Internet of Things communication method, device, system and medium
Through the encryption authentication development toolkit integrated or independently operated on the energy IoT platform, the secure connection between the device and the platform is achieved, and the communication security controllability problem under different local area networks is solved, the access cost is reduced and the platform's generalization ability is improved.
Patent Information
- Application Number
- CN202510714815.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-07-11
AI Technical Summary
The communication security controllability of energy IoT platforms and IoT devices under different local area networks, and traditional methods increase access costs and reduce the platform's generalization capabilities.
The encryption authentication mechanism adopts the reverse proxy method, and integrates or runs independently on the energy IoT platform through the encryption authentication development toolkit, communicates with the platform, performs key verification, port mapping and handshake authentication, establishes a data forwarding channel, and realizes a secure connection between the device and the platform.
It solves the problem of communication security controllability under different local area networks, reduces the cost of access to IoT devices, improves the generalization capabilities and security of the platform, and does not require upgrading and transformation of equipment.
Smart Images

Figure CN120301702A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of the Internet of Things, and particularly to an Internet of Things communication method, device, system and medium. Background Art
[0002] Due to the relevant requirements for energy data security, the energy Internet of Things platform is generally deployed and applied in a local intranet (unidirectional intranet, that is, some network domains can access the Internet, but do not provide services externally; or the ability to provide services externally is limited and cannot be expanded), while Internet of Things devices in actual scenarios are generally applied in a public network environment. To solve the problem that the energy Internet of Things platform (intranet) and Internet of Things devices (extranet) are not in the same network environment, the traditional method is to use network slicing technology or build a private network for network interconnection. However, the cost of building a private network is generally higher than that of a common public network, and the service-providing ability of the intranet server is limited, with a high expansion cost. Secondly, there are a wide variety of Internet of Things devices with inconsistent standards. If unified communication authentication with a single Internet of Things platform is carried out, the solution is usually that the Internet of Things device itself synchronously supports the encryption authentication process according to the requirements of the energy Internet of Things platform. However, this method reduces the generalization ability of the Internet of Things platform and increases the access cost. Summary of the Invention
[0003] The purpose of the present invention is to provide an Internet of Things communication method, device, system and medium, which can solve the problem of secure and controllable communication between Internet of Things devices and the energy Internet of Things platform in different local area networks, improve the generalization ability of the energy Internet of Things platform, and reduce the access cost of Internet of Things devices accessing the platform.
[0004] To solve the above technical problems, the present invention provides an Internet of Things communication method for a server, including:
[0005] Verifying a license key carried by an encryption authentication development kit; the encryption authentication development kit is integrated on the energy Internet of Things platform; or, the encryption authentication development kit runs independently and communicates and couples with the energy Internet of Things platform;
[0006] After the key verification is successful, determining a target port applied for by the encryption authentication development kit according to a pre-configured port mapping relationship;
[0007] When an Internet of Things device connects to the target port, performing a handshake authentication with the encryption authentication development kit;
[0008] After the handshake authentication is successful, receiving a data request from the Internet of Things device, and sending the data request to the encryption authentication development kit, so that the encryption authentication development kit obtains reply data from the energy Internet of Things platform and forwards it to the server;
[0009] Receive the reply data and send the reply data to the Internet of Things device.
[0010] In a first aspect, in the above-mentioned Internet of Things communication method provided by the present invention, before verifying the license key carried by the encryption authentication development kit, it further includes:
[0011] Receive a key application instruction;
[0012] In response to the key application instruction, based on the encryption authentication development kit, generate a corresponding license key for the service to be opened in the energy Internet of Things platform;
[0013] Correspondingly, authenticating the license key carried by the encryption authentication development kit includes:
[0014] Communicate with the encryption authentication development kit through the command channel between the encryption authentication development kit and the server to verify the license key carried by the encryption authentication development kit;
[0015] If the license key carried by the encryption authentication development kit is consistent with any generated license key, it is determined that the password verification is successful.
[0016] In another aspect, in the above-mentioned Internet of Things communication method provided by the present invention, before determining the target port applied for by the encryption authentication development kit according to the pre-configured port mapping relationship, it further includes:
[0017] Configure the service to be opened in the energy Internet of Things platform to be mapped to the corresponding port to obtain a port mapping relationship;
[0018] At the same time, classify and manage the ports participating in the mapping to obtain a port pool;
[0019] Correspondingly, determining the target port applied for by the encryption authentication development kit according to the pre-configured port mapping relationship includes:
[0020] According to the port mapping relationship, determine the target port applied for by the license key carried by the encryption authentication development kit in the port pool.
