Authenticator device and method for securely identifying valid device in offline wireless environment
By storing authentication keys and certificates in the authenticator device, the problem of validity verification of remote devices without network connection is solved, safe and reliable offline authentication is achieved, and the dependence on cloud connections is reduced.
Patent Information
- Application Number
- CN202480006116.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-01-10
- Filing Date
- 2024-01-05
- Publication Date
- 2025-08-08
AI Technical Summary
In the absence of a network connection, it is difficult for the prior art to securely identify and verify the effectiveness of remote devices, there is a risk that sensitive key information is attacked by unauthorized users, and it is highly dependent on cloud connections.
An authenticator device is provided, including a memory, a communication interface and a controller, by receiving authentication information from a cloud network and authenticating a remote device in an offline environment, and using an internally stored authentication key and certificate for secure authentication.
It realizes the effectiveness of remote devices securely verifying in the network-free area, reduces dependence on cloud connections, protects sensitive information from being attacked, and ensures the security and reliability of authentication.
Smart Images

Figure CN120457657A_ABST
Abstract
Description
Background Art
[0001] Facilities such as buildings may have complex lighting systems that are used both to provide light and to monitor and manage nearby devices. These lighting systems may include a series of lighting fixtures, each of which includes sensors and wireless communication technology to relay information, such as sensor information. In addition, the lighting system may include components such as mobile devices (e.g., mobile phones) that include mobile applications to control various features of the lighting system.
[0002] The lack of cloud connectivity in a network imposes various constraints on handling features such as device authentication. Device authentication involves identifying a remote device (such as a lighting fixture) and verifying its credentials. Typically, these constraints are easily overcome if cloud connectivity is available, as all remote devices have a common server to sync with. However, when a network connection is absent, authenticating remote devices becomes difficult, if not impossible.
[0003] One method used to authenticate remote devices is public-key cryptography. This method is based on a key pair consisting of a public key and a private key. Data encrypted with a public key can only be decrypted using the corresponding private key. Conversely, data encrypted with a private key can only be decrypted using the corresponding public key. A certificate verifies that an entity is the owner of a specific public key.
[0004] There is a need for a secure method to identify whether a remote device is valid. If the decryption key required for authentication is stored on the mobile device, there is the possibility that the sensitive key information may be vulnerable to attack by unauthorized users. Otherwise, if the decryption key information is maintained in the cloud, there is a dependency on network connectivity. Therefore, in areas where there is no network connectivity and therefore no access to the cloud, it is desirable to have an authentication device and corresponding method that can verify the remote device and securely maintain the decryption key. Summary of the Invention
[0005] An authentication device / method is provided that works in conjunction with a mobile device and can verify the validity of a remote device located in an area where a network connection does not exist. Advantageously, the authenticator device can provide the required credentials to the remote device so that the remote device knows that it is communicating with a valid mobile application on the mobile device.
[0006] The authenticator device is a portable device that includes a memory, a communication interface, and a controller. The controller receives authentication information from a cloud network via the communication interface, stores the authentication information in the memory, and uses the authentication information to authenticate a device when the authenticator device and the device are not connected to the cloud network.
[0007] A method for authenticating a wireless device in an offline environment includes: connecting an authenticator device to a cloud network; receiving, by the authenticator device, an authentication key and a certificate from the cloud network; storing the authentication key and the certificate in an internal memory of the authenticator device; when the authenticator device is not connected to the cloud network, establishing, by the authenticator device, a connection to a mobile device, the mobile device including a mobile application for communicating with a remote device; and authenticating, by the authenticator device via the mobile application, the remote device using the authentication key.
[0008] The authentication system includes an authenticator device including a memory and a controller, wherein the controller receives an authentication key and a certificate from a cloud network via a communication interface and stores the authentication key and the certificate in the memory; a wireless remote device; and a mobile device including a mobile application that communicates with the authenticator device and the wireless remote device. When the authenticator device and the wireless remote device are not connected to the cloud network, the authenticator device authenticates the wireless remote device via the mobile device.
[0009] This Summary is provided to introduce some concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] To easily identify the discussion of any particular element or act, the highest-order digit or digits in a reference number refer to the figure number in which the element is first introduced.
[0011] Figure 1 A system diagram of an example wireless network is shown.
[0012] Figure 2 Components of an authenticator device are shown.
