Internet of Things authentication and authorization system based on IPv6 identity identification

By providing IPv6 identity identification and encrypted transmission for IoT devices, combined with identity authentication and permission management, the problems of inconsistent authentication of IoT devices and insufficient communication security are solved, and the security and ease of use of the Internet of Things are improved.

CN120455083AInactive Publication Date: 2025-08-08RAZERTECHNOLOGYCO LTD
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510594849.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-09
Publication Date
2025-08-08
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The authentication and authorization management of IoT devices mainly relies on traditional IPv4 addresses and password methods, resulting in poor scalability and security when accessing large-scale devices, easy to bypass device authentication, lack of effective encryption during data transmission, and vulnerable to attacks.

Method used

The Internet of Things authentication and authorization system based on IPv6 identity is adopted. By generating a unique IPv6 identity for each device, combining the device's identity authentication and data encryption transmission, it supports access control of roles and attributes, and records the logs of device access, authentication and authorization operations.

Benefits of technology

It improves the security and scalability of the Internet of Things environment, effectively prevents device forgery, data tampering and abuse of permissions, and ensures communication security and authentication management between devices and platforms and applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455083A_ABST
    Figure CN120455083A_ABST
Patent Text Reader

Abstract

The invention provides an Internet of Things authentication and authorization system based on an IPv6 identity label. An Internet of Things device obtains a unique IPv6 identity label and unique device certificate information after registering on an Internet of Things cloud platform; storing the identity information and the role permission data, and performing identity verification and permission verification in a device communication process; the Internet of Things cloud platform verifies the identity of the Internet of Things equipment; the Internet of Things cloud platform performs identity authentication by comparing the IPv6 identity identifier with registered equipment certificate information, and generates an identity certificate of the Internet of Things APP binding equipment through an IPv6 digital identity certificate encryption algorithm; and through addition and binding of the Internet of Things application APP and Internet of Things equipment, an identity certificate is generated on the Internet of Things cloud platform. The system effectively solves the problems of inconsistent device authentication, insufficient communication security, device access and dynamic authority management in the Internet of Things, improves the security, expandability and usability of the Internet of Things, and has a wide application prospect.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of Internet of Things, and in particular to an Internet of Things authentication and authorization system based on IPv6 identity identification. Background Art

[0002] With the rapid development of IoT technology, IoT devices are increasingly being used in smart homes, security management, and other areas. An increasing number of devices, such as smart appliances, environmental monitoring systems, and health monitoring devices, are being connected to IoT networks. However, with the increasing number of IoT devices and the complexity of their interconnectivity, IoT security issues are becoming increasingly prominent, particularly in device authentication and data transmission security, which present significant risks.

[0003] Currently, IoT device authentication and authorization management primarily relies on traditional authentication methods such as IPv4 (Internet Protocol version 4) addresses and passwords. These methods exhibit poor scalability and security when faced with large-scale device access. Device authentication can be easily bypassed, and device and user data is often not effectively encrypted during transmission, making them vulnerable to man-in-the-middle attacks or data theft.

[0004] Therefore, there is an urgent need for an IoT security system that combines the IPv6 (Internet Protocol Version 6) protocol, ensures device authentication, data encryption and dynamic permission control, so as to protect the security and user privacy in the IoT environment. Summary of the Invention

[0005] In light of this, the present invention aims to provide an Internet of Things (IoT) authentication and authorization system based on IPv6 identity. Through innovative designs for device access, identity verification, data encryption, rights management, and log auditing, this system offers a secure, reliable, and scalable solution. This system ensures access rights and communication security between IoT devices, effectively preventing security issues such as device counterfeiting, data tampering, and rights abuse, thereby enhancing the overall security of the IoT environment.

[0006] In the first aspect, an embodiment of the present invention provides an Internet of Things authentication and authorization system based on IPv6 identity identification, and the Internet of Things authentication and authorization system includes: an Internet of Things device, an Internet of Things cloud platform and an Internet of Things application APP; the Internet of Things device is used to obtain a unique IPv6 identity identification and a unique device certificate information after registering on the Internet of Things cloud platform; store identity information, role authority data, and perform identity authentication and authority verification during device communication; the Internet of Things cloud platform is used to verify the identity of the Internet of Things device; the Internet of Things cloud platform performs identity authentication by comparing the IPv6 identity identification with the registered device certificate information, and generates an identity certificate for the Internet of Things application APP to bind the device through the IPv6 digital identity certificate encryption algorithm; the Internet of Things application APP is used to add and bind Internet of Things devices, and generates an identity certificate on the Internet of Things cloud platform.

