The following introduces an authentication method for a smart home device of this application. Figure 2 It is a schematic flowchart of an authentication method for a smart home device provided by the embodiments of this specification. This specification provides the method operation steps as described in the embodiments or flowcharts, but based on routine or non-creative labor, there may be more or fewer operation steps. The step order listed in the embodiments is only one way among the execution orders of numerous steps and does not represent the only execution order. When the actual system or server product executes, it may be executed in the order of the method shown in the embodiments or the drawings or executed in parallel (for example, in an environment of parallel processors or multi-threaded processing). Specifically, as Figure 2 shown, the method may be applied to the control unit in the smart home device, and the method includes:

[0054] S201: When the smart home device is in the powered-on state and the master device in the smart home device receives a connection instruction, the master device obtains a device that matches the target device carried in the connection instruction to obtain an auxiliary device; the target device is a smart home device that has been historically authenticated with the master device.

[0055] In the embodiments of this specification, in the application scenario of smart home, and all smart home devices adopt Bluetooth Low Energy (BLE) technology. BLE is a short-range wireless communication technology suitable for the short-range communication requirements between devices. The master device is the device that initiates the connection and is the BLE host. Among them, the master device can be a range hood. When the master device receives a connection instruction sent by the controller, where the connection instruction is used to control the master device to connect to the target device, so the connection instruction carries the target device that needs to be connected to the master device. Since the master device can be connected to multiple auxiliary devices to control the operation of different auxiliary devices, the master device needs to search for the target device carried by the connection instruction among the devices that have been historically authenticated with it, thereby obtaining the auxiliary device, which is the BLE slave. The auxiliary device can be a stove, a steam oven, or other auxiliary devices that can be controlled by the range hood. By automatically identifying the required historically authenticated auxiliary device based on the connection instruction by the master device, the operation process is simplified, enabling the devices for local communication to achieve identity authentication and enhancing the security of device authentication.

[0056] In the embodiments of this specification, when the smart home device is in the powered-on state and the master device in the smart home device receives a connection instruction, the master device obtains a device that matches the target device carried by the connection instruction to obtain the auxiliary device, including:

[0057] When the smart home device is in the powered-on state and the master device in the smart home device receives the connection instruction, the master device obtains the target device identifier carried by the connection instruction;

[0058] In the embodiments of this specification, since a master device can be connected to multiple auxiliary devices, a device identification library is stored in the master device, and each device identifier corresponds to an auxiliary device that has been historically authenticated with the master device. When the smart home device is in the powered-on state and the master device receives a connection instruction, it can be seen that after the master device and the auxiliary device are paired and disconnected, the short-term identifiers in the two devices do not disappear. Therefore, the host needs to first obtain the target device identifier carried by the connection instruction to obtain the auxiliary device that needs to be connected subsequently, so as to complete device authentication and connection.

[0059] The master device queries a preset device that matches the target device identifier in the device identification library to obtain the auxiliary device; the device identification library includes the mapping relationship between the preset device identifier and the preset device.

[0060] In the embodiments of this specification, the master device finds an auxiliary device in the identification device library that matches the target device identification, so as to initiate a connection request to the auxiliary device subsequently. By automatically identifying the device to be connected based on the connection instruction by the master device, the operation process is simplified, the risk of illegal device access is reduced, and multi-device linkage is achieved.

[0061] In the embodiments of this specification, before obtaining an auxiliary device by obtaining a device that matches the target device carried in the connection instruction when the smart home device is in the powered-on state and receives the connection instruction, as Figure 3 shown, Figure 3 is a schematic flow chart of an authentication method for a smart home device provided by an embodiment of this specification, and the method further includes:

[0062] S301: The master device generates a historical short-term identifier and a historical long-term identifier, and obtains a first hardware address corresponding to the auxiliary device.

[0063] In the embodiments of this specification, when the master device and the auxiliary device are paired for the first time, the master device generates quick authentication information, that is, a historical short-term identifier, and authentication information, that is, a historical long-term identifier, and obtains the hardware MAC address of the auxiliary device, that is, the first hardware address. By generating the historical short-term identifier and the historical long-term identifier, it is convenient to generate authentication information with the auxiliary device subsequently, and by obtaining the MAC address of the auxiliary device, it helps to pair the master device and the auxiliary device, improving the security of device authentication.

[0064] In the embodiments of this specification, before the master device generates a historical short-term identifier and a historical long-term identifier and obtains a first hardware address corresponding to the auxiliary device, as Figure 4 shown, Figure 4 is a schematic flow chart of an authentication method for a smart home device provided by an embodiment of this specification, and the method further includes:

[0065] S401: The master device sends an initial device pairing request to the auxiliary device.

[0066] In the embodiments of this specification, the master device sends an initial device pairing request to the auxiliary device, requesting to start the generation of a session key and authentication information. By initializing the communication between devices, the authentication information generation process is started.

[0067] S402: The auxiliary device sends a pairing feedback result to the master device.

[0068] In the embodiments of this specification, the auxiliary device agrees or refuses according to its own situation and sends a pairing feedback result to the master device, so that the master device formulates different strategies for different feedback results.

[0069] S403: If the pairing feedback result indicates that the auxiliary device agrees to pair with the master device, the master device generates the first session key according to the target key protocol and sends a first notification message to the auxiliary device; the first notification message indicates that the first session key has been generated.

[0070] In the embodiments of this specification, the target key protocol may be the ECDH protocol. The ECDH protocol is a key negotiation protocol used to securely generate shared keys in an insecure channel and is commonly used for the communication parties to negotiate and generate end-to-end encrypted session keys. When the auxiliary device agrees to the initial device pairing request of the master device, the master device generates a public key PB_Key_A corresponding to the master device and a private key PV_Key_A corresponding to the master device based on the ECDH key negotiation mechanism, and sends the public key PB_Key_A to the auxiliary device. At the same time, the master device receives the public key PB_Key_B corresponding to the auxiliary device sent by the auxiliary device. Subsequently, based on the ECDH protocol, the master device calculates the first session key using its own private key PV_Key_A and the public key PB_Key_B sent by the auxiliary device, and the master device deletes all the stored public keys and private keys. After the calculation of the first session key is completed, the master device sends a first notification message to the auxiliary device to ensure that the auxiliary device knows that the first session key has been calculated.

[0071] S404: The auxiliary device generates the second session key according to the target key protocol and sends a second notification message to the master device; the second notification message indicates that the second session key has been generated.

[0072] In the embodiments of this specification, the auxiliary device generates a public key PB_Key_B corresponding to the auxiliary device and a private key PV_Key_B corresponding to the auxiliary device based on the ECDH protocol, and sends the public key PB_Key_B to the master device. At the same time, the auxiliary device receives the public key PB_Key_A corresponding to the master device sent by the master device. Subsequently, based on the ECDH protocol, the auxiliary device calculates the second session key using its own private key PV_Key_B and the public key PB_Key_A sent by the master device, and the auxiliary device deletes all the stored public keys and private keys. After the calculation of the second session key is completed, the auxiliary device sends a second notification message to the master device to ensure that the master device knows that the second session key has been calculated. Through the ECDH key exchange protocol, the master device and the auxiliary device can securely negotiate and establish a shared session key on an insecure channel. At the same time, both parties delete unnecessary public keys and private keys to protect privacy, ensuring the confidentiality and security of subsequent communications, not only preventing third-party eavesdropping but also providing an encryption basis for the subsequent data transmission.

[0073] S302: The master device encrypts the historical short-term identifier, the historical long-term identifier, and the first hardware address using the first session key to obtain encrypted information.

[0074] In the embodiments of this specification, the master device encrypts the historical short-term identifier, the historical long-term identifier, and the first hardware address using the first session key to obtain encrypted information for subsequent transmission to the auxiliary device. Among them, both the historical short-term identifier and the historical long-term identifier are a string of numbers or texts randomly generated by the master device, and their lengths can be customized, which helps to implement the identity authentication between the master device and the auxiliary device.

[0075] S303: The master device sends the encrypted information to the auxiliary device.

[0076] In the embodiments of this specification, Device A sends the encrypted historical short-term identifier, historical long-term identifier, and the first hardware address to the auxiliary device. The auxiliary device obtains all the information required to generate the authentication information, including the hardware MAC address for identity verification, so that the auxiliary device can perform identity verification and generate the authentication information between the master device and the auxiliary device subsequently.