[0013] Figure 3 A system diagram of an authentication system is shown.
[0014] Figure 4 A sequence diagram of the proposed method according to an embodiment is shown.
[0015] Figure 5 A process flow of a method according to one embodiment is shown. DETAILED DESCRIPTION
[0016] Figure 1 A system diagram of an example wireless network is shown. Figure 1, the wireless network 100 includes a plurality of remote devices 102 arranged in a mesh network 104. The plurality of remote devices 102 can communicate with each other. In one embodiment, the mesh network 104 can be a network of remote devices 102 as lighting fixtures. Low Energy (BLE) network. The number of lighting fixtures in the mesh network 104 can be as many as 250 lighting fixtures. Although the lighting fixtures are referred to as remote devices, this is for illustrative purposes only. The remote device 102 can be any wireless device that does not have a connection to the cloud network. For devices that are not part of the mesh network 104, such as the mobile device 112, communication 108 with the mesh network 104 is accomplished via a proxy remote device 106. Although the proxy remote device 106 can be the remote device closest to the mobile device 112, the proxy remote device can be any remote device in the remote devices 102. The proxy remote device 106 receives information from the mobile device 112 and then permeates the information to the other remote devices 102 in the mesh network 104.
[0017] The mobile application 110 configures (i.e., sets up) the remote device 102 into the mesh network 104 and controls features on the remote device 102 via the mobile application 110 running on the mobile device 112. To ensure that this setup operation is completed securely, the mobile application 110 and the remote device 102 authenticate each other to ensure that the remote device 102 is a valid device and that the mobile application 110 is valid to communicate with the mesh network 104. When a cloud connection is present, the mobile application 110 communicates directly with the cloud network to perform this authentication via a cryptographic application in the cloud network. However, many times, the remote device 102 is located in an area that does not have a cloud connection.
[0018] Therefore, to solve this problem, the inventors propose an authenticator device that can authenticate both the mobile application 110 and the remote device 102 and / or the remote device 102 configured in the wireless mesh network 104 when the mobile application 110 cannot connect to the cloud network.
[0019] Figure 2Components of an authenticator device are shown. The authenticator device 200 shown is an external device (i.e., an edge device) comprising hardware that can run a Linux-based system or an RTOS (real-time operating system) system utilizing a microcontroller. Similar to the mobile application 110, the authenticator device 200 is mobile so that its user can carry it to a site of the wireless network 100. The authenticator device 200 includes an internal memory 108, which can be a non-volatile memory. The memory 208 can store authentication keys and certificates for verifying the mobile device 112. In order for the authenticator device 200 to operate wirelessly, it can include a battery 204. Alternatively, the authenticator device 200 is powered by a DC adapter. The authenticator device 200 includes a communication interface 210 to enable communication to a cloud network. For example, the authenticator device 200 can include an Ethernet port so that the authenticator device 200 can communicate with the cloud network via Ethernet. Alternatively, the communication interface 210 may be Wi-Fi or BLE, so that the authenticator device 200 would require corresponding ports to support these communication protocols.
[0020] The controller 202 on the authenticator device 200 communicates with the cloud network when a cloud connection exists to receive an authentication key and certificate, and stores the authentication key and certificate in the memory 208. Then, when a cloud connection does not exist, the controller 202 can securely identify valid devices (i.e., the remote device 102 or the mobile application 110) in the wireless environment. The authenticator device 200 also includes a real-time clock 206 that is synchronized with the current time when the authenticator device 200 is connected to the cloud network.
[0021] Figure 3 3. The authentication system 300 includes an authenticator device 200, a mesh network 104 of remote devices 102, a mobile application 110, and a cloud network 306. The authenticator device 200 includes a Figure 2 The components described.
[0022] When a cloud connection is present (i.e., in online mode), the authenticator device 200 communicates with the cloud network 306 via a communication interface 302, which can be Ethernet, Wi-Fi, BLE, or any other wired or wireless network protocol. This communication interface can be used to communicate remotely, i.e., to communicate with the cloud network or a remote server to share the required certificates and authentication keys. In online mode, the authenticator device 200 will download a set of encrypted authentication keys (e.g., a public-private key pair as described above) and certificates for authenticating the mobile application 110 installed on the mobile device 112. Alternatively, instead of connecting to the cloud network 306, the authenticator device 200 can connect to a local server with stored authentication keys and certificates to receive them. The authenticator device 200 will then store these authentication keys and certificates in its memory 208. Additionally, in online mode, the authenticator device 200 can synchronize its real-time clock 206 with the current local time during its communication with the cloud network 306.