[0007] In an optional embodiment of the present application, when the above-mentioned IoT device is registered on the IoT cloud platform, a unique IPv6 identity is generated in accordance with the RFC8200 standard; the IPv6 identity is used to identify the digital identity of the IoT device.

[0008] In an optional embodiment of the present application, the above-mentioned IoT cloud platform performs identity authentication by comparing the IPv6 identity identifier with the registered device certificate information when the IoT device accesses.

[0009] In an optional embodiment of the present application, when a user binds an IoT device to the above-mentioned IoT application APP, the IoT cloud platform generates an identity credential for the IoT application APP-bound device through the following calculation formula of the IPv6 digital identity certificate encryption algorithm: IPv6 digital identity certificate = Fx (IPv6 identification address, application APP identification, timestamp, input encryption algorithm); wherein, Fx() is a pre-set function; the IPv6 identification address is the unique IPv6 identity identification address of the IoT device; the application APP identification is the unique identification of the application APP registered on the IoT cloud platform; the timestamp is the certificate generation time to ensure the timeliness of the identity identification; the input encryption algorithm is an algorithm for encrypting information to ensure data security and prevent forgery.

[0010] In an optional embodiment of the present application, each time the above-mentioned Internet of Things authentication and authorization system communicates, each data packet carries an IPv6 digital identity certificate and a timestamp to prevent replay attacks on device data and ensure the uniqueness and legitimacy of each communication request; the identity authentication step includes: calling the calculation formula of the IPv6 digital identity certificate encryption algorithm to generate an IPv6 digital identity certificate, and determining whether the generated IPv6 digital identity certificate is consistent with the received identity certificate; if they are consistent, the current access is legal; if they are inconsistent, the current access is illegal.

[0011] In an optional embodiment of the present application, the above-mentioned Internet of Things authentication and authorization system supports role-based and attribute-based access control to ensure that users and Internet of Things devices with different roles operate according to the principle of least privilege.

[0012] In an optional embodiment of the present application, the above-mentioned Internet of Things application APP is also used by administrators to manage members and assign different roles and functional permissions to each member.

[0013] In an optional embodiment of the present application, after the administrator assigns roles and functional permissions to members, the above-mentioned IoT application APP uploads the permission information to the IoT cloud platform and sends the permission information to the local storage of the device.

[0014] In an optional embodiment of the present application, when communicating, the above-mentioned Internet of Things device performs user authority verification based on locally stored role authority information to determine whether the user is allowed to perform the operation.

[0015] In an optional embodiment of the present application, the above-mentioned Internet of Things authentication and authorization system automatically records logs of device access, identity authentication, data transmission and authorization operations for administrators to conduct security audits.

[0016] The embodiments of the present invention bring the following beneficial effects:

[0017] An embodiment of the present invention provides an Internet of Things (IoT) authentication and authorization system based on IPv6 identity. This system provides a globally unique identity for each IoT device through the IPv6 protocol. By combining device identity authentication with encrypted data transmission, it ensures communication security and authentication management between devices and platforms, and between devices and applications within the IoT. The system includes multiple steps, including device access, identity authentication, authorization management, and data encryption. It provides flexible permission control and dynamic authorization management, and supports user and device identity authentication and data protection. This system effectively addresses issues such as inconsistent device authentication, insufficient communication security, device access, and dynamic permission management within the IoT, improving the security, scalability, and usability of the IoT, and has broad application prospects.

[0018] Other features and advantages of the present disclosure will be set forth in the following description, or some features and advantages may be inferred or unambiguously determined from the description, or may be learned by practicing the above-mentioned technology of the present disclosure.