[0077] S304: The auxiliary device decrypts the historical short-term identifier in the encrypted information using the second session key to obtain a second decrypted identifier.

[0078] In the embodiments of this specification, after the auxiliary device decrypts to obtain the second decrypted identifier, it waits for the decryption result of the subsequent auxiliary device and then confirms whether the second decrypted identifier is valid, improving the security and reliability of device authentication.

[0079] S305: The auxiliary device decrypts the historical long-term identifier in the encrypted information using the second session key to obtain a third decrypted identifier.

[0080] In the embodiments of this specification, after the auxiliary device decrypts to obtain the third decrypted identifier, it waits for the decryption result of the subsequent auxiliary device and then confirms whether the third decrypted identifier is valid.

[0081] S306: The auxiliary device decrypts the first hardware address in the encrypted information using the second session key to obtain a decrypted hardware address.

[0082] In the embodiments of this specification, after the auxiliary device decrypts to obtain the decrypted hardware address, it uses the decrypted hardware address for identity authentication, improving the security of device identity authentication.

[0083] S307: The auxiliary device obtains a second hardware address corresponding to the auxiliary device, and performs a matching process on the decrypted hardware address and the second hardware address to obtain a hardware address matching result.

[0084] In the embodiments of this specification, the auxiliary device matches the decrypted hardware address and the second hardware address to obtain a hardware address matching result, which characterizes the identity authentication result between the master device and the auxiliary device. By the master device generating and sending a historical short-term identifier, a historical long-term identifier, and a first hardware address to the auxiliary device, and the auxiliary device decrypting this information using a second session key and verifying its integrity, the identity of the auxiliary device and the legality of the communication are ensured, and at the same time, a foundation is laid for subsequent fast identity authentication and control operations.

[0085] In the embodiments of this specification, after the auxiliary device obtains a second hardware address corresponding to the auxiliary device and performs a matching process on the decrypted hardware address and the second hardware address to obtain a hardware address matching result, as Figure 5 shown, Figure 5 is a schematic flowchart of an authentication method for a smart home device provided by the embodiments of this specification. The method further includes:

[0086] S501: If the hardware address matching result indicates that the decrypted hardware address is the same as the second hardware address, the auxiliary device sends a decryption success message to the master device.

[0087] In the embodiments of this specification, since the decrypted hardware address is the address obtained by the auxiliary device decrypting the encrypted hardware address of the auxiliary device sent by the master device, if the decrypted hardware address is the same as the second hardware address, it can be determined that the identity authentication of the auxiliary device is passed, and the auxiliary device sends a decryption success message to the master device to notify the master device that the key availability verification is passed.

[0088] S502: The master device stores the historical short-term identifier in a first volatile memory corresponding to the master device, and stores the historical long-term identifier in a first non-volatile memory corresponding to the master device.

[0089] In the embodiments of this specification, the first volatile memory is the RAM corresponding to the master device, and the first non-volatile memory is the Flash corresponding to the master device. Storing the historical short-term identifier in the RAM corresponding to the master device helps subsequent rapid authentication and realizes the identity authentication between the master device and the auxiliary device. Storing the historical long-term identifier and the first session secret key in the Flash corresponding to the master device, and after storing in the Flash, a certain method can be used for encryption again, or the secure area provided by the chip can be used for storage, preventing the attacker from directly reading the data in the Flash to obtain the first session secret key and the historical long-term identifier, which helps to realize the mutual authentication between the master device and the auxiliary device subsequently, and improves the reliability and security of device authentication.

[0090] S503: The auxiliary device stores the historical short-term identifier in the second volatile memory corresponding to the auxiliary device, and stores the historical long-term identifier in the second non-volatile memory corresponding to the auxiliary device.

[0091] In the embodiments of this specification, the second volatile memory is the RAM corresponding to the auxiliary device, and the second non-volatile memory is the Flash corresponding to the auxiliary device. Storing the historical short-term identifier in the RAM corresponding to the auxiliary device, and storing the historical long-term identifier and the second session secret key in the Flash corresponding to the auxiliary device. After storing in the Flash, a certain method can be used for encryption again, or the secure area provided by the chip can be used for storage, preventing the attacker from directly reading the data in the Flash to obtain the second session secret key and the historical long-term identifier. By using the target secret key protocol for encryption and decryption of the historical short-term identifier, the historical long-term identifier, and the hardware address of the auxiliary device, the integrity and non-repudiation of data transmission between the master device and the auxiliary device are ensured, and at the same time, the security status of both parties is updated, providing a guarantee for maintaining a long-term secure session and preventing replay attacks.

[0092] In the embodiments of this specification, the auxiliary device obtains the second hardware address corresponding to the auxiliary device, and performs a matching process on the decrypted hardware address and the second hardware address. After obtaining the hardware address matching result, as Figure 6 shown, Figure 6 is a schematic flowchart of an authentication method for a smart home device provided by the embodiments of this specification. The method further includes:

[0093] S601: If the hardware address matching result indicates that the decrypted hardware address is different from the second hardware address, the auxiliary device sends a decryption failure message to the master device.

[0094] In the embodiments of this specification, the decryption hardware address is different from the second hardware address. At this time, it can be determined that the authentication of the auxiliary device fails, and the auxiliary device sends a decryption failure message to the master device to notify the master device that the key availability verification fails.

[0095] S602: Based on the decryption failure message, the master device obtains the current authentication times between the master device and the auxiliary device.

[0096] In the embodiments of this specification, the auxiliary device attempts to recount and obtains the current authentication times between the master device and the auxiliary device, and this current authentication times is incremented by 1 based on the historical authentication times.

[0097] S603: If the current authentication times is less than the preset authentication times, the master device sends a device pairing request to the auxiliary device.

[0098] In the embodiments of this specification, when the current authentication times is less than the preset authentication times, at this time the master device sends a device pairing request to the auxiliary device, which is used to start requesting to generate a session key and authentication information again. By verifying the validity of the information sent by the master device decrypted by the auxiliary device, and in the case of failed verification, the pairing request can be re-initiated until a secure connection is successfully established between the two parties, enhancing the reliability of device authentication, improving the security of communication between the two parties, and establishing a trust basis for subsequent encrypted communication.

[0099] In the embodiments of this specification, the method further includes:

[0100] If the master device is in a powered-off state, the master device deletes the short-term identifier in the first volatile memory.

[0101] In the embodiments of this specification, the master device continuously monitors its own power state. If the master device is in a powered-off state, that is, the master device loses power, at this time the short-term identifier in the first volatile memory RAM disappears after the master device loses power.

[0102] If the auxiliary device is in a powered-off state, the auxiliary device deletes the short-term identifier in the second volatile memory.

[0103] In the embodiments of this specification, the auxiliary device continuously monitors its own power status. If the auxiliary device is in the powered-off state, that is, the auxiliary device loses power, the short-term identifier in the second volatile memory disappears after the auxiliary device loses power. When the device is powered off, the short-term identifier stored in the volatile memory corresponding to the device is automatically cleared, which effectively prevents the risk of long-term storage or unauthorized access of the short-term identifier, reduces the potential security hazards caused by the residue of the short-term identifier, ensures that a new authentication process is required each time the device is started, and enhances the security and reliability of device authentication.

[0104] S203: The master device obtains the short-term identifier stored locally and matching the auxiliary device, and encrypts the short-term identifier using the first session key to obtain the first ciphertext information; the short-term identifier is the identifier generated by the auxiliary device and sent to the master device when the historical authentication is passed; the first session key is the key generated by the master device based on the target key protocol.

[0105] In the embodiments of this specification, multiple short-term identifiers are stored in the first volatile memory RAM corresponding to the master device, and each short-term identifier represents an auxiliary device. The master device obtains the short-term identifier corresponding to the auxiliary device and encrypts it using the first session key for subsequent device authentication, improving the security and reliability of device authentication.

[0106] S205: The master device sends the first ciphertext information to the auxiliary device.

[0107] In the embodiments of this specification, the master device sends the first ciphertext information to the auxiliary device so that the auxiliary device can perform device authentication through this information.

[0108] S207: The auxiliary device decrypts the first ciphertext information using the second session key to obtain the first decrypted identifier; the second session key is the key generated by the auxiliary device based on the target key protocol.

[0109] In the embodiments of this specification, the auxiliary device decrypts the short-term identifier in the first ciphertext information using the second session key to obtain the first decrypted identifier. Subsequently, device authentication is performed by using the first decrypted identifier, improving the efficiency and reliability of device authentication.