[0023] When there is no cloud connection, such as when a user is at a remote site, the authenticator device 200 can be used in conjunction with a mobile device 112 running a mobile application 110 to authenticate a remote device 102 or multiple remote devices 102 configured in a mesh network 104 in an offline mode. The authenticator device 200 connects to the mobile application 110 using a Wi-Fi connection 304. The mobile application 110 can connect to the mesh network 104 via the BLE 5.0 protocol or other protocols supported by both the mobile application 110 and the remote device 102.
[0024] Figure 4 A sequence diagram of a method for authenticating a device in an offline wireless environment is shown. Initially, in online mode 402, authenticator device 200 connects to cloud network 306 via communication interface 302. In online mode 402, once connected, authenticator device 200 requests and receives an authentication key and certificate from cloud network 306. Cloud network 306 encrypts the authentication key before sending it to authenticator device 200. In addition, the current local time is shared with authenticator device 200. For security purposes, authenticator device 200 deletes the authentication key after a fixed period of time. Similarly, certificates may also be deleted from the authenticator device's internal memory 208 after a fixed period of time. In one embodiment, this fixed period of time may be seventy-two hours, however, other time periods may also be used.
[0025] Once the authentication key and certificate are received by the authenticator device 200, it is ready to authenticate the remote device 102 in an offline environment without cloud connectivity. The remote device 102 will use the certificate to verify that the mobile application 110 on the mobile device 112 is valid. The mobile application 110 uses the authentication key to verify that the remote device 102 or the remote device's mesh network 104 is valid.
[0026] In offline mode 404, the authenticator device 200 establishes a Wi-Fi connection 304 with the mobile application 110. The mobile application 110 on the mobile device 112 is then ready to communicate with the authenticator device 200. Once the connection to the authenticator device 200 is established, the mobile application 110 will request a certificate in an encrypted format that cannot be read or decoded by the mobile application 110. In this way, the certificate should not be accessible to an adversary or corrupted by a virus that may be present on the mobile application 110. The mobile application 110 only passes the certificate to a remote device 102 that is capable of decoding the certificate. The certificate is not stored in the mobile application. Additionally, in offline mode 404, the local time from the real-time clock 206 can be shared with the remote device 102 to synchronize the remote device 102 to the local time and / or a remote server.
[0027] To authenticate the remote device 102, the mobile application 110 scans the remote device 102 for an encrypted string. The encrypted string is sent to the mobile application 110 in response. The mobile application 110 passes the encrypted string to the authenticator device 200, where the encrypted string is decrypted using the authentication key. Based on the decryption, the authenticator device 200 can determine whether the remote device 102 is a valid remote device. If it is a valid device, the remote device 102 is authenticated and the remote device 102 is displayed in the list of valid remote devices on the mobile application 110. In the configuration of the mesh network 104 by the mobile application 110, the remote device 102 can be added to the mesh network 104. If the authenticator device 200 determines that the remote device 102 is not a valid device, a negative confirmation will be sent back to the mobile application 110, and the remote device 102 will not be displayed in the list on the mobile application.
[0028] The certificate is used to authenticate the mobile application 110. The firmware of the remote device 102 includes a decryption algorithm that it applies to the certificate to determine if the mobile device 112 is a valid mobile device. The remote device 102 does not communicate with the mobile application 110 until the certificate is verified.
[0029] Once both the mobile application 110 and the remote device 102 are authenticated, a list of authenticated remote devices 102 is sent to the authenticator device 200, where it is stored in the internal memory 208 until cloud connectivity is restored. At this point, the cloud network 306 synchronizes with the authenticator device 200 and receives the list of authenticated and configured remote devices 102.
[0030] If during communication between the mobile application 110 and the remote device 102 , the communication is terminated, then when communication is re-established, the remote device 102 will again request a certificate from the mobile application in order to re-verify that the mobile application 110 is valid.
