Internet of Things equipment authentication method and device

Through the IoT device authentication method, the terminal information is decrypted using the encryption key, the device authorization is verified and the dynamic username is generated, which solves the problem of the difficulty of logging in IoT devices and the difficulty of operation and maintenance, and achieves higher security and maintainability.

CN120378877APending Publication Date: 2025-07-25QINGDAO HAIER AIR CONDITIONING ELECTRONICS CO LTD +2
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202410588197.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-13
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the prior art, the login security of IoT devices is poor and difficult to operate and maintain, and the user account management is cumbersome, resulting in passwords being easily lost and it is difficult to ensure security.

Method used

The IoT device authentication method is adopted, and the terminal identifier, device identifier, user name and encryption password sent by the receiving terminal, the pre-received encryption key is used to decrypt, the device authorization is verified, and the dynamic user name is generated, and the platform signature is used to ensure information security.

Benefits of technology

It improves the login security of IoT devices, reduces the difficulty of operation and maintenance, reduces the risk of password leakage, and enhances the system's maintainability and information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378877A_ABST
    Figure CN120378877A_ABST
Patent Text Reader

Abstract

The invention relates to the field of communication, and provides an Internet of Things equipment authentication method and device, and the method comprises the steps: receiving a terminal identifier, an equipment identifier, a user name and an encrypted password sent by a terminal, and enabling the encrypted password to be obtained by encrypting the password through employing a first preset encryption algorithm of a pre-received encryption key, the user name is dynamically generated and returned based on the item number, the equipment identifier, the first timestamp and the first signature sent by the terminal; according to a pre-generated encryption key, decrypting the encryption password to obtain a first plaintext; and according to the first plaintext, the terminal identifier, the device identifier and the user name, verifying whether corresponding device authorization exists, and based on a verification result, returning a status code corresponding to the verification result to the terminal. According to the invention, the problems of poor login security and high operation and maintenance difficulty caused by manual application of configuration passwords are solved, the maintainability of the system is improved, the maintenance difficulty is reduced, and the data security is protected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to an authentication method and device for Internet of Things devices. Background Art

[0002] With the development of the mobile Internet, there are more and more mobile-terminal-based applications, which greatly facilitate and enrich users' work and life. Currently, due to the need for user security, each application requires a user to set up an application account containing a password and a username. Multiple application accounts form a user account, and by maintaining the user account, the application is authorized and authenticated based on the corresponding username and password of the application to log in to the application.

[0003] However, the maintenance of the above user accounts is rather cumbersome. Every time a new device is connected, a new password needs to be manually applied for and configured, which not only easily causes the loss of passwords, but also cannot guarantee the security of logins, and invisibly increases the operation and maintenance pressure, and is prone to cause confusion of user passwords as the number of projects grows. Summary of the Invention

[0004] The present invention provides an authentication method and device for Internet of Things devices, which are used to solve the defects in the prior art that manually applying for and configuring passwords results in poor login security and great operation and maintenance difficulty, improve the maintainability of the system, reduce the maintenance difficulty, and protect data security.

[0005] The present invention provides an authentication method for Internet of Things devices, including: receiving a terminal identifier, a device identifier, a username, and an encrypted password sent by a terminal, where the encrypted password is obtained by encrypting a password using a first preset encryption algorithm that adopts a pre-received encryption key, and the username is dynamically generated and returned in advance based on a project number, a device identifier, a first timestamp, and a first signature sent by the terminal; decrypting the encrypted password according to the encryption key to obtain a first plaintext; verifying whether there is a corresponding device authorization according to the first plaintext, the terminal identifier, the device identifier, and the username, and based on the verification result, returning a status code corresponding to the verification result to the terminal.

[0006] It should be noted that by receiving the terminal identifier, the device identifier, the username, and the encrypted password sent by the terminal, the received encrypted key is decrypted by using the pre-generated encryption key, so as to verify the received terminal identifier, device identifier, and username by using the decrypted first plaintext, so as to implement authentication, and on the basis of ensuring security, confirm whether the corresponding Internet of Things device has the corresponding target connection permission.

[0007] According to the present invention, there is provided an authentication method for Internet of Things devices. The encrypted password is encrypted by the Internet of Things device based on the device identifier and the second timestamp using a first preset encryption algorithm and is forwarded through the terminal. Verifying whether there is corresponding device authorization according to the first plaintext, the terminal identifier, the device identifier, and the user name includes: determining whether the device identifier plaintext in the first plaintext is consistent with the device identifier sent by the terminal, and based on the consistency, looking up the device information stored previously according to the device identifier plaintext in the first plaintext to determine whether there is corresponding device identifier information; wherein the device information includes the device identifier information corresponding to each Internet of Things device, the terminal identifier information corresponding to each device identifier information for applying for the device user name, and the device user name applied for previously; based on the existence of corresponding device identifier information, obtaining the terminal identifier information and the device user name according to the device information; determining whether the device user name is consistent with the user name sent by the terminal, and determining whether the terminal device information is consistent with the terminal identifier sent by the terminal, and based on both being consistent, confirming the existence of corresponding authorization and allowing connection; otherwise, confirming the non-existence of corresponding authorization and rejecting connection.

[0008] It should be noted that by verifying whether the device identifier plaintext in the first plaintext is consistent with the device identifier sent by the terminal, the security is preliminarily ensured, and the corresponding relationship between the terminal identifier and the user name is further verified, so that when it is ensured that the terminal identifier and the user name actually exist and correspond, the authorization is confirmed. Even if an attacker forges the encrypted password, without knowing the encryption method and rules, it is impossible to restore the terminal identifier and the device identifier, improving the security.

[0009] According to an authentication method for Internet of Things devices provided by the present invention, the encrypted password is encrypted by the terminal based on the terminal identifier, the device identifier, and the second timestamp using a first preset encryption algorithm; verifying whether there is corresponding device authorization according to the first plaintext, the terminal identifier, the device identifier, and the user name includes: verifying whether the terminal identifier plaintext in the first plaintext is consistent with the terminal identifier sent by the terminal, and verifying whether the device identifier plaintext in the first plaintext is consistent with the device identifier sent by the terminal; based on both being consistent, looking up the user name of the Internet of Things device previously applied for by the terminal according to the terminal identifier plaintext in the first plaintext to obtain the device user name; determining whether the device user name is consistent with the user name sent by the terminal, and based on the consistency, confirming the existence of corresponding authorization and allowing connection; otherwise, confirming the non-existence of corresponding authorization and rejecting connection.