[0021] In another aspect, in the above-mentioned Internet of Things communication method provided by the present invention, after determining the target port applied for by the encryption authentication development kit, it further includes:
[0022] Start listening on the target port in the external network environment; at this time, the target port is open but in an unreadable state.
[0023] On the other hand, in the above-mentioned Internet of Things communication method provided by the present invention, when the Internet of Things device connects to the target port, a handshake authentication with the encryption authentication development kit is performed, including:
[0024] When the Internet of Things device connects to the target port, an activation event of the target port is triggered; at this time, the target port is in a non-readable state;
[0025] A tourist access channel open to the Internet of Things device is created and set to a temporarily non-readable state;
[0026] A connection message command is sent to the encryption authentication development kit, so that the encryption authentication development kit establishes a data forwarding channel between the encryption authentication development kit and the server according to the connection message command, and returns a channel establishment success message to the server;
[0027] After receiving the success message, the tourist access channel and the target port are set to a readable state to complete the handshake authentication between the server and the encryption authentication development kit.
[0028] On the other hand, in the above-mentioned Internet of Things communication method provided by the present invention, after triggering the activation event of the target port, it further includes:
[0029] According to the port mapping relationship, the proxy service corresponding to the target port is determined;
[0030] Correspondingly, a connection message command is sent to the encryption authentication development kit, so that the encryption authentication development kit establishes a data forwarding channel between the encryption authentication development kit and the server according to the connection message command, including:
[0031] A connection message command carrying the configuration information of the proxy service is sent to the encryption authentication development kit through the command channel between the encryption authentication development kit and the server, so that the encryption authentication development kit receives and parses the configuration information, establishes a service real channel with the proxy service, and at the same time establishes a data forwarding channel between the encryption authentication development kit and the server, and maintains the mapping rule between the data forwarding channel and the service real channel.
[0032] On the other hand, in the above-mentioned Internet of Things communication method provided by the present invention, sending the data request to the encryption authentication development kit so that the encryption authentication development kit obtains the reply data of the energy Internet of Things platform and forwards it to the server, including:
[0033] Trigger a channel data monitoring event, and send the data request to the encryption authentication development kit through the data forwarding channel, so that the encryption authentication development kit forwards the data request to the energy Internet of Things platform according to the mapping rule between the data forwarding channel and the service real channel; after the energy Internet of Things platform processes the data request, return reply data to the encryption authentication development kit; the encryption authentication development kit forwards the reply data to the server.
[0034] To solve the above technical problems, the present invention also provides an Internet of Things communication device for a server, including:
[0035] A key verification module, used to verify the license key carried by the encryption authentication development kit; the encryption authentication development kit is integrated on the energy Internet of Things platform; or, the encryption authentication development kit runs independently and communicates and couples with the energy Internet of Things platform;
[0036] A port determination module, used to determine the target port applied for by the encryption authentication development kit according to the pre-configured port mapping relationship after the key verification is successful;
[0037] A handshake authentication module, used to perform handshake authentication with the encryption authentication development kit when the Internet of Things device connects to the target port;
[0038] A request forwarding module, used to receive the data request of the Internet of Things device after the handshake authentication is successful, and send the data request to the encryption authentication development kit, so that the encryption authentication development kit obtains the reply data of the energy Internet of Things platform and forwards it to the server;
[0039] A data transmission module, used to receive the reply data and send the reply data to the Internet of Things device.
[0040] To solve the above technical problems, the present invention also provides a communication system, including: a server, an energy Internet of Things platform, and an Internet of Things device;
[0041] Wherein, the server is used to verify the license key carried by the encryption authentication development kit; the encryption authentication development kit is integrated on the energy Internet of Things platform; or, the encryption authentication development kit runs independently and communicates and couples with the energy Internet of Things platform; after the key verification is successful, determine the target port applied for by the encryption authentication development kit according to the pre-configured port mapping relationship; when the Internet of Things device connects to the target port, perform handshake authentication with the encryption authentication development kit; after the handshake authentication is successful, receive the data request of the Internet of Things device and send the data request to the encryption authentication development kit;
[0042] The encryption authentication development kit is used to obtain the response data of the energy Internet of Things platform and forward it to the server.
[0043] The server is further configured to receive the response data and send the response data to the Internet of Things device.