[0031] In one embodiment, another layer of encryption can be utilized to prevent a malicious device from accessing the encrypted string from the mobile application 110 by impersonating a valid remote device. After receiving the encrypted string from the mobile application 110, the authenticator device 200 can then send a random encrypted equation back to the remote device 102 via the mobile application 110. The random encrypted equation can be received from the cloud network 306 when the authenticator device 200 is in online mode 402. The remote device 102 decodes the encrypted equation, solves the equation, encrypts the answer to the equation, and sends the encrypted answer back to the authenticator device 200 via the mobile application 110. The equation can change randomly. The random equation can be deleted from the authenticator device's internal memory 208 after a fixed period of time. Similarly, for the certificate and encrypted string, the fixed period of time can be seventy-two hours, however, other time periods can also be used.
[0032] Figure 5 The process flow for authenticating a wireless device in an offline environment is shown. Figure 5 , method 500 connects (502) the authenticator device to the cloud network. Method 500 also receives (504) an authentication key and certificate from the cloud network by the authenticator device. Method 500 also stores (506) the authentication key and certificate in an internal memory of the authenticator device. When the authenticator device is not connected to the cloud network, method 500 also establishes (508) a connection to a mobile device, the mobile device including a mobile application for communicating with the remote device, by the authenticator device. Method 500 also authenticates (510) the remote device using the authentication key via the mobile application, by the authenticator device.
[0033] Although the subject matter has been described in language specific to structural features and / or acts, it will be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as examples of implementing the claims, and other equivalent features and acts are intended to be within the scope of the claims.
Claims
1. An authenticator device, comprising: Memory; as well as Controller: receiving authentication information from the cloud network via the communication interface, storing the authentication information in the memory, and When the authenticator device and a device are not connected to the cloud network, the device is authenticated using the authentication information. 2 . The authenticator device of claim 1 , further comprising a real-time clock that is synchronized to a local time when the authenticator device is connected to the cloud network via the communication interface.
3. The authenticator device according to claim 1, wherein: The device is a remote device.
4. The authenticator device according to claim 3, wherein: The remote devices are a plurality of wireless lighting fixtures configured into a mesh network.
5. The authenticator device according to claim 1, wherein: The device is a mobile application installed on a mobile device.
6. A method for authenticating a wireless device in an offline environment, the method comprising: Connecting the authenticator device to the cloud network; receiving, by the authenticator device, an authentication key and a certificate from the cloud network; storing the authentication key and the certificate in an internal memory of the authenticator device; establishing, by the authenticator device, a connection to a mobile device when the authenticator device is not connected to the cloud network, the mobile device including a mobile application that communicates with a remote device; as well as The remote device is authenticated by the authenticator device via the mobile application using the authentication key.
7. The method according to claim 6, wherein: Authenticating the remote device includes: establishing communication between the mobile application and the remote device; receiving, by the mobile application, an encrypted string from the remote device; The mobile application transmits the encrypted string to the authenticator device; Decrypting the encrypted string by the authenticator device using the authentication key; The remote device is authenticated in response to a valid encrypted string.
8. The method according to claim 7, further comprising authenticating the mobile application by: receiving, by the remote device via the mobile device, the certificate from the authenticator device; Decrypting the certificate by the remote device using an algorithm; as well as Responsive to the valid certificate, the mobile application is authenticated.
9. The method according to claim 8, wherein When the mobile application and the remote device are authenticated, the remote device is added to a list in the mobile application as an authenticated remote device.
10. The method according to claim 9, further comprising: A mesh network of remote devices including the authenticated remote device is configured by the mobile application.
11. The method according to claim 9, further comprising: The list is transferred from the mobile application to the authenticator device, the list is stored by the authenticator device in the internal memory, and when the authenticator device is connected to the cloud network, the list is transferred to the cloud network.
12. The method according to claim 6, further comprising: After a fixed period of time, the authentication key and the certificate are deleted from the internal memory by the authenticator device.
13. The method according to claim 12, wherein: The fixed time period is seventy-two hours.
14. The method according to claim 12, further comprising: When the authenticator device is connected to the cloud network, a real-time clock on the authenticator device is synchronized with the current time.
15. An authentication system comprising: an authenticator device comprising a memory and a controller, wherein the controller receives an authentication key and a certificate from a cloud network via a communication interface and stores the authentication key and the certificate in the memory; wireless remote device; and a mobile device comprising a mobile application, said mobile application communicating with said authenticator device and said wireless remote device, Wherein, when the authenticator device and the wireless remote device are not connected to the cloud network, the authenticator device authenticates the wireless remote device via the mobile device.