[0110] In the embodiments of this specification, after the auxiliary device decrypts the first ciphertext information using the second session key to obtain the first decrypted identifier, as Figure 7 shown, Figure 7 is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification, and the method further includes:

[0111] S701: If the first decryption identifier does not match the short-term identifier in the second volatile memory, the auxiliary device obtains the first short-term authentication count.

[0112] In the embodiments of this specification, the default value of the short-term identifier can be all 0. When the first decryption identifier is all 0 or the first decryption identifier is different from the short-term identifier in the second volatile memory RAM, it is determined at this time that the short-term identifier sent by the master device is invalid, and the auxiliary device obtains the first short-term authentication count corresponding to the short-term identifier stored in the auxiliary device.

[0113] S702: If the first short-term authentication count is greater than or equal to the first preset short-term authentication count, the auxiliary device deletes the short-term identifier in the second volatile memory.

[0114] In the embodiments of this specification, when the first short-term authentication count reaches the preset maximum authentication count, that is, the first preset short-term authentication count, the short-term identifier in the second volatile memory RAM is deleted at this time.

[0115] S703: The master device obtains the second short-term authentication count.

[0116] In the embodiments of this specification, the master device also obtains the second short-term authentication count of the short-term identifier stored in the master device in real time.

[0117] S704: If the second short-term authentication count is greater than or equal to the second preset short-term authentication count, the master device deletes the short-term identifier in the first volatile memory.

[0118] In the embodiments of this specification, when the second short-term authentication count reaches the preset maximum authentication count corresponding to the short-term identifier of the master device, that is, the second preset short-term authentication count, the short-term identifier in the first volatile memory RAM is deleted at this time. By clearing the unnecessary short-term identifiers, the memory resources are released, the device performance is optimized, the retention time of the short-term identifier information inside the device is reduced, the risk of information leakage is reduced, both the memory space is saved, and the information security protection is strengthened.

[0119] In the embodiments of this specification, the first ciphertext information further includes the long-term identifier in the first non-volatile memory and the first random number generated by the master device; after the master device deletes the short-term identifier in the first volatile memory if the second short-term authentication count is greater than or equal to the second preset short-term authentication count, as Figure 8 shown, Figure 8 is a schematic flowchart of an authentication method for a smart home device provided by the embodiments of this specification, and the method further includes:

[0120] S801: The auxiliary device performs a matching process on the long-term identifier in the second non-volatile memory and the fourth decryption identifier to obtain a long-term authentication result; the fourth decryption identifier is the identifier obtained by decrypting the long-term identifier stored by the master device in the first ciphertext information.

[0121] In the embodiments of this specification, the long-term identifier in the second non-volatile memory is the authentication information stored in the Flash corresponding to the auxiliary device, and the fourth decryption identifier is the identifier obtained by decrypting the long-term identifier sent by the master device to the auxiliary device, that is, the authentication information locally stored by the master device. Since the fast authentication fails at this time, it is necessary to perform a matching process on the long-term identifier in the Flash of the second non-volatile memory and the fourth decryption identifier in order to perform the normal device authentication process.

[0122] S802: If the long-term authentication result indicates that the identifier in the second non-volatile memory matches the fourth decryption identifier, the auxiliary device generates a second random number, and uses the second session secret key to encrypt the first decrypted random number and the second random number to obtain a second ciphertext information; the first decrypted random number is the random number obtained by the auxiliary device decrypting the first random number in the first ciphertext information.

[0123] In the embodiments of this specification, if the identifier in the Flash of the second non-volatile memory matches the fourth decryption identifier, then the first step of the normal device authentication of the auxiliary device is successful at this time. The auxiliary device generates a second random number random2, and the length of the second random number random2 can be customized. The auxiliary device encrypts the first random number random1 obtained by decryption, that is, the first decrypted random number, and the second random number using the second session secret key to obtain the second ciphertext information.

[0124] S803: The auxiliary device sends the second ciphertext information to the master device.

[0125] In the embodiments of this specification, the auxiliary device sends the second ciphertext information to the master device for the master device to perform device authentication, and the auxiliary device also sends a notification message to the master device to notify the master device that the first step of device authentication is successful.

[0126] S804: The master device uses the first session secret key to decrypt the first decrypted random number in the second ciphertext information to obtain a second decrypted random number; and the master device decrypts the second random number in the second ciphertext information to obtain a third decrypted random number.

[0127] In the embodiments of this specification, the master device uses the first session key to decrypt the first decryption random number and the second random number in the second ciphertext information, respectively obtaining the second decryption random number and the third decryption random number for subsequent device authentication.

[0128] S805: If the first random number is the same as the second decryption random number, the master device determines that the authentication of the auxiliary device has been completed.

[0129] In the embodiments of this specification, since the second decryption random number is generated by the master device, sent to the auxiliary device, decrypted by the auxiliary device, and then encrypted and sent back to the master device, it is only necessary to verify whether the second decryption random number and the first random number are consistent to verify whether the unilateral device authentication between the master device and the auxiliary device is successful. When the first random number and the second decryption random number are the same, it can be determined at this time that the master device has completed the authentication of the auxiliary device. Through the interaction between the master device and the auxiliary device, including generating random numbers and comparing random numbers, the normal authentication process between devices is finally realized, ensuring the security of communication between devices, improving the efficiency and flexibility of device authentication, and laying a solid foundation for subsequent continuous communication.

[0130] In the embodiments of this specification, after the master device determines that the authentication of the auxiliary device has been completed if the first random number is the same as the first decryption random number, as Figure 9 shown, Figure 9 is a schematic flowchart of an authentication method for a smart home device provided by the embodiments of this specification. The method further includes:

[0131] S901: The master device generates a third random number and uses the first session key to encrypt the third decryption random number and the third random number to obtain third ciphertext information.

[0132] In the embodiments of this specification, when the master device completes the authentication of the identity of the auxiliary device, at this time, it is only necessary for the auxiliary device to complete the authentication of the identity of the master device to achieve mutual authentication between the master device and the auxiliary device, thereby completing the entire normal device authentication process. When the master device completes the authentication of the identity of the auxiliary device, at this time, the master device generates a third random number random3 and uses the first session key to encrypt the third random number and the third decryption random number to obtain third ciphertext information for subsequent auxiliary device to authenticate the identity of the master device, improving the security and reliability of device authentication.

[0133] S902: The master device sends the third ciphertext information to the auxiliary device.

[0134] In the embodiments of this specification, the master device sends third ciphertext information to the auxiliary device for the auxiliary device to perform device authentication.

[0135] S903: The auxiliary device uses the second session key to decrypt the third decryption random number in the third ciphertext information to obtain a fourth decryption random number; and the auxiliary device decrypts the third random number in the third ciphertext information to obtain a fifth decryption random number.

[0136] In the embodiments of this specification, the auxiliary device uses the second session key to decrypt the third decryption random number and the third random number in the third ciphertext information to obtain a fourth decryption random number and a fifth decryption random number respectively for subsequent device authentication.

[0137] S904: If the second random number is the same as the fourth decryption random number, the auxiliary device determines that the authentication of the master device has been completed.

[0138] In the embodiments of this specification, since the fourth random number is generated by the auxiliary device, encrypted and sent to the master device, and then decrypted and encrypted back to the auxiliary device by the master device, only the second random number and the fourth decryption random number need to be matched to determine whether the auxiliary device and the master device are successfully authenticated. When the second random number is the same as the fourth decryption random number, it can be determined that the auxiliary device has completed the authentication of the master device.

[0139] S905: The auxiliary device sends an authentication success message to the master device.

[0140] In the embodiments of this specification, when the auxiliary device completes the authentication of the master device, the auxiliary device sends an authentication success message to the master device to notify the master device. At this time, the mutual authentication between the master device and the auxiliary device is completed, that is, the normal device authentication process is completed. Through the interaction between the master device and the auxiliary device, including generating random numbers, sending ciphertext information, receiving ciphertext information, and comparing random numbers, the normal authentication process between devices is finally realized, ensuring the security of communication between devices and improving the efficiency and flexibility of device authentication.

[0141] S209: If the short-term identifier stored by the auxiliary device matches the first decryption identifier, the auxiliary device determines that it has been successfully authenticated with the master device and sends an authentication passed message to the master device.