[0044] As can be seen from the above technical solutions, an Internet of Things communication method provided by the present invention includes: verifying a license key carried by an encryption authentication development kit; the encryption authentication development kit is integrated on an energy Internet of Things platform; or, the encryption authentication development kit runs independently and communicates and couples with the energy Internet of Things platform; after the key verification is successful, determine a target port applied for by the encryption authentication development kit according to a pre-configured port mapping relationship; when an Internet of Things device connects to the target port, perform a handshake authentication with the encryption authentication development kit; after the handshake authentication is successful, receive a data request from the Internet of Things device, and send the data request to the encryption authentication development kit, so that the encryption authentication development kit obtains the response data of the energy Internet of Things platform and forwards it to the server; receive the response data and send the response data to the Internet of Things device.
[0045] The beneficial effect of the present invention is that the above Internet of Things communication method provided by the present invention uses an encryption authentication mechanism based on a reverse proxy method to replace the dedicated line and private network solution. By using a server in combination with an encryption authentication development kit, the energy Internet of Things platform and the Internet of Things device can be connected and communicate, which can solve the problem of communication security and controllability between the Internet of Things device and the energy Internet of Things platform in different local area networks. It has little intrusion into the energy Internet of Things platform, does not require upgrading and transforming the Internet of Things device, improves the efficiency of access applications, enhances the generalization ability of the energy Internet of Things platform, reduces the access cost of the Internet of Things device accessing the energy Internet of Things platform, and ensures security.
[0046] In addition, the present invention also provides a corresponding Internet of Things communication device, communication system and computer-readable storage medium for the Internet of Things communication method, which have the same or corresponding technical features as the above-mentioned Internet of Things communication method, and the effects are the same. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0048] Figure 1 It is a flowchart of the Internet of Things communication method provided by an embodiment of the present invention.
[0049] Figure 2 Schematic framework diagram of the Internet of Things communication method provided by an embodiment of the present invention;
[0050] Figure 3 Schematic diagram of the authentication stage of services to be developed on the energy Internet of Things platform provided by an embodiment of the present invention;
[0051] Figure 4 Schematic diagram of the handshake authentication stage between the encryption authentication development toolkit and the server provided by an embodiment of the present invention;
[0052] Figure 5 Schematic diagram of the communication stage between the energy Internet of Things platform and Internet of Things devices provided by an embodiment of the present invention;
[0053] Figure 6 Schematic diagram of the structure of the Internet of Things communication device provided by an embodiment of the present invention. Detailed implementation manners
[0054] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0055] It should be noted that in the description of the present invention, the terms "include", "comprise" or any other variant thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or device including a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present invention are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0056] In order to enable those skilled in the art of the present technology to better understand the solution of the present invention, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.
[0057] In combination with the specific application environment architecture or specific hardware architecture on which the execution of the Internet of Things communication method depends, the specific application environment architecture or specific hardware architecture will be described herein.
[0058] An embodiment of the present invention provides an Internet of Things communication method. In combination with the execution process of the Internet of Things communication method, the method will be described in detail. Figure 1 Flowchart of the Internet of Things communication method provided by an embodiment of the present invention, as Figure 1 shown, the method includes:
[0059] S101. Verify the license key carried by the encryption authentication development kit; the encryption authentication development kit is integrated on the energy Internet of Things platform; or, the encryption authentication development kit runs independently and communicates and couples with the energy Internet of Things platform.
[0060] Figure 2 This is a framework schematic diagram of the Internet of Things communication method provided by the embodiments of the present invention. As Figure 2 shown, compared with the original energy Internet of Things platform communication solution, the present invention adds a set of methods for encrypting, authenticating, and monitoring communication channels between Internet of Things devices and the energy Internet of Things platform. The encryption authentication development kit (Software Development Kit, SDK) provided by the present invention is a third-party secondary development kit with built-in encryption authentication scheduling algorithms and used in cooperation with the server. The encryption authentication development kit can be integrated into the existing energy Internet of Things platform and supports coupling through communication call methods such as caching, message middleware, inner classes, Transmission Control Protocol (TCP), Remote Procedure Call (RCP), and Hyper Text Transfer Protocol (HTTP); it can also run independently and communicate and couple with the original energy Internet of Things platform. The server here can be an encryption authentication server, which refers to a server used to provide encryption and authentication services, and its core function is to ensure the security of network communication, data transmission, and user access. The encryption authentication server can protect data through encryption to prevent information from being stolen or tampered with during transmission or storage; at the same time, it verifies the identity of users, systems, or systems through an authentication mechanism to ensure that only authorized objects can access resources.
[0061] When performing step S101, the encryption authentication development kit can be automatically or manually started first, and then the server verifies the license carried by the encryption authentication development kit.
[0062] S102. After the key verification is successful, determine the target port applied for by the encryption authentication development kit according to the pre-configured port mapping relationship.