[0019] In order to make the above-mentioned objectives, features and advantages of the present disclosure more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0021] Figure 1 A schematic diagram of the structure of an Internet of Things authentication and authorization system based on IPv6 identity provided by an embodiment of the present invention;

[0022] Figure 2 A schematic diagram of a device access authentication process provided by an embodiment of the present invention;

[0023] Figure 3 A schematic diagram of device authorization and access permission control provided by an embodiment of the present invention;

[0024] Figure 4 A schematic diagram of device communication identity authentication provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0025] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0026] With the rapid development of IoT technology, IoT devices are increasingly being used in smart homes, security management, and other areas. An increasing number of devices, such as smart appliances, environmental monitoring systems, and health monitoring devices, are being connected to IoT networks. However, with the increasing number of IoT devices and the complexity of their interconnectivity, IoT security issues are becoming increasingly prominent, particularly in device authentication and data transmission security, which present significant risks.

[0027] Currently, IoT device authentication and authorization management primarily relies on traditional authentication methods such as IPv4 addresses and passwords. These methods exhibit poor scalability and security when faced with large-scale device access. Device authentication can be easily bypassed, and device and user data is often not effectively encrypted during transmission, making them vulnerable to man-in-the-middle attacks and data theft.

[0028] Therefore, there is an urgent need for an IoT security system that combines the IPv6 protocol, ensures device authentication, data encryption, and dynamic permission control to protect security and user privacy in the IoT environment.

[0029] Based on this, the embodiments of the present invention provide an IPv6 identity-based IoT authentication and authorization system. Through innovative designs for device access, identity verification, data encryption, rights management, and log auditing, it offers a secure, reliable, and scalable solution. This system ensures access rights and communication security between IoT devices, effectively preventing security issues such as device counterfeiting, data tampering, and rights abuse, thereby enhancing the overall security of the IoT environment.

[0030] To facilitate understanding of this embodiment, an Internet of Things authentication and authorization system based on IPv6 identity disclosed in an embodiment of the present invention is first introduced in detail.

[0031] Example 1:

[0032] The embodiment of the present invention provides an Internet of Things authentication and authorization system based on IPv6 identity identification, see Figure 1 The schematic diagram of the structure of an Internet of Things authentication and authorization system based on IPv6 identity identification is shown. The Internet of Things authentication and authorization system based on IPv6 identity identification (hereinafter referred to as the system) includes: an Internet of Things device (hereinafter referred to as the device), an Internet of Things cloud platform (hereinafter referred to as the cloud platform), and an Internet of Things application app (hereinafter referred to as the app).

[0033] IoT devices are used to obtain a unique IPv6 identity and unique device certificate information after registering on the IoT cloud platform; store identity information, role permission data, and perform identity authentication and permission verification during device communication;

[0034] The IoT cloud platform is used to verify the identity of IoT devices. The IoT cloud platform performs identity authentication by comparing the IPv6 identity identifier with the registered device certificate information, and generates the identity certificate for the IoT application app to bind the device using the IPv6 digital identity certificate encryption algorithm.

[0035] The IoT application APP is used to add and bind IoT devices and generate identity credentials on the IoT cloud platform.

[0036] This embodiment uses the IPv6 protocol to provide a globally unique identity for each IoT device. Combining device authentication with encrypted data transmission ensures secure communication and authentication management between devices and platforms, and between devices and applications within the IoT. The IoT authentication and authorization system encompasses multiple steps, including device access, identity verification, authorization management, and data encryption. It provides flexible permission control and dynamic authorization management, supporting user and device authentication and data protection.

[0037] In some embodiments, when the IoT device is registered on the IoT cloud platform, a unique IPv6 identity is generated in accordance with the RFC 8200 standard; the IPv6 identity is used to identify the digital identity of the IoT device.

[0038] RFC 8200 is the final standardization document for the IPv6 protocol. It comprehensively standardizes the IPv6 protocol and defines its basic rules and operations. In this embodiment, the IoT device will be assigned a unique IPv6 identity and device certificate information after registering on the IoT cloud platform to ensure device uniqueness.

[0039] In some embodiments, when an IoT device accesses the IoT cloud platform, the IoT cloud platform performs identity authentication by comparing the IPv6 identity with the registered device certificate information.