[0142] In the embodiments of this specification, when the short-term identifier stored in the second volatile memory RAM of the auxiliary device is the same as the first decryption identifier, it can be determined that the auxiliary device and the master device are successfully authenticated, and an authentication passed message is sent to the master device. By storing the short-term identifier in the volatile memory, the efficiency of device authentication is improved.

[0143] In the embodiments of this specification, after the auxiliary device determines successful authentication with the master device and sends an authentication passed message to the master device if the short-term identifier stored in the auxiliary device matches the first decryption identifier, as Figure 10 shown, Figure 10 is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification. The method further includes:

[0144] S1001: The auxiliary device generates an updated short-term identifier and sends the updated short-term identifier to the master device.

[0145] In the embodiments of this specification, after the master device and the auxiliary device authenticate successfully bidirectionally, at this time the auxiliary device generates an updated short-term identifier, that is, new fast authentication information, and sends the updated short-term identifier to the master device.

[0146] S1002: The master device updates the short-term identifier in the first volatile memory to the updated short-term identifier.

[0147] In the embodiments of this specification, the master device updates the short-term identifier in the first volatile memory RAM, that is, the fast authentication information, to the updated short-term identifier, realizing the update of the short-term identifier, preventing being retried multiple times by a third party, and thus realizing fast device authentication.

[0148] S1003: The auxiliary device updates the short-term identifier in the second volatile memory to the updated short-term identifier.

[0149] In the embodiments of this specification, the auxiliary device updates the short-term identifier in the second volatile memory RAM to the updated short-term identifier. By the master device and the auxiliary device respectively generating and saving the updated short-term identifier generated by the auxiliary device into their respective volatile memories RAM, it ensures that the preparation for the next fast device authentication is ready, clears the old short-term identifier, reduces memory occupancy, and improves the security and efficiency of the device authentication process, providing a reliable guarantee for future fast device authentication and subsequent control operations of the device.

[0150] S211: The master device sends a control instruction to the auxiliary device.

[0151] In the embodiments of this specification, after the master device and the auxiliary device authenticate successfully, the master device can be a range hood, and the auxiliary device can be a cooking stove. The range hood can send a control instruction to the cooking stove to control the cooking stove to adjust the fire size, turn on and off, etc.

[0152] In an exemplary embodiment, as Figure 11 shown, Figure 11A timing diagram for generating authentication information provided by an embodiment of this specification, including:

[0153] S1101: Device A requests device B to start generating a session key and authentication information.

[0154] In the embodiment of this specification, device A is a BLE host, also known as a central device, which is the device that actively initiates and manages connections. The host usually has relatively high computing power and resources and can manage multiple slave devices simultaneously. Device B is a BLE slave, also known as a peripheral device, which is a device that waits passively for connections. The slave usually has relatively low computing power and resources and focuses on performing specific tasks. When device A and device B are paired for the first time, device A actively sends a request to device B to generate a session key and authentication information.

[0155] S1102: Device B rejects the pairing request from device A and notifies device A.

[0156] In the embodiment of this specification, device B, according to its own situation, for example, when device B is not in a pairing state, device B replies to device A to reject the pairing request. At this time, the process ends and device A disconnects from device B.

[0157] S1103: Device B agrees to the pairing request from device A and notifies device A.

[0158] In the embodiment of this specification, when device B is in a pairing state or other pair-able situations, device B replies to device A to agree to the pairing request.

[0159] S1104: Device B generates a public key and a private key corresponding to device B.

[0160] In the embodiment of this specification, device B generates a public key PB_Key_B corresponding to device B and a private key PV_Key_B corresponding to device B.

[0161] S1105: Device A generates a public key and a private key corresponding to device A.

[0162] In the embodiment of this specification, device A generates a public key PB_Key_A corresponding to device A and a private key PV_Key_A corresponding to device A.

[0163] S1106: Device A sends the public key of device A to device B.

[0164] In the embodiment of this specification, device A sends the public key PB_Key_A corresponding to device A to device B.

[0165] S1107: Device B sends the public key of device B to device A.

[0166] In the embodiments of this specification, Device B sends the public key PB_Key_B corresponding to Device B to Device A.

[0167] S1108: Device A calculates the session key and deletes all public and private keys in Device A.

[0168] In the embodiments of this specification, Device A uses the private key PV_Key_A corresponding to Device A and the public key PB_Key_B corresponding to Device B to calculate the session key based on the ECDH protocol. After calculating the session key, Device A deletes all public and private keys in Device A and notifies Device B that the session key has been calculated.

[0169] S1109: Device B calculates the session key and deletes all public and private keys in Device B.

[0170] In the embodiments of this specification, Device B uses the private key PV_Key_B corresponding to Device B and the public key PB_Key_A corresponding to Device A to calculate the session key based on the ECDH protocol. After calculating the session key, Device B deletes all public and private keys in Device B and notifies Device A that the session key has been calculated.

[0171] S1110: Device A generates authentication information and fast authentication information.

[0172] In the embodiments of this specification, Device A generates authentication information and fast authentication information, both of which are a random string of numbers or text, and the length can be customized.

[0173] S1111: Device A sends the authentication information, fast authentication information encrypted with the session key, and the hardware address of Device B to Device B.

[0174] In the embodiments of this specification, Device A can encrypt the authentication information, fast authentication information, and the MAC hardware address of Device B using the session key with the AES-CBC scheme and send them to Device B.

[0175] S1112: Device B decrypts the information sent by Device A to obtain the authentication information, fast authentication information, and the hardware address of Device B sent by Device A.

[0176] In the embodiments of this specification, Device B receives the encrypted information sent by Device A. Device B decrypts it using the session key to obtain the decrypted authentication information, decrypted fast authentication information, and the decrypted MAC address of Device B.

[0177] S1113: Device B fails to decrypt and notifies Device A that the key availability check fails.

[0178] In the embodiments of this specification, if device B fails to decrypt the encrypted information sent by device A, or device B decrypts successfully but the MAC hardware address obtained after decryption does not match the MAC hardware address of device B, then it is determined that device B decrypts failed, and device B notifies device A that the key availability verification fails.

[0179] S1114: Increment the retry count of device A by 1.

[0180] In the embodiments of this specification, device A determines whether the current retry count has reached a preset maximum value. If it has reached the maximum value, device A will disconnect the connection; if it has not reached the maximum value, device A increases the retry count, and for each retry, the retry count of the device is incremented by 1.

[0181] S1115: Device A sends a request to generate a session key and authentication information to device B again.

[0182] In the embodiments of this specification, device A requests to start the ECDH process again and restart the ECDH process, that is, device A sends a request to generate a session key and authentication information to device B again.

[0183] S1116: Device B decrypts successfully and notifies device A that the key availability verification passes.

[0184] In the embodiments of this specification, when device B decrypts the encrypted information sent by device A and the MAC hardware address obtained after decryption is the same as the MAC hardware address of device B, then it is determined that device B decrypts successfully, and device B notifies device A that the key availability verification passes.

[0185] S1117: Device B saves the fast authentication information to the random access memory of device B.

[0186] In the embodiments of this specification, device B saves the decrypted fast authentication information to the random access memory RAM corresponding to device B.

[0187] S1118: Device A saves the fast authentication information to the random access memory of device A.

[0188] In the embodiments of this specification, device A saves the fast authentication information generated by device A to the random access memory RAM corresponding to device A.

[0189] S1119: Device A saves the authentication information and the session key to the flash memory of device A.

[0190] In the embodiments of this specification, device A saves the authentication information generated by device A and the session secret key calculated by device A to the flash memory Flash corresponding to device A. After the data is stored in the Flash, it can be encrypted again in a certain way, or stored in the secure area provided by the chip to prevent the attacker from directly reading the data in the Flash.

[0191] S1120: Device B saves the authentication information and the session secret key to the flash memory of device B.

[0192] In the embodiments of this specification, device B saves the decrypted authentication information and the session secret key calculated by device B to the flash memory Flash corresponding to device B. After the data is stored in the Flash, it can be encrypted again in a certain way, or stored in the secure area provided by the chip to prevent the attacker from directly reading the data in the Flash.