[0010] It should be noted that by verifying the device identifier plaintext and the device identifier plaintext in the first plaintext, the security is initially ensured, and further, the corresponding device name is searched based on the terminal identifier plaintext to verify the accuracy of the received user name. When it is ensured that the terminal identifier and the user name actually exist and correspond to each other, authorization is confirmed. Even if an attacker forges the encrypted password, without knowing the encryption method and rules, it is impossible to restore the terminal identifier and the device identifier, which improves the security.

[0011] According to an Internet of Things device authentication method provided by the present invention, before receiving the terminal identifier, device identifier, user name, and encrypted password sent by a terminal, it includes: receiving the project number, device identifier, first timestamp, and first signature sent by the terminal, where the first signature is encrypted by the terminal according to the project number, device identifier, and first timestamp using a second preset encryption algorithm; encrypting based on the project number, device identifier, and first timestamp using the second preset encryption algorithm to obtain a platform signature; verifying whether the first signature is correct based on the platform signature; generating a user name according to the project number, device identifier, and first timestamp when the verification of the first signature is correct; and returning the user name to the terminal to forward the user name to the corresponding Internet of Things device through the terminal.

[0012] It should be noted that by encrypting the received project number, device identifier, and first timestamp to verify the received first signature using the obtained platform signature, the accuracy of the first signature is determined, information theft by a third party is avoided, the security of communication is improved, and when the first signature is ensured to be accurate, a user name corresponding to the Internet of Things device is generated, which is convenient for dynamically allocating user names when a new Internet of Things device is accessed, further improving the security of information, eliminating the need to apply for user registration, and reducing the operation and maintenance difficulty.

[0013] According to an Internet of Things device authentication method provided by the present invention, encrypting based on the project number, device identifier, and first timestamp using a second preset encryption algorithm to obtain a platform signature includes: encoding the device identifier based on a preset information digest algorithm to obtain a device identifier code; combining the project number, device identifier code, and first timestamp in a first preset combination order to obtain a first combination; encoding the first combination using the preset information digest algorithm to obtain a platform signature; or combining the project number and device identifier in a second preset combination order to obtain a second combination; encoding the second combination using the preset information digest algorithm to obtain a combined code; combining the combined code and the first timestamp in a third preset combination order to obtain a third combination; and encoding the third combination using the preset information digest algorithm to obtain a platform signature.

[0014] It can be seen that by customizing the combination order, the randomness and unpredictability of the encoding can be fully ensured, thereby enhancing the security of information, avoiding the situation where an attacker forges a signature, preventing information leakage, and by encapsulating a timestamp in the signature, the signature is dynamically updated to ensure the timeliness of the signature, avoiding the situation where an attacker intercepts and reuses the signature, and further enhancing the security.

[0015] According to an authentication method for Internet of Things devices provided by the present invention, a username is generated based on a project number, a device identifier, and a first timestamp, including: combining the project number, the device identifier, and the first timestamp in a fourth preset combination manner to obtain a fourth combination; according to the fourth combination, using a hashing algorithm to obtain a string; adding a preset identifier to a preset position of the string to obtain a username. By adding an identifier to a preset position of the string, the security of the generated username is enhanced, avoiding the theft of the username by an attacker, and facilitating subsequent identification and parsing of the username.

[0016] According to an authentication method for Internet of Things devices provided by the present invention, before generating a username based on a project number, a device identifier, and a first timestamp when the platform signature verification is correct, it further includes: based on the project number, searching for device information to obtain at least one device identifier information corresponding to the project number; wherein, the device information includes each device identifier information and the project information corresponding to each device identifier information; searching for at least one device identifier information corresponding to the project number to determine whether there is a corresponding received device identifier, and based on the existence of the corresponding received device identifier, confirming that the verification is passed; or, based on the device identifier, searching for device information to determine whether there is corresponding device identifier information; wherein, the device information includes each device identifier information and the project information corresponding to each device identifier information; based on the existence of the corresponding device identifier information, obtaining the corresponding project information; determining whether the project information is consistent with the project number, and based on the consistency, confirming that the verification is passed.

[0017] It should be noted that since each Internet of Things device corresponds to a unique project, and the same project may correspond to different Internet of Things devices, it is necessary to record the device numbers and project numbers of the Internet of Things devices in one-to-one correspondence in advance, so as to further verify the correspondence between the device identifier and the project number during the generation of the username, ensure that the device and the project actually exist and the correspondence is correct, and thus further ensure the security during the information transmission process.

[0018] According to an authentication method for Internet of Things devices provided by the present invention, after verifying whether there is a corresponding device authorization based on the first plaintext, terminal identifier, device identifier, and username, it includes: based on verifying the existence of a corresponding device authorization, using a cryptographically secure random number generator to generate a random key with a preset number of digits; based on a preset encoding method, converting the byte sequence of the random key into a string form to obtain an encryption key; and sending the encryption key to the terminal to update the previously received encryption key.

[0019] It should be noted that by generating the encryption key before returning the username to the terminal, it is convenient for the terminal to send the encryption key to the corresponding Internet of Things device, so that subsequently the Internet of Things device encrypts the device identifier and the second timestamp or the device identifier, the second timestamp, and the terminal identifier based on the encryption key, and sends the encrypted password obtained by encryption to the platform, so that the platform decrypts the received encrypted password based on the corresponding encryption key, and then verifies whether there is a corresponding device authorization to achieve authentication; and before returning the username to the terminal each time, a new encryption key is generated to facilitate the dynamic generation of a new encrypted password, avoiding the situation where the encrypted password is continuously used after being obtained and is prone to leakage, increasing the difficulty for attackers to intercept and analyze the password, and greatly improving the security.

[0020] According to an authentication method for Internet of Things devices provided by the present invention, the device identifier, username, and encrypted password are sent by the Internet of Things device to the message queue, and based on the first-in, first-out principle of the message queue, the device identifier, username, and encrypted password sent by each Internet of Things device are sequentially sent to the terminal.