[0063] When performing step S102 after the password verification in step S101 is successful, the server can determine the target port of the license application of the encryption authentication development kit according to the pre-configured port mapping relationship.
[0064] S103. When the Internet of Things device connects to the target port, perform a handshake authentication with the encryption authentication development kit.
[0065] Step S103 can automatically complete the handshake authentication between the encryption authentication development kit and the server, and establish a corresponding proxy channel.
[0066] S104. After the handshake authentication is successful, receive the data request of the IoT device, and send the data request to the encryption authentication development kit, so that the encryption authentication development kit can obtain the response data of the energy IoT platform and forward it to the server.
[0067] When executing step S104, after the handshake success channel is ready, the server and the IoT device can use the proxy channel to complete the communication with the IoT platform.
[0068] S105. Receive the response data and send the response data to the IoT device.
[0069] It should be noted that the server of the present invention can complete functions such as encryption authentication management, communication channel speed limit and monitoring, and scheduling algorithm control between the energy IoT platform and the IoT device. It is the message transfer center of the present invention and supports distribution.
[0070] In the above IoT communication method provided by the embodiments of the present invention, the encryption authentication mechanism based on the reverse proxy method replaces the dedicated line and private network solution. By using the server in combination with the encryption authentication development kit, the connection and communication between the energy IoT platform and the IoT device are realized, which can solve the problem of secure and controllable communication between the IoT device and the energy IoT platform in different local area networks, has little intrusion into the energy IoT platform, does not require upgrading and transforming the IoT device, improves the efficiency of access applications, enhances the generalization ability of the energy IoT platform, reduces the access cost of the IoT device accessing the energy IoT platform, and ensures security.
[0071] Further, in specific implementation, in the above IoT communication method provided by the embodiments of the present invention, before verifying the license key carried by the encryption authentication development kit in step S101, it may further include: receiving a key application instruction; in response to the key application instruction, based on the encryption authentication development kit, generating a corresponding license key for the service to be opened in the energy IoT platform.
[0072] Correspondingly, step S101 authenticates the license key carried by the encryption authentication development kit. Specifically, it may include: communicating with the encryption authentication development kit through the command channel (cmd Tunnel) between the encryption authentication development kit and the server to verify the license key carried by the encryption authentication development kit; if the license key carried by the encryption authentication development kit is consistent with any generated license key, it is determined that the password verification is successful.
[0073] In implementation, the server of the present invention has a configuration management function. The server may include a license management module. When the energy Internet of Things platform releases and provides services externally, based on the encryption authentication development kit, this license management module is used to manage the license key for providing services, and can control the service's ability to provide services externally, including whether to limit the speed, whether to enable, etc. The energy Internet of Things platform can complete the handshake with the server based on the development kit, carrying the License. The core fields included can be as follows: "license name, license key, user identity, upload speed limit, download speed limit, whether online (1. Online; 2. Offline), whether enabled (1. Enabled; 2. Disabled), creation time, update time", and has functions such as "reset license key, disable license key".
[0074] Figure 3 It is a schematic diagram of the authentication stage of the to-be-developed service of the energy Internet of Things platform provided by the embodiment of the present invention. As Figure 3 shown, based on the encryption authentication development kit, apply for a license key on the server, and this key is applied one-to-one to the specific service to be opened by the energy Internet of Things platform. The encryption authentication development kit can carry the license key and communicate with the server using the command channel. The server verifies the availability of the key and updates the license status within the platform. Here, the command channel is a hidden basic channel for the command interaction channel between the encryption authentication development kit and the server. The commands here can include the communication handshake commands for completing the communication between the encryption authentication development kit and the authentication server, or other inherent hidden commands within the system.
[0075] Furthermore, in specific implementation, in the above-mentioned Internet of Things communication method provided by the embodiment of the present invention, before performing step S102 to determine the target port applied for by the encryption authentication development kit according to the pre-configured port mapping relationship, it may further include: configuring the to-be-opened services in the energy Internet of Things platform to be mapped to the corresponding ports to obtain the port mapping relationship; at the same time, classifying and managing the ports participating in the mapping to obtain the port pool.
[0076] Correspondingly, step S102 determines the target port applied for by the encryption authentication development kit according to the pre-configured port mapping relationship, and specifically may include: determining the target port applied for by the license key carried by the encryption authentication development kit in the port pool according to the port mapping relationship.