[0040] When the IoT device in this embodiment connects to the IoT, the IoT cloud platform performs identity authentication by comparing the IPv6 identity with the registered device certificate information.

[0041] In some embodiments, when a user binds an IoT device to the IoT application APP, the IoT cloud platform generates an identity credential for the IoT application APP-bound device through the following calculation formula of the IPv6 digital identity certificate encryption algorithm: IPv6 digital identity certificate = Fx (IPv6 identification address, application APP identification, timestamp, input encryption algorithm); wherein, Fx() is a pre-set function; the IPv6 identification address is the unique IPv6 identity identification address of the IoT device; the application APP identification is the unique identification of the application APP registered on the IoT cloud platform; the timestamp is the certificate generation time to ensure the timeliness of the identity identification; the input encryption algorithm is an algorithm for encrypting information to ensure data security and prevent forgery.

[0042] After the IoT device identity authentication in this embodiment is passed, the user can add the device to the application app for binding. After receiving the binding request, the cloud platform uses the IPv6 digital identity certificate encryption algorithm to generate an identity certificate. The identity certificate serves as the legal credential for the application app to communicate with the device.

[0043] In some embodiments, each time the above-mentioned Internet of Things authentication and authorization system communicates, each data packet carries an IPv6 digital identity certificate and a timestamp to prevent replay attacks on device data and ensure the uniqueness and legitimacy of each communication request; the identity authentication step includes: calling the calculation formula of the IPv6 digital identity certificate encryption algorithm to generate an IPv6 digital identity certificate, and determining whether the generated IPv6 digital identity certificate is consistent with the received identity certificate; if they are consistent, the current access is legal; if they are inconsistent, the current access is illegal.

[0044] In this embodiment, when performing IoT communication, each data packet will carry an IPv6 digital identity certificate as a legal identity credential, and generate a timestamp for transmission together to prevent replay attacks.

[0045] In some embodiments, the IoT authentication and authorization system supports role-based and attribute-based access control to ensure that users and IoT devices with different roles operate according to the principle of least privilege.

[0046] The system in this embodiment supports role-based and attribute-based access control, ensuring that users and devices with different roles can operate according to the principle of least privilege.

[0047] In some embodiments, the aforementioned IoT application APP is also used by administrators to manage members and assign different roles and functional permissions to each member.

[0048] In the application, the administrator can manage group members and grant different roles and functional permissions to each member, and assign different access rights.

[0049] In some embodiments, after the administrator assigns roles and functional permissions to members, the above-mentioned IoT application APP uploads the permission information to the IoT cloud platform and sends the permission information to the local storage of the device.

[0050] After the APP administrator adds group members and assigns them role permissions, the member function access permissions will be uploaded to the IoT cloud platform and sent to the device's local storage.

[0051] In some embodiments, when communicating, the IoT device performs a user authority check based on locally stored role authority information to determine whether the user is allowed to perform an operation.

[0052] When communicating, the IoT device in this embodiment verifies the role of the current access user and the permissions they have on the device to determine whether to allow the user to perform a certain operation.

[0053] In some embodiments, the IoT authentication and authorization system automatically records logs of device access, identity authentication, data transmission, and authorization operations for administrators to conduct security audits.

[0054] The system in this embodiment automatically records the access, authentication, data transmission and authorization operation logs of all devices. System administrators can conduct regular security audits to check for abnormal security incidents and respond to potential security threats in a timely manner.

[0055] An embodiment of the present invention provides an Internet of Things (IoT) authentication and authorization system based on IPv6 identity. This system provides a globally unique identity for each IoT device through the IPv6 protocol. By combining device identity authentication with encrypted data transmission, it ensures communication security and authentication management between devices and platforms, and between devices and applications within the IoT. The system includes multiple steps, including device access, identity authentication, authorization management, and data encryption. It provides flexible permission control and dynamic authorization management, and supports user and device identity authentication and data protection. This system effectively addresses issues such as inconsistent device authentication, insufficient communication security, device access, and dynamic permission management within the IoT, improving the security, scalability, and usability of the IoT, and has broad application prospects.