[0021] It should be noted that the message queue receives messages sent by different Internet of Things devices. Here, the messages include the device identifier, username, and encrypted password, and in accordance with the first-in, first-out principle, the device identifier, username, and encrypted password sent by the Internet of Things device that sent the message first are preferentially sent to the terminal for authentication, thus avoiding the situation where each Internet of Things device directly sends messages to the terminal, resulting in the terminal being unable to respond to the messages sent by each Internet of Things device in a timely manner, and by temporarily storing the messages sent by each Internet of Things device through the message queue, it is possible to avoid the situation where the terminal responds slowly due to inconsistent transmission speeds between the terminal and the Internet of Things devices.

[0022] According to an authentication method for Internet of Things devices provided by the present invention, based on the verification result, a status code corresponding to the verification result is returned to the terminal, including: based on the verification result showing that there is a corresponding authorization, returning a status code allowing connection to the terminal; otherwise, returning a status code not allowing connection to the terminal, so as to facilitate the terminal to determine whether the corresponding Internet of Things device has the corresponding target connection permission based on the status code.

[0023] The present invention also provides an authentication device for Internet of Things (IoT) devices, including: an information receiving module, which receives a terminal identifier, a device identifier, a username, and an encrypted password sent by a terminal. The encrypted password is obtained by encrypting a password using a first preset encryption algorithm with a pre-received encryption key, and the username is dynamically generated and returned in advance based on a project number, a device identifier, a first timestamp, and a first signature sent by the terminal; a decryption module, which decrypts the encrypted password according to the encryption key to obtain a first plaintext; and an authentication module, which verifies whether there is a corresponding device authorization according to the first plaintext, the terminal identifier, the device identifier, and the username, and returns a status code corresponding to the verification result to the terminal based on the verification result.

[0024] It should be noted that the information receiving module receives the terminal identifier, the device identifier, the username, and the encrypted password sent by the terminal, so that the decryption module decrypts the received encrypted password using the pre-generated encryption key, and then the authentication module verifies the received terminal identifier, device identifier, and username using the decrypted first plaintext to implement authentication, and on the basis of ensuring security, confirm whether the corresponding IoT device has the corresponding target connection permission.

[0025] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of any one of the above-mentioned IoT device authentication methods are implemented.

[0026] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of any one of the above-mentioned IoT device authentication methods are implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0028] Figure 1 is one of the flow diagrams of the IoT device authentication method provided by the present invention;

[0029] Figure 2 is another flow diagram of the IoT device authentication method provided by the present invention;

[0030] Figure 3 is yet another flow diagram of the IoT device authentication method provided by the present invention;

[0031] Figure 4It is a schematic structural diagram of the authentication device for Internet of Things devices provided by the present invention;

[0032] Figure 5 It is a schematic structural diagram of the electronic device provided by the present invention. Detailed implementation manners

[0033] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without making creative efforts shall fall within the protection scope of the present invention.

[0034] Figure 1 A flowchart of an authentication method for Internet of Things devices according to the present invention is described. The execution subject of this method is the platform, which specifically includes:

[0035] S11. Receive the terminal identifier, device identifier, username, and encrypted password sent by the terminal. The encrypted password is obtained by encrypting the password using a first preset encryption algorithm with a pre-received encryption key, and the username is dynamically generated and returned in advance based on the project number, device identifier, first timestamp, and first signature sent by the terminal;

[0036] S12. Decrypt the encrypted password according to the pre-generated encryption key to obtain the first plaintext;

[0037] S13. Verify whether there is a corresponding device authorization according to the first plaintext, terminal identifier, device identifier, and username, and based on the verification result, return the status code of the corresponding verification result to the terminal.

[0038] It should be noted that the platform refers to the background service of the entire system. The step numbers "S1N" in this specification do not represent the sequence of the authentication method for Internet of Things devices. Specifically combined below Figures 2 - 3 Describe the authentication method for Internet of Things devices of the present invention.

[0039] In step S11, receive the terminal identifier, device identifier, username, and encrypted password sent by the terminal. The encrypted password is obtained by encrypting the password using a first preset encryption algorithm with a pre-received encryption key, and the username is dynamically generated and returned in advance based on the project number, device identifier, first timestamp, and first signature sent by the terminal.

[0040] Specifically, the encrypted password can be encrypted by the Internet of Things device based on the device identifier and the second timestamp using a first preset encryption algorithm and forwarded by the terminal. It should be noted that the first preset encryption algorithm can be set according to actual design requirements and will not be further limited here. For example, the Internet of Things device encrypts the device identifier and performs secondary encryption by combining the encrypted device identifier and the second timestamp to obtain the encrypted password; for another example, after the Internet of Things device combines the device identifier and the second timestamp according to actual combination requirements, it uses the symmetric encryption algorithm (Advanced Encryption Standard, abbreviated as AES) for encryption to obtain the encrypted password.

[0041] In addition, the encrypted password can also be encrypted by the terminal based on the terminal identifier, the device identifier, and the second timestamp using a first preset encryption algorithm. Similarly, the first preset encryption algorithm can be set according to actual design requirements. For example, the Internet of Things device uses AES to encrypt the terminal identifier, the device identifier, and the second timestamp combined according to actual combination requirements to obtain the encrypted password; for another example, the Internet of Things device selects the required encryption algorithm to encrypt the device identifier and then selects the encryption algorithm again to encrypt the terminal identifier, the encrypted device identifier, and the second timestamp combined according to actual combination requirements to obtain the encrypted password.

[0042] It should be added that by using the encrypted password, relevant personnel are prevented from accessing the password, thereby ensuring the security of the password and preventing the password from being stolen by a third party.

[0043] In an alternative embodiment, referring to Figure 2 , the device identifier, the username, and the encrypted password are sent by the Internet of Things device to the message queue, and based on the first-in, first-out principle of the message queue, the device identifier, the username, and the encrypted password sent by each Internet of Things device are sequentially sent to the terminal.

[0044] It should be noted that the message queue receives messages sent by different Internet of Things devices. Here, the messages include the device identifier, the username, and the encrypted password, and in accordance with the first-in, first-out principle, the device identifier, the username, and the encrypted password sent by the Internet of Things device that sent the message first are preferentially sent to the terminal for authentication, thereby preventing each Internet of Things device from directly sending messages to the terminal, so that the terminal cannot respond to the messages sent by each Internet of Things device in a timely manner. Moreover, by temporarily storing the messages sent by each Internet of Things device in the message queue, the situation where the terminal response is slow due to inconsistent information transmission speeds between the terminal and the Internet of Things device can be avoided.