[0077] In implementation, the server of the present invention may further include a port mapping module. The port mapping module can proxy and forward relevant services of the energy Internet of Things platform to corresponding ports to provide services externally, thereby increasing the capabilities and security of the energy Internet of Things platform from the external perspective in an intranet environment. The function of the port mapping module is mainly used for the configuration management function of mapping specific services to a specific external network port. The core fields it contains can be as follows: "service license, coupling form (such as message middleware, internal class, TCP, RCP, HTTP), IP and PORT of the energy Internet of Things platform service when the coupling form is TCP, upload speed limit, download speed limit, whether online (1, online; 2, offline), number of proxy response data packets, proxy timeout in milliseconds, whether enabled (1, enabled; 2, disabled), creation time, update time", and it has functions such as "start / stop, speed limit mapping relationship".
[0078] The server of the present invention may further include a service port pool management module. To prevent problems such as service abuse and service grouping management during the process of providing services externally, and to classify and manage services and ports more systematically with different permissions, the service port pool management module can classify and manage the ports participating in the mapping. The core fields it contains are: "group name, owner type (0, globally shared; 1, user-owned; 2, license-owned), whether enabled (1, enabled; 2, disabled), creation time, update time".
[0079] The present invention can determine the target port applied for by the license in the port pool according to the port mapping relationship configured on the server. The port pool here centrally manages available ports, avoiding the disorderly occupation or idleness of ports and improving the overall resource utilization rate. The port mapping relationship can be dynamically adjusted according to the service load. When the traffic of a certain type of service surges, the port pool can quickly allocate more target ports to avoid service response delays or connection refusals caused by insufficient ports. The server centrally manages the port mapping relationship, eliminating the need to configure ports separately for each service, reducing the operation and maintenance complexity. When a new service or an extended service instance is added, the target port can be directly applied for from the port pool to quickly complete the deployment without manually coordinating port conflict issues, improving the service online efficiency.
[0080] Further, in specific implementation, in the above steps, after determining the target port applied for by the encryption authentication development kit, it may further include: starting the listening of the target port in the external network environment; at this time, the target port is open but in an unreadable state.
[0081] In implementation, after determining the target port of the encrypted authentication development kit application, the present invention can initiate the listening of this port in the external network environment. At this time, the port is open but unreadable. This can confuse the attacker's detection of the system, and the attacker cannot read the encrypted content, protecting the confidentiality of data transmission. And only after completing the authentication process can the permission to read the port data be obtained, ensuring that all data interactions are authenticated, significantly enhancing data security.
[0082] Further, in specific implementation, in the above-mentioned Internet of Things communication method provided by the embodiment of the present invention, when the Internet of Things device connects to the target port in step S103, a handshake authentication with the encrypted authentication development kit is performed, which may specifically include: when the Internet of Things device connects to the target port, triggering the activation event of the target port; at this time, the target port is in an unreadable state; creating a visitor access channel (visitor Tunnel) open to the Internet of Things device and setting it to a temporarily unreadable state; sending a connection message command to the encrypted authentication development kit, so that the encrypted authentication development kit establishes a data forwarding channel (data TransferTunnel) between the encrypted authentication development kit and the server according to the connection message command, and returns a channel establishment success message to the server; after receiving the success message, setting the visitor access channel and the target port to a readable state to complete the handshake authentication between the server and the encrypted authentication development kit.
[0083] In implementation, the visitor access channel is a communication channel opened by the server to the Internet of Things device and is used as the actual data interaction channel, and speed limit configuration can be performed. The data forwarding channel is the data channel between the encrypted authentication development kit and the server, which forwards the data in the real channel of the service to be proxied. Through this data forwarding channel, the data is forwarded to the server, and then the server forwards it to the visitor access channel, thereby completing the proxy forwarding of the data. The relevant traffic monitoring is recorded and monitored during the forwarding process. During the process, the data is encrypted according to the user's encryption requirements. It should be noted that the data forwarding channel can only be used after authentication is completed, and the actual data transmission of the service to be proxied also uses this channel.
[0084] Figure 4 It is a schematic diagram of the handshake authentication stage between the encrypted authentication development kit and the server provided by the embodiment of the present invention. As Figure 4As shown, the target port of the service to be opened is already in the ready state. When the IoT device connects to this target port, it first triggers the activation event of the target port. According to the maintained port mapping information, it searches for the proxy intranet service (i.e., the service to be proxied) corresponding to the port. Then it initializes the visitor access channel. The visitor access channel is temporarily unreadable and waits to be readable after the client proxy is established; it sends a connection message command using the command channel. The encryption authentication development kit can, according to the connection message command, establish a data forwarding channel between the encryption authentication development kit and the server, and return a message indicating the successful establishment of the channel to the server; after receiving the success message, it sets the visitor access channel and the target port to the readable state, and at this time, the handshake authentication between the server and the encryption authentication development kit is completed.