[0056] Example 2:

[0057] This embodiment provides a detailed implementation method for an Internet of Things authentication and authorization system based on IPv6 identity, covering security mechanisms such as IoT device access, identity authentication, data encryption, and dynamic rights management, ensuring the security and reliability of devices and data in the IoT environment. The specific technical solution is as follows:

[0058] Step 1, see Figure 2 The diagram shows a device access authentication process. When each IoT device is manufactured or put into use for the first time, it is registered with the IoT cloud platform. The cloud platform assigns a unique IPv6 identity to each device. This IPv6 identity is bound to the device's certificate information to ensure the uniqueness and identifiability of each device in the system.

[0059] Step 2, such as Figure 2 As shown in the figure, when an IoT device connects to the IoT network, the cloud platform will authenticate the device by comparing its IPv6 identity with the registered device certificate information. Once verified, the device can continue to connect to the network for subsequent operations.

[0060] Step 3, see Figure 3 The diagram below illustrates device authorization and access control. A user initiates a device binding request through an IoT app. The cloud platform uses an IPv6 digital identity certificate encryption algorithm to generate an identity certificate containing the device's IPv6 address and the app's identifier. This identity certificate authenticates subsequent communications between the user's device and the app.

[0061] Step 4: Figure 3 As shown in the figure, in the IoT application APP, administrators can manage group members and assign different roles and functional permissions to them.

[0062] Step five, such as Figure 3As shown in the figure, in the IoT application app, after the administrator sets roles and permissions for group members, this permission information will be uploaded to the IoT cloud platform. After receiving the permission information, the cloud platform will send the permission data to the local storage of the IoT device.

[0063] Step 6, see Figure 4 The diagram shows a device communication identity authentication diagram. Every time the IoT communicates, it carries an IPv6 digital identity certificate and timestamp to ensure the uniqueness of the data packet and prevent replay attacks.

[0064] Step seven, such as Figure 4 As shown, when devices communicate, they first verify the IPv6 digital identity certificate and timestamp information of the received data packet. They then use the locally stored IPv6 identification address, application ID, and other information to calculate the IPv6 digital identity certificate. They then compare this with the received identity certificate to determine if the identity certificate is valid. If the verification fails, the operation is rejected and a security log is recorded.

[0065] Step eight, such as Figure 4 As shown, after the identity certificate is verified, a local permission check is performed to determine whether the current user's role and access permissions allow the operation. The specific process is as follows: the device obtains the user identity information of the current operation request, reads the locally stored permission information, and checks whether the user has permission to perform the operation. If the user's permissions meet the requirements, the device performs the operation.

[0066] In step nine, the system automatically records all key operations, including device access, identity authentication, permission changes, and data transfer. Devices store operation logs locally and also regularly upload them to the IoT cloud platform for centralized storage and auditing. System administrators can audit the logs to identify abnormal operations, unauthorized access, or data tampering.

[0067] The above method provided by the embodiment of the present invention covers security mechanisms such as IoT device access, identity authentication, data encryption and dynamic rights management, which can ensure the security and reliability of devices and data in the IoT environment.

[0068] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working process of the system and / or device described above can refer to the corresponding process in the aforementioned embodiment and will not be repeated here.

[0069] In addition, in the description of the embodiments of the present invention, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they may refer to fixed connections, detachable connections, or integral connections; they may refer to mechanical connections or electrical connections; they may refer to direct connections or indirect connections through an intermediate medium; and they may refer to internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on the specific circumstances.

[0070] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program code.

[0071] In the description of the present invention, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicating orientations or positional relationships, are based on the orientations or positional relationships shown in the accompanying drawings and are intended solely to facilitate and simplify the description of the present invention. They are not intended to indicate or imply that the devices or components referred to must have, be constructed, or operate in a specific orientation, and therefore should not be construed as limitations on the present invention. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0072] Finally, it should be noted that the above embodiments are only specific implementation methods of the present invention, which are used to illustrate the technical solutions of the present invention, rather than to limit them. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily conceive of changes to the technical solutions described in the above embodiments within the technical scope disclosed by the present invention, or replace some of the technical features therein with equivalents. Such modifications, changes or replacements do not deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. An Internet of Things authentication and authorization system based on IPv6 identity identification, characterized in that: The IoT authentication and authorization system includes: IoT devices, IoT cloud platform and IoT application APP; The IoT device is used to obtain a unique IPv6 identity and unique device certificate information after registering on the IoT cloud platform; store identity information, role authority data, and perform identity authentication and authority verification during device communication; The IoT cloud platform is used to verify the identity of the IoT device; the IoT cloud platform performs identity authentication by comparing the IPv6 identity identifier with the registered device certificate information, and generates the identity certificate of the IoT application APP bound device through the IPv6 digital identity certificate encryption algorithm; The Internet of Things application APP is used to add and bind the Internet of Things device and generate the identity certificate on the Internet of Things cloud platform.