[0045] In addition, before receiving the terminal identifier, device identifier, username, and encrypted password sent by the receiving terminal, it further includes: the terminal centrally controls the connection message queues of all Internet of Things devices, so that the Internet of Things devices can send the device identifier, username, and encrypted password to the message queue based on their own authentication requirements. Specifically, the terminal sends control instructions to all Internet of Things devices to control the corresponding Internet of Things device connection message queues.

[0046] In an alternative embodiment, with reference to Figure 3 , before receiving the terminal identifier, device identifier, username, and encrypted password sent by the receiving terminal, it includes: receiving the project number, device identifier, first timestamp, and first signature sent by the receiving terminal, where the first signature is encrypted by the terminal using a second preset encryption algorithm based on the project number, device identifier, and first timestamp; encrypting using the second preset encryption algorithm based on the project number, device identifier, and first timestamp to obtain a platform signature; verifying whether the first signature is correct based on the platform signature; generating a username based on the project number, device identifier, and first timestamp when the first signature verification is correct; and returning the username to the terminal for the terminal to forward the username to the corresponding Internet of Things device.

[0047] It should be noted that the specific method for obtaining the platform signature for the first signature can be referred to below, and will not be repeated here. Additionally, by encrypting the received project number, device identifier, and first timestamp to verify the received first signature using the obtained platform signature, the accuracy of the first signature can be determined, preventing third parties from stealing information, improving the security of communication, and generating the username for the corresponding Internet of Things device when ensuring the accuracy of the first signature, facilitating the dynamic allocation of usernames when new Internet of Things devices are connected, further enhancing information security, eliminating the need for user registration, and reducing operation and maintenance difficulties.

[0048] It should be added that verifying whether the first signature is correct based on the platform signature further includes: ending the process and returning an error message when the first signature verification is incorrect.

[0049] Specifically, based on the project number, device identifier, and the first timestamp, encryption is performed using a second preset encryption algorithm to obtain a platform signature, including: encoding the device identifier based on a preset message digest algorithm to obtain a device identifier code; combining the project number, device identifier code, and the first timestamp in a first preset combination order to obtain a first combination; encoding the first combination using a preset message digest algorithm to obtain a platform signature; or combining the project number and device identifier in a second preset combination order to obtain a second combination; encoding the second combination using a preset message digest algorithm to obtain a combined code; combining the combined code and the first timestamp in a third preset combination order to obtain a third combination; encoding the third combination using a preset message digest algorithm to obtain a platform signature.

[0050] It should be added that the preset message digest algorithm can adopt algorithms such as Message-Digest Algorithm 5, abbreviated as MD5, etc., and can be specifically selected according to actual design requirements, and no further limitation is made here. In addition, the first preset combination order, the second preset combination order, and the third preset combination order can be set based on actual design requirements. For example, the first preset combination order can be the combination order of project number_device identifier code_first timestamp, the second preset combination order can be the combination order of project number_device identifier, and the third preset combination can be the combination order of combined code_first timestamp, and no further limitation is made here.

[0051] Thus, by customizing the combination order, the randomness and unpredictability of the encoding can be fully ensured, thereby strengthening the security of information, avoiding the situation where an attacker forges a signature, preventing information leakage, and by encapsulating the timestamp in the signature, the signature can be dynamically updated to ensure the timeliness of the signature, avoiding the situation where an attacker intercepts and reuses the signature, and further strengthening the security.

[0052] In addition, based on the project number, device identifier, and the first timestamp, a username is generated, including: combining the project number, device identifier, and the first timestamp in a fourth preset combination method to obtain a fourth combination; obtaining a string according to the fourth combination using a hash algorithm; adding a preset identifier to a preset position of the string to obtain a username.

[0053] It should be noted that the fourth preset combination method can be the combination order of project number_device identifier_first timestamp, and can be specifically set according to actual design requirements, and no further limitation is made here. In addition, the preset position can be customized according to actual design requirements, such as the beginning, end, or after the nth character in the middle of the string, and no further limitation is made here.

[0054] In addition, for example, when the preset position is the beginning of the string A, the preset identifier is group_control, and the corresponding username format is group_control_A. By adding an identifier at the preset position of the string, the security of the generated username is enhanced, preventing attackers from stealing the username and facilitating subsequent identification and parsing of the username.

[0055] In an alternative embodiment, before returning the username to the terminal, it further includes: identifying and parsing the username.

[0056] In an alternative embodiment, before generating a username based on the project number, device identifier, and first timestamp when the platform signature verification is correct, it further includes: based on the project number, searching for device information to obtain at least one device identifier information corresponding to the project number; wherein the device information includes each device identifier information and the project information corresponding to each device identifier information; searching for at least one device identifier information corresponding to the project number to determine whether there is a corresponding received device identifier, and based on the existence of a corresponding received device identifier, confirming that the verification is passed; or, based on the device identifier, searching for device information to determine whether there is a corresponding device identifier information; wherein the device information includes each device identifier information and the project information corresponding to each device identifier information; based on the existence of a corresponding device identifier information, obtaining the corresponding project information; determining whether the project information is consistent with the project number, and based on the consistency, confirming that the verification is passed.

[0057] It should be added that searching for at least one device identifier information corresponding to the project number to determine whether there is a corresponding received device identifier further includes: based on the non-existence of a corresponding received device identifier, ending the process and returning an error message; searching for device information based on the device identifier to determine whether there is a corresponding device identifier information further includes: based on the non-existence of a corresponding device identifier information, ending the process and returning an error message; determining whether the project information is consistent with the project number further includes: based on the inconsistency, ending the process and returning an error message.

[0058] It should be noted that since each Internet of Things device corresponds to a unique project, and the same project may correspond to different Internet of Things devices, it is necessary to pre-record the device numbers and project numbers of the Internet of Things devices in a one-to-one correspondence, so as to further verify the correspondence between the device identifier and the project number during the generation of the username, ensure that the device and the project actually exist and the correspondence is correct, and thus further ensure the security during the information transmission process.

[0059] Step S12, decrypt the encrypted password according to the pre-generated encryption key to obtain the first plaintext.