[0085] Furthermore, in specific implementation, in the above steps, after triggering the activation event of the target port, it may further include: determining the service to be proxied corresponding to the target port according to the port mapping relationship.
[0086] Correspondingly, in the above steps, sending a connection message command to the encryption authentication development kit so that the encryption authentication development kit can, according to the connection message command, establish a data forwarding channel between the encryption authentication development kit and the server may specifically include: sending a connection message command carrying the configuration information of the service to be proxied to the encryption authentication development kit through the command channel between the encryption authentication development kit and the server, so that the encryption authentication development kit receives and parses the configuration information, establishes a real service channel (real Tunnel) with the service to be proxied, at the same time establishes a data forwarding channel between the encryption authentication development kit and the server, and maintains the mapping rule between the data forwarding channel and the real service channel.
[0087] In implementation, the real service channel is the channel between the service to be proxied and the encryption authentication development kit (including forms such as message middleware, inner classes, TCP, RCP, HTTP, etc.), that is, the channel between the energy IoT platform and the encryption authentication development kit.
[0088] Such as Figure 4As shown in the figure, during the process of sending connection message data through the command channel, relevant configuration information of the service to be proxied (such as message middleware, inner class, TCP, RCP, HTTP, etc. configuration information) can be carried. For example, when the mode is TCP, the IP and Port are carried. Receive and parse the proxy configuration information, such as IP and Port; establish a real connection according to the IP and Port, that is, the real service to be proxied, and set it to the non-readable state of the channel, and maintain the real channel of the service. Establish a data forwarding channel (i.e., proxy channel), and maintain the mapping relationship with the real service channel, and return a message indicating that the channel establishment is successful. After the encryption authentication server receives the successful message, set the tourist access channel readable and the target port readable, so as to complete the handshake authentication stage between the development toolkit and the server.
[0089] Further, in specific implementation, in the above-mentioned Internet of Things communication method provided by the embodiment of the present invention, step S104 sends a data request to the encryption authentication development toolkit, so that the encryption authentication development toolkit obtains the reply data of the energy Internet of Things platform and forwards it to the server, which may specifically include: triggering a channel data monitoring event, and sending the data request to the encryption authentication development toolkit through the data forwarding channel, so that the encryption authentication development toolkit forwards the data request to the energy Internet of Things platform according to the mapping rule between the data forwarding channel and the real service channel; after the energy Internet of Things platform processes the data request, it returns the reply data to the encryption authentication development toolkit; the encryption authentication development toolkit forwards the reply data to the server.
[0090] Figure 5 It is a schematic diagram of the communication stage between the energy Internet of Things platform and the Internet of Things device provided by the embodiment of the present invention. As Figure 5 shown, the tourist access channel, the data forwarding channel, and the target port are already in the ready-to-read / write state. When the Internet of Things device initiates a data request, the channel data monitoring event is triggered, and the encryption authentication server uses the data forwarding channel to send the device request data. The encryption authentication development toolkit can forward the data to the service proxied by the energy Internet of Things platform according to the key / value mapping between the data forwarding channel and the real service channel. The energy Internet of Things platform processes the data to obtain the reply data, returns the reply data to the encryption authentication development toolkit, and the encryption authentication development toolkit forwards the reply data to the server through the data forwarding channel to complete the reply of the Internet of Things device data.
[0091] In practical applications, the server may further include a monitoring report module, which can count statistical report information such as user traffic, license traffic, and daily / yearly / monthly traffic according to different spatial and temporal dimensions. This can accurately locate the hotspots of resource consumption, effectively analyze the traffic trend, and improve the resource management efficiency.
[0092] It should be noted that the energy Internet of Things platform (intranet) and Internet of Things devices (extranet) are not in the same network environment. The Internet of Things communication method provided by the present invention is based on the idea of reverse proxy technology, and can replace the dedicated line and private network solution through software encryption authentication. The two network environments are connected through software encryption and communication channel authentication management methods, ensuring security and controllability, and effectively reducing the cost of dedicated lines and private networks.
[0093] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method.