[0193] In this embodiment, device A, that is, the BLE host, initiates a request to generate a session secret key and authentication information. Device B, that is, the BLE slave, can choose to accept or reject. In the case where device B accepts, both parties start to negotiate and generate a session secret key using the ECDH protocol. After both parties complete the ECDH process, device A generates an authentication information and a fast authentication information, and encrypts the authentication information, the fast authentication information, and the MAC address of device B using the session secret key. The encrypted information is sent to device B. Device B uses the same session secret key to decrypt to obtain the original authentication information and fast authentication information. After the decryption is completed, both parties store the session secret key and the authentication information in their respective flash memories Flash, and the fast authentication information is stored in the RAM for subsequent use. Through the ECDH protocol, even if the communication channel may be eavesdropped, a third party cannot know the actually used session secret key; by encrypting and decrypting the authentication information and the fast authentication information, the security of the data during transmission is ensured; storing the session secret key and the authentication information in the flash memory and further adopting additional encryption measures increases the security of the data; by retaining some information in the RAM, the subsequent authentication process is made more rapid and convenient.

[0194] In an exemplary embodiment, as Figure 12 shown, Figure 12 is a timing diagram of an identity authentication process provided by the embodiments of this specification, including:

[0195] S1201: Device A randomly generates a first random number.

[0196] In the embodiments of this specification, Device A, i.e., the BLE host, generates a first random number random1. The length of this random number can be customized, and the same applies to other subsequent random numbers random_X; generating random numbers is used for subsequent encryption and verification processes, enhancing the security of device authentication.

[0197] S1202: Device A sends the encrypted fast authentication information, authentication information, and the first random number to Device B.

[0198] In the embodiments of this specification, Device A combines the fast authentication information, authentication information, and the first random number random1, and performs encryption processing using the session key; by encrypting important information, it prevents unauthorized access by other devices.

[0199] S1203: Device B decrypts the information sent by Device A to obtain the fast authentication information, authentication information, and the first random number.

[0200] In the embodiments of this specification, Device B, i.e., the BLE slave, after receiving the encrypted information, decrypts it using the session key and extracts the fast authentication information, authentication information, and the first random number random1; decrypting the message helps to confirm the validity of the information and prepares for the next verification.

[0201] S1204: If the fast authentication of Device B passes, Device B sends the encrypted new fast authentication information and the first random number to Device A.

[0202] In the embodiments of this specification, there is fast authentication information in the random access memory (RAM) of Device B, and the fast authentication information sent by Device A is valid; Device B checks the validity of the fast authentication information; ensuring that the fast authentication information has not expired or been tampered with.

[0203] S1205: Device A sends a confirmation reply notification to Device B.

[0204] In the embodiments of this specification, if the fast authentication information is invalid, then Device B sends an ACK message to inform Device A that the fast authentication is successful.

[0205] S1206: Device A saves the new fast authentication information into the random access memory of Device A.

[0206] In the embodiments of this specification, if the fast authentication information is valid, Device B saves the new fast authentication information into the RAM. By updating the fast authentication information, it facilitates the next fast verification.

[0207] S1207: Device B saves the new fast authentication information into the random access memory of Device B.

[0208] In the embodiments of this specification, Device A also saves the updated fast authentication information to its RAM to ensure that both parties have the latest fast authentication information.

[0209] S1208: Delete the fast authentication information in the random access memory of Device B.

[0210] In the embodiments of this specification, Device B checks whether the usage times of the fast authentication information in the RAM have reached the preset maximum value MAX. Among them, every time Device B compares the received fast authentication information of Device A with its own, it records 1. When it reaches MAX, Device B resets the fast authentication information in the RAM to avoid potential security risks caused by over-reliance by controlling the usage frequency of the fast authentication information.

[0211] S1209: Delete the fast authentication information in the random access memory of Device A.

[0212] In the embodiments of this specification, Device A checks whether the usage times of the fast authentication information in the RAM have reached the preset maximum value MAX. Among them, every time Device A sends a valid fast authentication information to Device B, it records 1 time. When it reaches MAX, Device A resets the fast authentication information in the RAM, clears the old fast authentication information, and prepares for the next round of verification.

[0213] S1210: Device B compares the authentication information in the flash memory of Device B with the parsed authentication information.

[0214] In the embodiments of this specification, when there is no fast authentication information in the RAM of Device B or the fast authentication information sent by Device A is invalid, at this time, the fast authentication information is filled with an invalid value, such as all FF or all 00, etc., and enters the normal identity authentication process. Device B checks whether the authentication information saved in the flash memory Flash of Device B is consistent with the authentication information sent by Device A, so as to carry out the normal identity authentication process.

[0215] S1211: Device B sends an authentication failure message to Device A.

[0216] In the embodiments of this specification, when the authentication information saved in the flash memory Flash of Device B is inconsistent with the authentication information sent by Device A, at this time, the authentication fails, and Device B sends an authentication failure message to Device A.

[0217] S1212: Device B randomly generates a second random number.

[0218] In the embodiments of this specification, when the authentication information saved in the flash memory Flash of Device B is consistent with the authentication information sent by Device A, at this time, the first step of authentication is successful, and Device A generates a new random number random2; prepare for the second round of verification.

[0219] S1213: Device B replies to Device A with an authentication success message, the encrypted first random number, and the second random number.

[0220] In the embodiments of this specification, Device B combines the received first random numbers random1 and random2 with the first-step authentication success message and encrypts them, and then sends them to Device A to share necessary verification information, further enhancing the security of the verification process.

[0221] S1214: Device A decrypts the information sent by Device B to obtain the first random number and the second random number.

[0222] In the embodiments of this specification, Device A decrypts the encrypted random1 and random2 for use in identity authentication.

[0223] S1215: Device A compares the first random number sent out with the received first random number.

[0224] In the embodiments of this specification, Device A compares whether the received random1 matches the previously generated random1 to confirm the integrity and consistency of the information.

[0225] S1216: If the comparison between the sent first random number and the received first random number is inconsistent, Device A sends a normal authentication failure message to Device B.

[0226] In the embodiments of this specification, if random1 is inconsistent in comparison, Device A confirms that the authentication fails and notifies Device B of the authentication failure.

[0227] S1217: Device A randomly generates a third random number.

[0228] In the embodiments of this specification, if random1 is consistent in comparison, at this time Device A has completed the authentication of Device B. Device A generates a third random number random3 and prepares for the third round of verification.

[0229] S1218: Device A sends the encrypted second random number and third random number to Device B.

[0230] In the embodiments of this specification, Device A combines random2, random3 with the second-step authentication success message and encrypts them to increase the complexity and security of the verification process.

[0231] S1219: Device B decrypts the information sent by Device A to obtain the second random number and the third random number.

[0232] In the embodiments of this specification, Device B decrypts the received encrypted information, extracts random2 and random3 to confirm the correctness of the information.

[0233] S1220: Device B compares the second random number sent out with the received second random number.

[0234] In the embodiments of this specification, Device B compares whether the previously generated random2 is the same as the received random2 to reconfirm the consistency of the information.

[0235] S1221: If the comparison between the sent second random number and the received second random number is inconsistent, Device B sends a comparison failure message to Device A.

[0236] In the embodiments of this specification, if the comparison of random2 is inconsistent, Device B confirms that the authentication fails and sends an authentication failure message to Device A.

[0237] S1222: Device B sends an authentication success message to Device A.

[0238] In the embodiments of this specification, if the comparison of random2 is consistent, Device B confirms that the authentication is successful and sends an authentication success message to Device A.

[0239] S1223: Device B generates new fast authentication information.

[0240] In the embodiments of this specification, Device B generates new fast authentication information to replace the original fast authentication information, improving the reliability and security of device identity authentication.

[0241] S1224: Device B sends the new fast authentication information to Device A.

[0242] In the embodiments of this specification, Device B sends the newly generated fast authentication information to Device A to realize the update of the fast authentication information of both parties.

[0243] S1225: Device A saves the new fast authentication information into the random access memory corresponding to Device A.

[0244] In the embodiments of this specification, Device A saves the new fast authentication information into its RAM to ensure that Device A has the latest fast authentication information.

[0245] S1226: Device B saves the new fast authentication information into the random access memory corresponding to Device B.

[0246] In the embodiments of this specification, Device B saves the new fast authentication information into its RAM to ensure that both parties have the latest fast authentication information.

[0247] In this embodiment, through multiple rounds of interaction between Device A and Device B, which involve key steps such as the generation of random numbers, the creation and exchange of authentication information, the generation and storage of fast authentication information, etc., the use of encryption algorithms and random numbers ensures data security during the communication process, preventing illegal eavesdropping and tampering; the fast authentication information simplifies the subsequent authentication process, reduces communication latency, and improves the user experience; by dynamically updating the fast authentication information, it adapts to changes in communication requirements under different application scenarios, enhancing the flexibility and adaptability of the system; by reasonably allocating and managing memory resources, unnecessary data redundancy is reduced, and the overall performance of the device is optimized.