[0060] It should be noted that the encrypted password is encrypted by the first preset encryption algorithm using an encryption key with dynamic updates by the Internet of Things device or terminal. The encryption key is updated by the platform after verifying the existence of corresponding device authorization after the previous authentication application. Therefore, after receiving the encrypted password, the platform can decrypt the encrypted password using the corresponding encryption key to obtain the original value of the encrypted password, that is, the first plaintext.

[0061] Step S13: Verify whether there is corresponding device authorization based on the first plaintext, terminal identifier, device identifier, and username, and return the status code corresponding to the verification result to the terminal based on the verification result.

[0062] In an optional embodiment, when the encrypted password is encrypted by the Internet of Things device based on the device identifier and the second timestamp using the first preset encryption algorithm and forwarded by the terminal, verifying whether there is corresponding device authorization based on the first plaintext, terminal identifier, device identifier, and username includes: determining whether the device identifier plaintext in the first plaintext is consistent with the device identifier sent by the terminal, and based on the consistency, searching for the previously stored device information according to the device identifier plaintext in the first plaintext to determine whether there is corresponding device identifier information; wherein the device information includes the device identifier information corresponding to each Internet of Things device, the terminal identifier information corresponding to each device identifier information for the applied device username, and the device username of the previous application; based on the existence of corresponding device identifier information, obtaining the terminal identifier information and the device username according to the device information; determining whether the device username is consistent with the username sent by the terminal, and determining whether the terminal device information is consistent with the terminal identifier sent by the terminal, and based on both being consistent, confirming the existence of corresponding authorization and allowing the connection; otherwise, confirming the non-existence of corresponding authorization and rejecting the connection.

[0063] It should be noted that determining whether the device identifier plaintext in the first plaintext is consistent with the device identifier sent by the terminal further includes: based on the inconsistency, confirming the non-existence of corresponding authorization and rejecting the connection; searching for the previously stored device information according to the device identifier plaintext in the first plaintext to determine whether there is corresponding device identifier information includes: based on the non-existence of corresponding device identifier information, confirming the non-existence of corresponding authorization and rejecting the connection.

[0064] In addition, by verifying whether the device identifier plaintext in the first plaintext is consistent with the device identifier sent by the terminal, the security is initially ensured, and the corresponding relationship between the terminal identifier and the username is further verified. Thus, when it is ensured that the terminal identifier and the username truly exist and correspond, the authorization is confirmed, so that even if an attacker forges the encrypted password, without knowing the encryption method and rules, it is impossible to restore the terminal identifier and the device identifier, improving the security.

[0065] In another alternative embodiment, when the encrypted password is encrypted by the terminal based on the terminal identifier, device identifier, and second timestamp using a first preset encryption algorithm, verifying whether there is corresponding device authorization according to the first plaintext, terminal identifier, device identifier, and username includes: verifying whether the terminal identifier plaintext in the first plaintext is consistent with the terminal identifier sent by the terminal, and verifying whether the device identifier plaintext in the first plaintext is consistent with the device identifier sent by the terminal; based on both being consistent, looking up the username of the Internet of Things device previously applied for by the terminal according to the terminal identifier plaintext in the first plaintext to obtain the device username; determining whether the device username is consistent with the username sent by the terminal, and based on being consistent, confirming that there is corresponding authorization and allowing the connection; otherwise, confirming that there is no corresponding authorization and rejecting the connection.

[0066] It should be noted that verifying whether the terminal identifier plaintext in the first plaintext is consistent with the terminal identifier sent by the terminal, and verifying whether the device identifier plaintext in the first plaintext is consistent with the device identifier sent by the terminal further includes: if there is at least one inconsistency, confirming that there is no corresponding authorization and rejecting the connection.

[0067] In addition, by verifying the device identifier plaintext and device identifier plaintext in the first plaintext to initially ensure security, and further looking up the corresponding device username based on the terminal identifier plaintext to verify the accuracy of the received username, when it is ensured that the terminal identifier and username truly exist and correspond, the authorization is confirmed, so that even if an attacker forges the encrypted password, without knowing the encryption method and rules, they cannot restore the terminal identifier and device identifier, improving security.

[0068] In an alternative embodiment, after verifying whether there is corresponding device authorization according to the first plaintext, terminal identifier, device identifier, and username, it includes: based on verifying that there is corresponding device authorization, using a cryptographically secure random number generator to generate a random key of a preset number of digits; based on a preset encoding method, converting the byte sequence of the random key into a string form to obtain an encryption key; sending the encryption key to the terminal to update the previously received encryption key.

[0069] It should be noted that by generating an encryption key before returning the username to the terminal, it is convenient for the terminal to send the encryption key to the corresponding Internet of Things device, so that subsequently the Internet of Things device can encrypt the device identifier and second timestamp or the device identifier, second timestamp, and terminal identifier based on the encryption key, and send the encrypted password obtained by encryption to the platform, so that the platform can verify based on the corresponding encryption key; and by generating a new encryption key before returning the username to the terminal each time, it is convenient to dynamically generate a new encrypted password, avoiding the situation where the encrypted password is continuously used after being obtained and is prone to leakage, increasing the difficulty for an attacker to intercept and analyze the password, and greatly improving security.

[0070] In addition, after the platform receives the terminal identifier, device identifier, username, and encrypted password sent by the terminal each time, and decrypts the encrypted password to verify the existence of corresponding authorization, as long as the current connection is not disconnected, there is no need for re-verification. If the connection is disconnected, due to the update of the encryption key, steps S11 - S13 need to be re-executed, which will not be elaborated here repeatedly.

[0071] In an alternative embodiment, based on the verification result, a status code corresponding to the verification result is returned to the terminal, including: when the verification result shows that the corresponding authorization exists, a status code allowing connection is returned to the terminal; otherwise, a status code not allowing connection is returned to the terminal. It should be noted that according to the verification result, a status code is returned to the terminal, so as to facilitate the terminal to determine whether the corresponding Internet of Things device has the corresponding target connection permission based on the status code.

[0072] In summary, the embodiment of the present invention receives the terminal identifier, device identifier, username, and encrypted password sent by the terminal, decrypts the received encrypted password by using the pre-generated encryption key, and then uses the decrypted first plaintext to verify the received terminal identifier, device identifier, and username to implement authentication, and on the basis of ensuring security, determines whether the corresponding Internet of Things device has the corresponding target connection permission.