[0094] The embodiments of the present application also provide an Internet of Things communication device. Figure 6 It is a schematic structural diagram of the Internet of Things communication device provided by the embodiments of the present invention. Based on the perspective of functional modules, as Figure 6 shown, this device is used for the server and includes:
[0095] A key verification module 10, which is used to verify the license key carried by the encryption authentication development kit; the encryption authentication development kit is integrated on the energy Internet of Things platform; or, the encryption authentication development kit runs independently and communicates and couples with the energy Internet of Things platform;
[0096] A port determination module 11, which is used to determine the target port applied for by the encryption authentication development kit according to the pre-configured port mapping relationship after the key verification is successful;
[0097] A handshake authentication module 12, which is used to perform a handshake authentication with the encryption authentication development kit when the Internet of Things device connects to the target port;
[0098] A request forwarding module 13, which is used to receive the data request of the Internet of Things device after the handshake authentication is successful, and send the data request to the encryption authentication development kit, so that the encryption authentication development kit can obtain the reply data of the energy Internet of Things platform and forward it to the server;
[0099] A data transmission module 14, which is used to receive the reply data and send the reply data to the Internet of Things device.
[0100] In the above-mentioned Internet of Things communication device provided by the embodiments of the present invention, through the interaction of the above five modules, an encryption authentication mechanism based on the reverse proxy method can replace the dedicated line and private network solution. By using the server in combination with the encryption authentication development toolkit, the connection and communication between the energy Internet of Things platform and the Internet of Things devices can be realized, which can solve the problem of secure and controllable communication between the Internet of Things devices and the energy Internet of Things platform under different local area networks. It has little intrusion into the energy Internet of Things platform, does not require upgrading and transformation of the Internet of Things devices, improves the efficiency of access applications, enhances the generalization ability of the energy Internet of Things platform, reduces the access cost of the Internet of Things devices accessing the energy Internet of Things platform, and ensures security.
[0101] Since the embodiments of the Internet of Things communication device part correspond to the embodiments of the Internet of Things communication method part, the description of the features in the corresponding embodiments of the Internet of Things communication device can refer to the relevant descriptions of the corresponding embodiments of the Internet of Things communication method, which will not be elaborated here one by one. And it has the same beneficial effects as the above-mentioned Internet of Things communication method.
[0102] The embodiments of the present application also provide a communication system, including a server, an energy Internet of Things platform, and Internet of Things devices; wherein, the server is used to verify the license key carried by the encryption authentication development toolkit; the encryption authentication development toolkit is integrated on the energy Internet of Things platform; or, the encryption authentication development toolkit runs independently and communicates and couples with the energy Internet of Things platform; after the key verification is successful, according to the pre-configured port mapping relationship, determine the target port applied for by the encryption authentication development toolkit; when the Internet of Things device connects to the target port, perform a handshake authentication with the encryption authentication development toolkit; after the handshake authentication is successful, receive the data request of the Internet of Things device and send the data request to the encryption authentication development toolkit; the encryption authentication development toolkit is used to obtain the reply data of the energy Internet of Things platform and forward it to the server; the server is also used to receive the reply data and send the reply data to the Internet of Things device.
[0103] The embodiments of the present invention also provide a computer-readable storage medium, in which a computer program is stored. Wherein, the computer program is set to execute the steps in any of the above-mentioned Internet of Things communication method embodiments when running.
[0104] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: USB flash drive, read-only memory (abbreviated as ROM), random access memory (abbreviated as RAM), mobile hard disk, magnetic disk, or optical disc and other various media that can store computer programs.
[0105] An embodiment of the present invention also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-described embodiments of the Internet of Things communication method.
[0106] An embodiment of the present invention also provides another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-described embodiments of the Internet of Things communication method.
[0107] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0108] The above has introduced in detail an Internet of Things communication method, device, system, and medium provided by the present invention. Specific examples are used herein to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the present invention.
Claims
1. An Internet of Things communication method, characterized in that, For the server side, including: Verify the license key carried by the encryption authentication development kit; the encryption authentication development kit is integrated on the energy Internet of Things platform; or, the encryption authentication development kit runs independently and communicates and couples with the energy Internet of Things platform; After the key verification is successful, determine the target port applied for by the encryption authentication development kit according to the pre-configured port mapping relationship; When the Internet of Things device connects to the target port, perform a handshake authentication with the encryption authentication development kit; After the handshake authentication is successful, receive the data request of the Internet of Things device, and send the data request to the encryption authentication development kit, so that the encryption authentication development kit obtains the reply data of the energy Internet of Things platform and forwards it to the server side; Receive the reply data and send the reply data to the Internet of Things device.
2. The Internet of Things communication method according to claim 1, wherein Before verifying the license key carried by the encryption authentication development kit, it further includes: Receive a key application instruction; In response to the key application instruction, based on the encryption authentication development kit, generate a corresponding license key for the service to be opened in the energy Internet of Things platform; Correspondingly, authenticating the license key carried by the encryption authentication development kit includes: Communicate with the encryption authentication development kit through the command channel between the encryption authentication development kit and the server to verify the license key carried by the encryption authentication development kit; If the license key carried by the encryption authentication development kit is consistent with any generated license key, it is determined that the password verification is successful.