[0248] The following takes the master device as the execution entity to introduce a specific embodiment of the authentication method for a smart home device in this specification. Figure 13 It is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification. Specifically, in combination with Figure 13 as shown, the method may include:

[0249] S1301: When the smart home device is in the powered-on state and receives a connection instruction, obtain a device that matches the target device carried in the connection instruction to obtain an auxiliary device; the target device is a smart home device that has been historically authenticated with the master device; the master device is a device among the smart home devices.

[0250] S1302: Obtain the short-term identifier stored locally that matches the auxiliary device, and encrypt the short-term identifier using the first session key to obtain the first ciphertext information; the short-term identifier is an identifier generated by the auxiliary device and sent to the master device when the historical authentication is passed; the first session key is a key generated based on the target key protocol.

[0251] S1303: Send the first ciphertext information to the auxiliary device; so that the auxiliary device decrypts the first ciphertext information using the second session key to obtain the first decrypted identifier; so that if the short-term identifier stored by the auxiliary device matches the first decrypted identifier, the auxiliary device determines that it has successfully authenticated with the master device and sends an authentication passed message to the master device; the second session key is a key generated by the auxiliary device based on the target key protocol.

[0252] S1304: Send a control instruction to the auxiliary device.

[0253] In some embodiments, before the step of obtaining a device that matches the target device carried in the connection instruction to obtain an auxiliary device when the smart home device is in the powered-on state and receives a connection instruction, the method further includes:

[0254] Generate a historical short-term identifier and a historical long-term identifier, and obtain a first hardware address corresponding to the auxiliary device;

[0255] Use the first session secret key to encrypt the historical short-term identifier, the historical long-term identifier, and the first hardware address to obtain encrypted information;

[0256] Send the encrypted information to the auxiliary device; so that the auxiliary device uses the second session secret key to decrypt the historical short-term identifier in the encrypted information to obtain a second decrypted identifier; so that the auxiliary device uses the second session secret key to decrypt the historical long-term identifier in the encrypted information to obtain a third decrypted identifier; so that the auxiliary device uses the second session secret key to decrypt the first hardware address in the encrypted information to obtain a decrypted hardware address; so that the auxiliary device obtains a second hardware address corresponding to the auxiliary device, and performs a matching process on the decrypted hardware address and the second hardware address to obtain a hardware address matching result.

[0257] In some embodiments, after sending the encrypted information to the auxiliary device, the method further includes:

[0258] If the hardware address matching result indicates that the decrypted hardware address is the same as the second hardware address, receive a decryption success message sent by the auxiliary device;

[0259] Store the historical short-term identifier in a first volatile memory corresponding to the main device, and store the historical long-term identifier in a first non-volatile memory corresponding to the main device; so that the auxiliary device stores the historical short-term identifier in a second volatile memory corresponding to the auxiliary device, and stores the historical long-term identifier in a second non-volatile memory corresponding to the auxiliary device.

[0260] In some embodiments, after sending the encrypted information to the auxiliary device, the method further includes:

[0261] If the hardware address matching result indicates that the decrypted hardware address is different from the second hardware address, receive a decryption failure message sent by the auxiliary device;

[0262] Based on the decryption failure message, obtain the current authentication times between the main device and the auxiliary device;

[0263] If the current authentication times is less than a preset authentication times, send a device pairing request to the auxiliary device.

[0264] In some embodiments, the method further includes:

[0265] If the master device is in a powered-off state, delete the short-term identifier in the first volatile memory; if the auxiliary device is in a powered-off state, enable the auxiliary device to delete the short-term identifier in the second volatile memory.

[0266] An embodiment of this specification provides an authentication device for a smart home device, which is applied to a master device. The device includes a processor and a memory. At least one instruction or at least one segment of program is stored in the memory, and the at least one instruction or at least one segment of program is loaded and executed by the processor to implement the authentication method of the smart home device as described above.

[0267] Introduce a specific embodiment of the authentication method of a smart home device in this specification with the auxiliary device as the execution subject. Figure 14 It is a schematic flowchart of an authentication method for a smart home device provided by an embodiment of this specification. Specifically, in combination with Figure 14 as shown, the method may include:

[0268] S1401: Receive the first ciphertext information sent by the master device; the first ciphertext information is the ciphertext information obtained by the master device by acquiring the short-term identifier stored locally and matching the auxiliary device, and encrypting the short-term identifier with the first session key; the short-term identifier is the identifier generated and sent to the master device when the historical authentication is passed; the first session key is the key generated by the master device based on the target key protocol; the auxiliary device is the device matched with the target device carried in the connection instruction obtained by the master device when the smart home device is in a powered-on state and the master device receives the connection instruction; the target device is a smart home device that has been historically authenticated with the master device; the master device is a device in the smart home device.

[0269] S1402: Decrypt the first ciphertext information with the second session key to obtain the first decrypted identifier; the second session key is the key generated based on the target key protocol.

[0270] S1403: If the short-term identifier stored in the auxiliary device matches the first decrypted identifier, determine that the authentication with the master device is successful, and send an authentication passed message to the master device.

[0271] S1404: Receive the control instruction sent by the master device.

[0272] In some embodiments, after the auxiliary device determines that the authentication with the master device is successful and sends an authentication passed message to the master device if the short-term identifier stored in the auxiliary device matches the first decrypted identifier, the method further includes:

[0273] Generate an updated short-term identifier and send the updated short-term identifier to the master device, so that the master device updates the short-term identifier in the first volatile memory corresponding to the master device to the updated short-term identifier;

[0274] Update the short-term identifier in the second volatile memory corresponding to the auxiliary device to the updated short-term identifier.

[0275] In some embodiments, after decrypting the first ciphertext information using the second session key to obtain a first decryption identifier, the method further includes:

[0276] If the first decryption identifier does not match the short-term identifier in the second volatile memory, obtain the first short-term authentication count;

[0277] If the first short-term authentication count is greater than or equal to a first preset short-term authentication count, perform a deletion process on the short-term identifier in the second volatile memory.

[0278] An embodiment of this specification provides an authentication device for a smart home device, which is applied to an auxiliary device. The device includes a processor and a memory. At least one instruction or at least one program segment is stored in the memory. The at least one instruction or at least one program segment is loaded and executed by the processor to implement the authentication method for the smart home device as described above.

[0279] An embodiment of this specification also provides an authentication device for a smart home device, which is applied to a master device, as Figure 15 shown. The device includes:

[0280] An auxiliary device determination module 1501, configured to obtain a device that matches the target device carried in the connection instruction when the smart home device is in a powered-on state and receives the connection instruction, so as to obtain an auxiliary device; the target device is a smart home device that has been historically authenticated with the master device; the master device is a device in the smart home device;

[0281] A first ciphertext information determination module 1502, configured to obtain a short-term identifier stored locally and matching the auxiliary device, and encrypt the short-term identifier using a first session key to obtain first ciphertext information; the short-term identifier is an identifier generated by the auxiliary device and sent to the master device when the historical authentication is passed; the first session key is a key generated based on a target key protocol;

[0282] The first ciphertext information sending module 1503 is configured to send the first ciphertext information to the auxiliary device; so that the auxiliary device decrypts the first ciphertext information by using a second session key to obtain a first decryption identifier; so that if the short-term identifier stored in the auxiliary device matches the first decryption identifier, the auxiliary device determines successful authentication with the master device and sends an authentication passed message to the master device; the second session key is a key generated by the auxiliary device based on the target key protocol.

[0283] The control instruction sending module 1504 is configured to send a control instruction to the auxiliary device.

[0284] In some embodiments, the device may further include:

[0285] The generation module is configured to generate a historical short-term identifier and a historical long-term identifier, and obtain a first hardware address corresponding to the auxiliary device.

[0286] The encrypted information determination module is configured to encrypt the historical short-term identifier, the historical long-term identifier, and the first hardware address by using the first session key to obtain encrypted information.

[0287] The encrypted information sending module is configured to send the encrypted information to the auxiliary device; so that the auxiliary device decrypts the historical short-term identifier in the encrypted information by using the second session key to obtain a second decryption identifier; so that the auxiliary device decrypts the historical long-term identifier in the encrypted information by using the second session key to obtain a third decryption identifier; so that the auxiliary device decrypts the first hardware address in the encrypted information by using the second session key to obtain a decrypted hardware address; so that the auxiliary device obtains a second hardware address corresponding to the auxiliary device, and performs a matching process on the decrypted hardware address and the second hardware address to obtain a hardware address matching result.