[0073] Next, the Internet of Things device authentication device provided by the present invention will be described. The Internet of Things device authentication device described below can be correspondingly referred to the Internet of Things device authentication method described above.

[0074] Figure 4 A schematic structural diagram of an Internet of Things device authentication device is shown. The device includes:

[0075] An information receiving module 41, which receives the terminal identifier, device identifier, username, and encrypted password sent by the terminal. The encrypted password is obtained by encrypting the password using a first preset encryption algorithm with a pre-received encryption key, and the username is dynamically generated and returned in advance based on the project number, device identifier, first timestamp, and first signature sent by the terminal;

[0076] A decryption module 42, which decrypts the encrypted password according to the encryption key to obtain the first plaintext;

[0077] An authentication module 43, which verifies whether there is corresponding device authorization according to the first plaintext, terminal identifier, device identifier, and username, and based on the verification result, returns a status code corresponding to the verification result to the terminal.

[0078] In this embodiment, the encrypted password can be obtained by the Internet of Things device through encryption based on the device identifier and the second timestamp using the first preset encryption algorithm and forwarded by the terminal; alternatively, the encrypted password can also be obtained by the terminal through encryption based on the terminal identifier, the device identifier, and the second timestamp using the first preset encryption algorithm.

[0079] In an alternative embodiment, the device identifier, the username, and the encrypted password are sent by the Internet of Things device to the message queue, and based on the first-in, first-out principle of the message queue, the device identifier, the username, and the encrypted password sent by each Internet of Things device are sequentially sent to the terminal.

[0080] In addition, before receiving the terminal identifier, the device identifier, the username, and the encrypted password sent by the terminal, it further includes: the terminal centrally controls all Internet of Things devices to connect to the message queue, so that the Internet of Things device can send the device identifier, the username, and the encrypted password to the message queue based on its own authentication requirements. Specifically, the terminal sends control instructions to all Internet of Things devices to control the corresponding Internet of Things devices to connect to the message queue.

[0081] In an alternative embodiment, the apparatus further includes: an information receiving module, before receiving the terminal identifier, the device identifier, the username, and the encrypted password sent by the terminal, receiving the project number, the device identifier, the first timestamp, and the first signature sent by the terminal, where the first signature is obtained by the terminal through encryption based on the project number, the device identifier, and the first timestamp using the second preset encryption algorithm; a platform signature module, encrypting based on the project number, the device identifier, and the first timestamp using the second preset encryption algorithm to obtain a platform signature; a signature verification module, verifying whether the first signature is correct based on the platform signature; a username generation module, generating a username based on the correct verification of the first signature according to the project number, the device identifier, and the first timestamp; a username return module, returning the username to the terminal for the terminal to forward the username to the corresponding Internet of Things device.

[0082] Specifically, the platform signature module includes: a first encoding unit, encoding the device identifier based on a preset information digest algorithm to obtain a device identifier encoding; a first combination unit, combining the project number, the device identifier encoding, and the first timestamp in a first preset combination order to obtain a first combination; a platform signature unit, encoding the first combination using a preset information digest algorithm to obtain a platform signature; or, a second combination unit, combining the project number and the device identifier in a second preset combination order to obtain a second combination; a second encoding unit, encoding the second combination using a preset information digest algorithm to obtain a combined encoding; a third combination unit, combining the combined encoding and the first timestamp in a third preset combination order to obtain a third combination; a third encoding unit, encoding the third combination using a preset information digest algorithm to obtain a platform signature.

[0083] In addition, the user name generation module includes: a fourth combination unit that combines the project number, device identifier, and first timestamp in a fourth preset combination manner to obtain a fourth combination; a hash unit that uses a hash algorithm to obtain a string based on the fourth combination; and a user name generation unit that adds a preset identifier to a preset position of the string to obtain a user name.

[0084] In an alternative embodiment, the device further includes a parsing module that identifies and parses the user name before returning it to the terminal.

[0085] In an alternative embodiment, the device further includes: a first lookup module that, before generating a user name based on the project number, device identifier, and first timestamp when the platform signature verification is correct, looks up device information based on the project number to obtain at least one device identifier information corresponding to the project number; where the device information includes each device identifier information and the project information corresponding to each device identifier information; a second lookup module that looks up at least one device identifier information corresponding to the project number to determine whether there is a corresponding received device identifier; a first verification module that, based on the existence of a corresponding received device identifier, confirms that the verification is passed; or a third lookup module that, based on the device identifier, looks up device information to determine whether there is corresponding device identifier information; where the device information includes each device identifier information and the project information corresponding to each device identifier information; an information acquisition module that, based on the existence of corresponding device identifier information, obtains the corresponding project information; and a second verification module that determines whether the project information is consistent with the project number and, based on the consistency, confirms that the verification is passed.

[0086] Furthermore, the device further includes: a process end module that, based on the second lookup module determining that there is no corresponding received device identifier, ends the process and returns an error message; the process end module is further configured to: based on the third lookup module determining that there is no corresponding device identifier information, end the process and return an error message; the process end module is further configured to: based on the second verification module determining an inconsistency, end the process and return an error message.

[0087] In an alternative embodiment, when the encrypted password is encrypted by the IoT device based on the device identifier and the second timestamp using the first preset encryption algorithm and forwarded by the terminal, the authentication module 43 includes: a first verification unit that determines whether the device identifier plaintext in the first plaintext is consistent with the device identifier sent by the terminal; a first search unit that, based on the consistency, searches for the previously stored device information according to the device identifier plaintext in the first plaintext to determine whether there is corresponding device identifier information; wherein the device information includes the device identifier information corresponding to each IoT device, the terminal identifier information corresponding to each device identifier information for applying for the device username, and the previously applied device username; an information acquisition unit that, based on the existence of the corresponding device identifier information, obtains the terminal identifier information and the device username according to the device information; a second verification unit that determines whether the device username is consistent with the username sent by the terminal and determines whether the terminal device information is consistent with the terminal identifier sent by the terminal; an authentication unit that, based on both being consistent, confirms the existence of the corresponding authorization and allows the connection; otherwise, confirms the non-existence of the corresponding authorization and rejects the connection.