3. The Internet of Things communication method according to claim 1, wherein Before determining the target port applied for by the encryption authentication development kit according to the pre-configured port mapping relationship, it further includes: Configure the services to be opened in the energy Internet of Things platform to be mapped to corresponding ports to obtain a port mapping relationship; At the same time, classify and manage the ports participating in the mapping to obtain a port pool; Correspondingly, determining the target port applied for by the encryption authentication development kit according to the pre-configured port mapping relationship includes: Determine the target port applied for by the license key carried by the encryption authentication development kit in the port pool according to the port mapping relationship.
4. The Internet of Things communication method according to claim 1, wherein After determining the target port applied for by the encryption authentication development kit, it further includes: Start listening on the target port in the external network environment; at this time, the target port is open but in a non-readable state.
5. The Internet of Things communication method according to claim 1, wherein, When the Internet of Things device connects to the target port, performing a handshake authentication with the encryption authentication development kit includes: When the Internet of Things device connects to the target port, trigger the activation event of the target port; at this time, the target port is in a non-readable state; Create a tourist access channel open to the Internet of Things device and set it to a temporarily non-readable state; Send a connection message command to the encryption authentication development kit, so that the encryption authentication development kit establishes a data forwarding channel between the encryption authentication development kit and the server side according to the connection message command and returns a channel establishment success message to the server side; After receiving the success message, set the tourist access channel and the target port to the readable state to complete the handshake authentication between the server and the encryption authentication development kit.
6. The Internet of Things communication method according to claim 5, characterized in that, After triggering the activation event of the target port, it further includes: Determine the proxy service corresponding to the target port according to the port mapping relationship; Correspondingly, send a connection message command to the encryption authentication development kit, so that the encryption authentication development kit establishes a data forwarding channel between the encryption authentication development kit and the server according to the connection message command, including: Send a connection message command carrying the configuration information of the proxy service to the encryption authentication development kit through the command channel between the encryption authentication development kit and the server, so that the encryption authentication development kit receives and parses the configuration information, establishes a service real channel with the proxy service, and at the same time establishes a data forwarding channel between the encryption authentication development kit and the server, and maintains the mapping rule between the data forwarding channel and the service real channel.
7. The Internet of Things communication method according to claim 6, wherein Send the data request to the encryption authentication development kit, so that the encryption authentication development kit obtains the response data of the energy Internet of Things platform and forwards it to the server, including: Trigger a channel data monitoring event, and send the data request to the encryption authentication development kit through the data forwarding channel, so that the encryption authentication development kit forwards the data request to the energy Internet of Things platform according to the mapping rule between the data forwarding channel and the service real channel; after the energy Internet of Things platform processes the data request, return the response data to the encryption authentication development kit; the encryption authentication development kit forwards the response data to the server.
8. An Internet of Things communication device, characterized in that, For the server, it includes: A key verification module for verifying the license key carried by the encryption authentication development kit; the encryption authentication development kit is integrated on the energy Internet of Things platform; or, the encryption authentication development kit runs independently and communicates and couples with the energy Internet of Things platform; A port determination module for determining the target port applied for by the encryption authentication development kit according to the pre-configured port mapping relationship after successful key verification; A handshake authentication module for performing handshake authentication with the encryption authentication development kit when the Internet of Things device connects to the target port; A request forwarding module for receiving the data request of the Internet of Things device after successful handshake authentication, and sending the data request to the encryption authentication development kit, so that the encryption authentication development kit obtains the response data of the energy Internet of Things platform and forwards it to the server; A data transmission module for receiving the response data and sending the response data to the Internet of Things device.
9. A communication system, characterized in that, It includes: A server, an energy Internet of Things platform, and an Internet of Things device; Among them, the server is used to verify the license key carried by the encryption authentication development kit; the encryption authentication development kit is integrated on the energy Internet of Things platform; or, the encryption authentication development kit runs independently and communicates and couples with the energy Internet of Things platform; after the key verification is successful, determine the target port applied for by the encryption authentication development kit according to the pre-configured port mapping relationship; when the Internet of Things device connects to the target port, perform a handshake authentication with the encryption authentication development kit; after the handshake authentication is successful, receive the data request of the Internet of Things device and send the data request to the encryption authentication development kit; The encryption authentication development kit is used to obtain the response data of the energy Internet of Things platform and forward it to the server; The server is further used to receive the response data and send the response data to the Internet of Things device.
10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the Internet of Things communication method according to any one of claims 1 to 7 are implemented.