[0288] In some embodiments, the device may further include:

[0289] The decryption success message module is configured to receive a decryption success message sent by the auxiliary device if the hardware address matching result indicates that the decrypted hardware address is the same as the second hardware address.

[0290] The storage module is configured to store the historical short-term identifier in a first volatile memory corresponding to the master device, and store the historical long-term identifier in a first non-volatile memory corresponding to the master device; so that the auxiliary device stores the historical short-term identifier in a second volatile memory corresponding to the auxiliary device, and stores the historical long-term identifier in a second non-volatile memory corresponding to the auxiliary device.

[0291] In some embodiments, the device may further include:

[0292] A decryption failure message module, configured to receive a decryption failure message sent by the auxiliary device if the hardware address matching result indicates that the decrypted hardware address is different from the second hardware address.

[0293] A current authentication times acquisition module, configured to acquire the current authentication times between the master device and the auxiliary device based on the decryption failure message.

[0294] A device pairing request sending module, configured to send a device pairing request to the auxiliary device if the current authentication times is less than a preset authentication times.

[0295] In some embodiments, the device may further include:

[0296] A first deletion module, configured to delete the short-term identifier in the first volatile memory if the master device is in a powered-off state; and to cause the auxiliary device to delete the short-term identifier in the second volatile memory if the auxiliary device is in a powered-off state.

[0297] The embodiments of this specification also provide an authentication device for a smart home device, which is applied to an auxiliary device. As Figure 16 shown, the device includes:

[0298] A first receiving module 1601, configured to receive first ciphertext information sent by a master device; the first ciphertext information is ciphertext information obtained by the master device acquiring a short-term identifier stored locally and matching the auxiliary device, and encrypting the short-term identifier using a first session key; the short-term identifier is an identifier generated and sent to the master device in the case of successful historical authentication; the first session key is a key generated by the master device based on a target key protocol; the auxiliary device is a device obtained by the master device when the smart home device is in a powered-on state and the master device receives a connection instruction, and matching the target device carried in the connection instruction; the target device is a smart home device that has been historically authenticated with the master device; the master device is a device in the smart home device;

[0299] A decryption module 1602, configured to decrypt the first ciphertext information using a second session key to obtain a first decrypted identifier; the second session key is a key generated based on the target key protocol;

[0300] An authentication module 1603, configured to determine successful authentication with the master device if the short-term identifier stored in the auxiliary device matches the first decryption identifier, and send an authentication passed message to the master device;

[0301] A second receiving module 1604, configured to receive a control instruction sent by the master device.

[0302] In some embodiments, the device may further include:

[0303] An updated short-term identifier module, configured to generate an updated short-term identifier and send the updated short-term identifier to the master device; so that the master device updates the short-term identifier in the first volatile memory corresponding to the master device to the updated short-term identifier.

[0304] An update module, configured to update the short-term identifier in the second volatile memory corresponding to the auxiliary device to the updated short-term identifier.

[0305] In some embodiments, the device may further include:

[0306] A first short-term authentication times obtaining module, configured to obtain the first short-term authentication times if the first decryption identifier does not match the short-term identifier in the second volatile memory.

[0307] A second deletion module, configured to perform a deletion process on the short-term identifier in the second volatile memory if the first short-term authentication times is greater than or equal to a first preset short-term authentication times.

[0308] The device in the device embodiment and the method embodiment are based on the same inventive concept.

[0309] An embodiment of this specification provides a smart home electronic device, which includes a processor and a memory. At least one instruction or at least one program segment is stored in the memory, and the at least one instruction or at least one program segment is loaded and executed by the processor to implement the authentication method of the smart home device provided in the above method embodiment.

[0310] An embodiment of the present application further provides a computer storage medium, which can be set in a terminal to save at least one instruction or at least one program segment related to implementing the authentication method of a smart home device in the method embodiment. The at least one instruction or at least one program segment is loaded and executed by the processor to implement the authentication method of the smart home device provided in the above method embodiment.

[0311] Embodiments of the present application also provide a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes to implement the authentication method of the smart home device provided in the foregoing method embodiments.

[0312] The memory described in the embodiments of the present specification can be used to store software programs and modules. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for functions, etc.; the data storage area can store data created according to the use of the device, etc. In addition, the memory may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices. Correspondingly, the memory may further include a memory controller to provide the processor with access to the memory.

[0313] The authentication method embodiments of the smart home device provided in the embodiments of the present specification can be executed on a mobile terminal, a computer terminal, a server, or a similar computing device. Taking running on a server as an example, Figure 17 is a hardware structure block diagram of a server for the authentication method of a smart home device provided in the embodiments of the present specification. As Figure 17As shown, the server 1700 can vary significantly due to configuration or performance differences. It can include one or more central processing units (CPUs) 1710 (the central processing unit 1710 can include, but is not limited to, processing devices such as microprocessor MCUs or programmable logic devices FPGAs), a memory 1730 for storing data, and one or more storage media 1720 for storing application programs 1723 or data 1722 (such as one or more mass storage devices). Among them, the memory 1730 and the storage media 1720 can be transient storage or persistent storage. The program stored in the storage media 1720 can include one or more modules, and each module can include a series of instruction operations on the server. Further, the central processing unit 1710 can be configured to communicate with the storage media 1720 and execute a series of instruction operations in the storage media 1720 on the server 1700. The server 1700 can also include one or more power supplies 1760, one or more wired or wireless network interfaces 1750, one or more input / output interfaces 1740, and / or one or more operating systems 1721, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, and so on.

[0314] The input / output interface 1740 can be used to receive or send data via a network. Specific examples of the above-mentioned network can include a wireless network provided by the communication provider of the server 1700. In one example, the input / output interface 1740 includes a network interface controller (NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one example, the input / output interface 1740 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0315] Those of ordinary skill in the art can understand that Figure 17 the structure shown is only illustrative and does not limit the structure of the above-mentioned electronic device. For example, the server 1700 can also include more or fewer components than Figure 17 shown, or have a different configuration from Figure 17 shown.

[0316] As can be seen from the embodiments of the authentication method and device for smart home devices provided by the present application above, when the smart home device is in a powered-on state and receives a connection instruction, a device matching the target device carried in the connection instruction is obtained to obtain an auxiliary device; the target device is a smart home device that has been historically authenticated with the master device; the master device is a device in the smart home device; a short-term identifier matching the auxiliary device stored locally is obtained, and the short-term identifier is encrypted using a first session key to obtain a first ciphertext message; the short-term identifier is an identifier generated by the auxiliary device and sent to the master device when the historical authentication is passed; the first session key is a key generated based on a target key protocol; the first ciphertext message is sent to the auxiliary device; so that the auxiliary device decrypts the first ciphertext message using a second session key to obtain a first decrypted identifier; so that if the short-term identifier stored by the auxiliary device matches the first decrypted identifier, the auxiliary device determines that the authentication with the master device is successful and sends an authentication passed message to the master device; the second session key is a key generated by the auxiliary device based on the target key protocol; a control instruction is sent to the auxiliary device. When two new devices are connected for the first time in the present application, the master device will initiate a request to generate a session key and authentication information. If the auxiliary device agrees, the two parties negotiate to generate a common session key through the ECDH algorithm. Subsequently, the master device randomly generates authentication information and fast authentication information and encrypts them with the session key, and sends them to the auxiliary device. After the auxiliary device decrypts them, it saves the authentication information to its non-volatile memory and saves the fast authentication information to its volatile memory for subsequent identity authentication. When the paired devices are reconnected, in order to confirm each other's identities, the two parties will perform a series of encrypted message exchanges. This process involves the generation and verification of random numbers, ensuring that even if a third party attempts to impersonate a legitimate device through methods such as replay attacks, it will not succeed. The master device will generate a random number and encrypt it together with the authentication information and send it to the auxiliary device. After the auxiliary device decrypts it, it verifies the correctness of the information and responds with another random number to the master device to complete the two-way identity verification. For the situation of frequent disconnection and reconnection, a fast authentication mechanism is proposed, which reduces the number of interactions required for conventional authentication and improves the connection efficiency of the devices. By checking the fast authentication information in the RAM, the identity verification can be quickly completed under specific conditions. By using the ECDH algorithm and dynamically generated random numbers, replay attacks are effectively resisted, ensuring the authenticity and security of the identities of both communication parties. The introduced fast authentication mechanism significantly reduces the time required for the devices to re-establish a trust relationship, optimizes the user experience, is not only applicable to newly paired devices but also can well handle the disconnection and reconnection between devices, and improves the efficiency and convenience of device identity authentication in the local communication environment.