[0088] Further, the authentication module 43 further includes: a process end unit that, based on the first verification unit determining that the device identifier plaintext in the first plaintext is inconsistent with the device identifier sent by the terminal, confirms the non-existence of the corresponding authorization and rejects the connection; the process end unit is further configured to: based on the second verification unit determining that the device username is inconsistent with the username sent by the terminal, confirm the non-existence of the corresponding authorization and reject the connection.

[0089] In another alternative embodiment, when the encrypted password is encrypted by the terminal based on the terminal identifier, the device identifier, and the second timestamp using the first preset encryption algorithm, the authentication module 43 further includes: a third verification unit that verifies whether the terminal identifier plaintext in the first plaintext is consistent with the terminal identifier sent by the terminal and verifies whether the device identifier plaintext in the first plaintext is consistent with the device identifier sent by the terminal; a second search unit that, based on both being consistent, searches for the username of the IoT device previously applied by the terminal according to the terminal identifier plaintext in the first plaintext to obtain the device username; a fourth verification unit that determines whether the device username is consistent with the username sent by the terminal; an authentication unit that, based on the consistency, confirms the existence of the corresponding authorization and allows the connection; otherwise, confirms the non-existence of the corresponding authorization and rejects the connection.

[0090] Further, the authentication module 43 further includes: a process end unit that, based on the third verification unit determining that the terminal identifier plaintext in the first plaintext is inconsistent with the terminal identifier sent by the terminal, and / or determining that the device identifier plaintext in the first plaintext is inconsistent with the device identifier sent by the terminal, confirms the non-existence of the corresponding authorization and rejects the connection.

[0091] In an alternative embodiment, the device further includes: a key generation module that, after verifying whether there is a corresponding device authorization according to the first plaintext, the terminal identifier, the device identifier, and the username, generates a random key of a preset number of digits by using a cryptographically secure random number generator based on the verification that there is a corresponding device authorization; a character conversion module that converts the byte sequence of the random key into a string form based on a preset encoding method to obtain an encryption key; and a key return module that sends the encryption key to the terminal to update the previously received encryption key.

[0092] In an alternative embodiment, the authentication module 43 further includes: a status code return unit that returns a status code allowing connection to the terminal based on the verification result indicating the confirmation of the existence of the corresponding authorization; otherwise, returns a status code not allowing connection to the terminal.

[0093] In summary, in the embodiment of the present invention, the information receiving module receives the terminal identifier, the device identifier, the username, and the encrypted password sent by the terminal, and the decryption module decrypts the received encrypted password by using the previously generated encryption key, so that the authentication module uses the decrypted first plaintext to verify the received terminal identifier, device identifier, and username to implement authentication, and on the basis of ensuring security, confirm whether the corresponding Internet of Things device has the corresponding target connection permission.

[0094] Figure 5 An example of the physical structure diagram of an electronic device is as Figure 5 shown. The electronic device may include: a processor 510, a communications interface 520, a memory 530, and a communication bus 540. Among them, the processor 510, the communications interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 may call the logical instructions in the memory 530 to execute the authentication method for Internet of Things devices, and the method includes: receiving the terminal identifier, the device identifier, the username, and the encrypted password sent by the terminal, where the encrypted password is obtained by encrypting the password by using a first preset encryption algorithm that uses the previously received encryption key, and the username is dynamically generated and returned in advance based on the project number, the device identifier, the first timestamp, and the first signature sent by the terminal; decrypting the encrypted password according to the pre-generated encryption key to obtain the first plaintext; verifying whether there is a corresponding device authorization according to the first plaintext, the terminal identifier, the device identifier, and the username, and based on the verification result, returning a status code corresponding to the verification result to the terminal.

[0095] In addition, when the logical instructions in the above-mentioned memory 530 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a platform, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0096] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the authentication method for Internet of Things devices provided by the above-mentioned various methods. The method includes: receiving the terminal identifier, device identifier, username, and encrypted password sent by the terminal. The encrypted password is obtained by encrypting the password using a first preset encryption algorithm with a pre-received encryption key. The username is dynamically generated and returned in advance based on the project number, device identifier, first timestamp, and first signature sent by the terminal; decrypting the encrypted password according to the pre-generated encryption key to obtain the first plaintext; verifying whether there is a corresponding device authorization according to the first plaintext, terminal identifier, device identifier, and username, and based on the verification result, returning the status code of the corresponding verification result to the terminal.

[0097] On the other hand, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is implemented to execute the authentication method for Internet of Things devices provided by the above-mentioned various methods. The method includes: receiving the terminal identifier, device identifier, username, and encrypted password sent by the terminal. The encrypted password is obtained by encrypting the password using a first preset encryption algorithm with a pre-received encryption key. The username is dynamically generated and returned in advance based on the project number, device identifier, first timestamp, and first signature sent by the terminal; decrypting the encrypted password according to the pre-generated encryption key to obtain the first plaintext; verifying whether there is a corresponding device authorization according to the first plaintext, terminal identifier, device identifier, and username, and based on the verification result, returning the status code of the corresponding verification result to the terminal.

[0098] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative labor.

[0099] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, platform, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0100] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. And these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of each embodiment of the present invention.

Claims

1. An authentication method for Internet of Things devices, characterized in that, Including: Receiving the terminal identifier, device identifier, username, and encrypted password sent by the receiving terminal. The encrypted password is obtained by encrypting the password using a first preset encryption algorithm with a pre-received encryption key. The username is dynamically generated and returned earlier based on the project number, device identifier, first timestamp, and first signature sent by the terminal. The username is dynamically generated and returned earlier based on the project number, device identifier, first timestamp, and first signature sent by the terminal. The username is dynamically generated and returned earlier based on the project number, device identifier, first timestamp, and first signature sent by the terminal. Decrypting the encrypted password according to the encryption key to obtain the first plaintext. Verifying whether there is a corresponding device authorization according to the first plaintext, the terminal identifier, the device identifier, and the username, and based on the verification result, returning a status code corresponding to the verification result to the terminal.