2. The Internet of Things authentication and authorization system based on IPv6 identity according to claim 1, characterized in that: When the IoT device is registered on the IoT cloud platform, it generates a unique IPv6 identity in accordance with the RFC 8200 standard; the IPv6 identity is used to identify the digital identity of the IoT device.

3. The Internet of Things authentication and authorization system based on IPv6 identity according to claim 1 or 2, characterized in that: When the IoT device accesses the platform, the IoT cloud platform performs identity authentication by comparing the IPv6 identity with the registered device certificate information.

4. The Internet of Things authentication and authorization system based on IPv6 identity according to claim 1, characterized in that: When the user binds the IoT device to the IoT application APP, the IoT cloud platform generates the identity certificate of the device bound to the IoT application APP through the following calculation formula of the IPv6 digital identity certificate encryption algorithm: IPv6 digital identity certificate = Fx (IPv6 identification address, application APP identification, timestamp, input encryption algorithm); Among them, Fx() is a pre-set function; the IPv6 identification address is the unique IPv6 identity identification address of the Internet of Things device; the application APP identification is the unique identification of the application APP registered on the Internet of Things cloud platform; the timestamp is the certificate generation time to ensure the timeliness of the identity identification; the input encryption algorithm is an algorithm for encrypting information to ensure data security and prevent forgery.

5. The Internet of Things authentication and authorization system based on IPv6 identity according to claim 4, characterized in that: Each time the IoT authentication and authorization system communicates, each data packet carries the IPv6 digital identity certificate and the timestamp to prevent device data replay attacks and ensure the uniqueness and legitimacy of each communication request; The identity authentication step includes: calling the calculation formula of the IPv6 digital identity certificate encryption algorithm to generate the IPv6 digital identity certificate, and determining whether the generated IPv6 digital identity certificate is consistent with the received identity certificate; If they are consistent, the current access is legal; if they are inconsistent, the current access is illegal.

6. The Internet of Things authentication and authorization system based on IPv6 identity according to claim 1, characterized in that: The IoT authentication and authorization system supports role-based and attribute-based access control to ensure that users with different roles and the IoT devices operate according to the principle of least privilege.

7. The Internet of Things authentication and authorization system based on IPv6 identity according to claim 1, characterized in that: The IoT application APP is also used by administrators to manage members and assign different roles and functional permissions to each member.

8. The Internet of Things authentication and authorization system based on IPv6 identity according to claim 7, characterized in that: After the administrator assigns roles and functional permissions to members, the IoT application APP uploads the permission information to the IoT cloud platform and sends the permission information to the local storage of the device.

9. The Internet of Things authentication and authorization system based on IPv6 identity according to claim 8, characterized in that: When communicating, the IoT device performs user authority verification based on locally stored role authority information to determine whether the user is allowed to perform an operation.

10. The Internet of Things authentication and authorization system based on IPv6 identity according to claim 1, characterized in that: The IoT authentication and authorization system automatically records logs of device access, identity authentication, data transmission, and authorization operations for administrators to conduct security audits.

Citation Information

Patent Citations

  • User authentication method and user authentication system based on Home-IOT cloud gate

    CN103825745A

  • Internet-electronic-business-transaction-oriented method and system

    CN103957217A

  • Identity authentication method, intelligent equipment and authentication server

    CN111327583A

  • Equipment control authority setting method and device, computer equipment and storage medium

    CN113612747A

  • Internet of Things equipment identity authentication method and system oriented to full life cycle, and storage medium

    CN114978542A