[0317] It should be noted that: the above order of the embodiments in this specification is only for description and does not represent the superiority or inferiority of the embodiments. And the above specific embodiments of this specification have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0318] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. The key point of each embodiment is to illustrate the differences from other embodiments. In particular, for the embodiments of the apparatus, device, and storage medium, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments.

[0319] Those of ordinary skill in the art can understand that all or part of the steps to implement the above embodiments can be completed by hardware, or can be completed by a program instructing the relevant hardware. The program can be stored in a computer storage medium. The above-mentioned storage medium can be a read-only memory, a disk, an optical disc, etc.

[0320] The above are only the preferred embodiments of this application and are not intended to limit this application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this application shall be included within the protection scope of this application.

Claims

1. A method for authenticating a smart home device, characterized in that, Applied to a master device, the method includes: When the smart home device is in the powered-on state and a connection instruction is received, obtaining a device that matches the target device carried in the connection instruction to obtain an auxiliary device; the target device is a smart home device that has been historically authenticated with the master device; the master device is a device among the smart home devices; Obtaining a locally stored short-term identifier that matches the auxiliary device, and using a first session key to encrypt the short-term identifier to obtain a first ciphertext message; the short-term identifier is an identifier generated by the auxiliary device and sent to the master device when historical authentication is passed; the first session key is a key generated based on a target key protocol; Sending the first ciphertext message to the auxiliary device; so that the auxiliary device uses a second session key to decrypt the first ciphertext message to obtain a first decrypted identifier; so that if the short-term identifier stored by the auxiliary device matches the first decrypted identifier, the auxiliary device determines that authentication with the master device is successful and sends an authentication passed message to the master device; the second session key is a key generated by the auxiliary device based on the target key protocol; Sending a control instruction to the auxiliary device.

2. The method according to claim 1, characterized in that Before the step of obtaining a device that matches the target device carried in the connection instruction when the smart home device is in the powered-on state and a connection instruction is received to obtain an auxiliary device, the method further includes: Generating a historical short-term identifier and a historical long-term identifier, and obtaining a first hardware address corresponding to the auxiliary device; Using the first session key to encrypt the historical short-term identifier, the historical long-term identifier, and the first hardware address to obtain an encrypted message; Sending the encrypted message to the auxiliary device; so that the auxiliary device uses the second session key to decrypt the historical short-term identifier in the encrypted message to obtain a second decrypted identifier; so that the auxiliary device uses the second session key to decrypt the historical long-term identifier in the encrypted message to obtain a third decrypted identifier; so that the auxiliary device uses the second session key to decrypt the first hardware address in the encrypted message to obtain a decrypted hardware address; so that the auxiliary device obtains a second hardware address corresponding to the auxiliary device and performs a matching process on the decrypted hardware address and the second hardware address to obtain a hardware address matching result.

3. The method according to claim 2, wherein After sending the encrypted message to the auxiliary device, the method further includes: If the hardware address matching result indicates that the decrypted hardware address is the same as the second hardware address, receiving a decryption success message sent by the auxiliary device; Store the historical short-term identifier in a first volatile memory corresponding to the master device, and store the historical long-term identifier in a first non-volatile memory corresponding to the master device; so that the auxiliary device stores the historical short-term identifier in a second volatile memory corresponding to the auxiliary device, and stores the historical long-term identifier in a second non-volatile memory corresponding to the auxiliary device.

4. The method according to claim 2, wherein After sending the encrypted information to the auxiliary device, the method further includes: If the hardware address matching result indicates that the decrypted hardware address is different from the second hardware address, receive a decryption failure message sent by the auxiliary device; Based on the decryption failure message, obtain the current authentication times between the master device and the auxiliary device; If the current authentication times is less than a preset authentication times, send a device pairing request to the auxiliary device.

5. The method according to claim 3, characterized in that, The method further includes: If the master device is in a powered-off state, delete the short-term identifier in the first volatile memory; if the auxiliary device is in a powered-off state, so that the auxiliary device deletes the short-term identifier in the second volatile memory.

6. A method for authenticating a smart home device, characterized in that, Applied to an auxiliary device, the method includes: Receive a first ciphertext message sent by a master device; the first ciphertext message is a ciphertext message obtained by the master device acquiring a short-term identifier stored locally that matches the auxiliary device and encrypting the short-term identifier using a first session key; the short-term identifier is an identifier generated and sent to the master device in the case of successful historical authentication; the first session key is a key generated by the master device based on a target key protocol; the auxiliary device is a device obtained by the master device when the smart home device is in a powered-on state and the master device receives a connection instruction and that matches the target device carried in the connection instruction; the target device is a smart home device that has been historically authenticated with the master device; the master device is a device in the smart home device; Decrypt the first ciphertext message using a second session key to obtain a first decrypted identifier; the second session key is a key generated based on the target key protocol; If the short-term identifier stored by the auxiliary device matches the first decrypted identifier, determine successful authentication with the master device, and send an authentication passed message to the master device; Receive a control instruction sent by the master device.

7. The method according to claim 6, characterized in that, After the auxiliary device determines successful authentication with the master device and sends an authentication passed message to the master device if the short-term identifier stored by the auxiliary device matches the first decrypted identifier, the method further includes: Generate an updated short-term identifier, and send the updated short-term identifier to the master device; so that the master device updates the short-term identifier in the first volatile memory corresponding to the master device to the updated short-term identifier; Update the short-term identifier in the second volatile memory corresponding to the auxiliary device to the updated short-term identifier.

8. The method according to claim 7, wherein After decrypting the first ciphertext information with the second session key to obtain the first decryption identifier, the method further includes: If the first decryption identifier does not match the short-term identifier in the second volatile memory, obtain the first short-term authentication count; If the first short-term authentication count is greater than or equal to the first preset short-term authentication count, delete the short-term identifier in the second volatile memory.

9. An authentication device for a smart home device, characterized in that, Applied to the master device, the apparatus includes: An auxiliary device determination module, configured to obtain a device that matches the target device carried in the connection instruction when the smart home device is in the powered-on state and the connection instruction is received, to obtain an auxiliary device; the target device is a smart home device that has been historically authenticated with the master device; the master device is a device in the smart home device; A first ciphertext information determination module, configured to obtain a short-term identifier stored locally that matches the auxiliary device, and encrypt the short-term identifier with a first session key to obtain first ciphertext information; the short-term identifier is an identifier generated by the auxiliary device and sent to the master device when historical authentication is passed; the first session key is a key generated based on a target key protocol; A first ciphertext information sending module, configured to send the first ciphertext information to the auxiliary device; so that the auxiliary device decrypts the first ciphertext information with a second session key to obtain a first decryption identifier; so that if the short-term identifier stored by the auxiliary device matches the first decryption identifier, the auxiliary device determines that authentication with the master device is successful, and sends an authentication passed message to the master device; the second session key is a key generated by the auxiliary device based on the target key protocol; A control instruction sending module, configured to send a control instruction to the auxiliary device.

10. An authentication device for a smart home device, characterized in that, Applied to the auxiliary device, the apparatus includes: A first receiving module, configured to receive the first ciphertext information sent by the master device; the first ciphertext information is ciphertext information obtained by the master device by obtaining a short-term identifier stored locally that matches the auxiliary device and encrypting the short-term identifier with a first session key; the short-term identifier is an identifier generated and sent to the master device when historical authentication is passed; the first session key is a key generated by the master device based on a target key protocol; the auxiliary device is a device obtained by the master device that matches the target device carried in the connection instruction when the smart home device is in the powered-on state and the master device receives the connection instruction; the target device is a smart home device that has been historically authenticated with the master device; The master device is a device in the smart home device; A decryption module, configured to decrypt the first ciphertext information with a second session key to obtain a first decryption identifier; the second session key is a key generated based on the target key protocol; An authentication module, configured to determine that authentication with the master device is successful and send an authentication passed message to the master device if the short-term identifier stored by the auxiliary device matches the first decryption identifier; The second receiving module is used to receive the control instruction sent by the master device.