2. The authentication method for Internet of Things devices according to claim 1, wherein The encrypted password is encrypted by the Internet of Things device based on the device identifier and the second timestamp using the first preset encryption algorithm and forwarded by the terminal. Verifying whether there is a corresponding device authorization according to the first plaintext, the terminal identifier, the device identifier, and the username includes: Determining whether the device identifier plaintext in the first plaintext is consistent with the device identifier sent by the terminal, and based on the consistency, searching for the device information stored earlier according to the device identifier plaintext in the first plaintext to determine whether there is corresponding device identifier information; wherein, the device information includes the device identifier information corresponding to each Internet of Things device, the terminal identifier information corresponding to each device identifier information for applying for the device username, and the device username applied for earlier. Based on the existence of corresponding device identifier information, obtaining the terminal identifier information and the device username according to the device information. Determining whether the device username is consistent with the username sent by the terminal, and determining whether the terminal device information is consistent with the terminal identifier sent by the terminal, and based on both being consistent, confirming the existence of corresponding authorization and allowing connection; otherwise, confirming the non-existence of corresponding authorization and rejecting connection.

3. The authentication method for Internet of Things devices according to claim 1, wherein The encrypted password is encrypted by the terminal based on the terminal identifier, device identifier, and second timestamp using the first preset encryption algorithm. Verifying whether there is a corresponding device authorization according to the first plaintext, the terminal identifier, the device identifier, and the username includes: Verifying whether the terminal identifier plaintext in the first plaintext is consistent with the terminal identifier sent by the terminal, and verifying whether the device identifier plaintext in the first plaintext is consistent with the device identifier sent by the terminal. Based on both being consistent, searching for the username of the Internet of Things device applied for earlier by the terminal according to the terminal identifier plaintext in the first plaintext to obtain the device username. Determining whether the device username is consistent with the username sent by the terminal, and based on the consistency, confirming the existence of corresponding authorization and allowing connection; otherwise, confirming the non-existence of corresponding authorization and rejecting connection.

4. The authentication method for Internet of Things devices according to claim 1, wherein, Before receiving the terminal identifier, device identifier, username, and encrypted password sent by the terminal, including: Receive the project number, device identifier, first timestamp, and first signature sent by the terminal, where the first signature is encrypted by the terminal using a second preset encryption algorithm based on the project number, the device identifier, and the first timestamp; Based on the project number, the device identifier, and the first timestamp, encrypt using the second preset encryption algorithm to obtain a platform signature; Based on the platform signature, verify whether the first signature is correct; Based on the correct verification of the first signature, generate a username according to the project number, the device identifier, and the first timestamp; Return the username to the terminal so that the terminal forwards the username to the corresponding Internet of Things device.

5. The authentication method for Internet of Things devices according to claim 4, wherein Based on the project number, the device identifier, and the first timestamp, encrypt using the second preset encryption algorithm to obtain a platform signature, including: Based on a preset information digest algorithm, encode the device identifier to obtain a device identifier code; According to the project number, the device identifier code, and the first timestamp, combine them in a first preset combination order to obtain a first combination; Use the preset information digest algorithm to encode the first combination to obtain a platform signature; or, According to the project number and the device identifier, combine them in a second preset combination order to obtain a second combination; Use the preset information digest algorithm to encode the second combination to obtain a combination code; According to the combination code and the first timestamp, combine them in a third preset combination order to obtain a third combination; Use the preset information digest algorithm to encode the third combination to obtain a platform signature.

6. The authentication method for Internet of Things devices according to claim 4, wherein, Generate a username according to the project number, the device identifier, and the first timestamp, including: Combine the project number, the device identifier, and the first timestamp in a fourth preset combination manner to obtain a fourth combination; According to the fourth combination, use a hash algorithm to obtain a string; Add a preset identifier to a preset position of the string to obtain a username.

7. The authentication method for the Internet of Things device according to claim 4, wherein Before generating a username according to the project number, the device identifier, and the first timestamp based on the correct verification of the platform signature, further include: Based on the project number, search for device information to obtain at least one device identifier information corresponding to the project number; where the device information includes each device identifier information and the project information corresponding to each device identifier information; Search for at least one device identifier information corresponding to the project number, determine whether there is a corresponding received device identifier, and based on the existence of a corresponding received device identifier, confirm that the verification is passed; or, Based on the device identifier, search for device information to determine whether there is corresponding device identifier information; where the device information includes each device identifier information and the project information corresponding to each device identifier information; Based on the existence of corresponding device identifier information, obtain the corresponding project information; Determine whether the project information is consistent with the project number, and based on the consistency, confirm that the verification is passed.

8. The authentication method for the Internet of Things device according to claim 1, wherein After verifying whether there is a corresponding device authorization according to the first plaintext, the terminal identifier, the device identifier, and the user name, it includes: Based on verifying the existence of a corresponding device authorization, use a cryptographically secure random number generator to generate a random key of a preset number of digits; Based on a preset encoding method, convert the byte sequence of the random key into a string form to obtain an encryption key; Send the encryption key to the terminal to update the previously received encryption key.

9. The authentication method for Internet of Things devices according to claim 1, wherein The device identifier, the user name, and the encrypted password are sent by the IoT device to the message queue, and based on the first-in, first-out principle of the message queue, the device identifier, the user name, and the encrypted password sent by each IoT device are sequentially sent to the terminal.

10. The authentication method for the Internet of Things device according to any one of claims 1-9, characterized in that, Based on the verification result, return a status code corresponding to the verification result to the terminal, including: Based on the verification result showing the confirmation of the existence of the corresponding authorization, return a status code allowing connection to the terminal; otherwise, return a status code not allowing connection to the terminal.

11. An authentication device for Internet of Things devices, characterized in that, It includes: An information receiving module that receives the terminal identifier, the device identifier, the user name, and the encrypted password sent by the terminal. The encrypted password is obtained by encrypting the password using a first preset encryption algorithm that uses the previously received encryption key. The user name is dynamically generated and returned in advance based on the project number, the device identifier, the first timestamp, and the first signature sent by the terminal. The user name is dynamically generated and returned in advance based on the project number, the device identifier, the first timestamp, and the first signature sent by the terminal; A decryption module that decrypts the encrypted password according to the encryption key to obtain the first plaintext; An authentication module that verifies whether there is a corresponding device authorization according to the first plaintext, the terminal identifier, the device identifier, and the user name, and based on the verification result, returns a status code corresponding to the verification result to the terminal.

12. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the IoT device authentication method according to any one of claims 1 to 10.

13. A non-transitory computer-readable storage medium storing a computer program thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the IoT device authentication method according to any one of claims 1 to 10.

Citation Information

Cited By

  • Heterogeneous device data unified access, verification and routing method and system

    CN121841865A