Authentication method and device of terminal equipment and electronic equipment
Patent Information
- Application Number
- CN202511713844.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-20
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2045-11-20
AI Technical Summary
[0003]存在以下显著问题:离线鉴权依赖云端交互:需预置多组密钥或通过卫星通信更新,违背无网场景核心需求
[0018]在本申请实施例中,采用在离线情况下,目标终端设备完成授权流程后,获取本地内存中的目标授权许可文件;依据目标授权许可文件进行鉴权流程,其中,目标授权许可文件与目标芯片标识绑定,目标芯片标识为目标终端设备的芯片标识的方式,通过在授权后取本地内存中的目标授权许可文件;依据目标授权许可文件进行鉴权流程,完全在离线的情况下仅依据目标授权许可文件进行鉴权流程,进而解决了相关技术离线鉴权依赖云端交互,需预置多组密钥或通过卫星通信更新,不适配离线终端自主授权鉴权的技术问题。
Smart Images

Figure CN121531361B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and more specifically, to an authentication method, apparatus, and electronic device for a terminal device. Background Technology
[0002] Authorization and authentication provide reliability and security guarantees for high-precision positioning enhancement services (such as satellite-based navigation enhancement services). As a service with extremely high security and reliability requirements, high-precision positioning enhancement services necessitate the design of an efficient, secure, and easily manageable authorization and authentication method. Most existing high-precision positioning enhancement services broadcast enhancement information via the internet, and their authorization and authentication are primarily implemented when a network connection is available. First, the terminal is registered and authorized. After the terminal is powered on, it sends an authentication request. Once authenticated, the terminal uploads its approximate location to the ground data center based on the Nrtip protocol and receives grid differential data to complete the high-precision positioning calculation. The entire process relies on the collaboration between the ground network and the data center.
[0003] The following significant issues exist: Offline authentication relies on cloud interaction: multiple sets of keys need to be pre-configured or updated via satellite communication, violating the core requirements of offline scenarios. There is a risk of service theft: the cloud periodically generates encryption and decryption keys, with the decryption key generated from the encryption key and related to the device ID. However, in offline scenarios, legitimate terminals do not interact with the cloud. If an attacker clones the legitimate terminal's key and ID to a new device, the new device can decrypt the received information and perform high-precision location calculations. Furthermore, the methods in related technologies are not suitable for offline terminal self-authorization and authentication.
[0004] There is currently no effective solution to the above problems. Summary of the Invention
[0005] This application provides an authentication method, apparatus, and electronic device for terminal devices, which at least solves the technical problem that related technologies rely on cloud interaction for offline authentication, require multiple pre-set keys or updates via satellite communication, and are not suitable for offline terminal self-authorization authentication.
[0006] According to one aspect of the embodiments of this application, an authentication method for a terminal device is provided, comprising: in an offline state, after the target terminal device completes the authorization process, obtaining a target authorization license file in local memory; and performing an authentication process based on the target authorization license file, wherein the target authorization license file is bound to a target chip identifier, and the target chip identifier is the chip identifier of the target terminal device.
[0007] Optionally, the terminal device completes the authorization process as follows: receiving an initial encrypted license file created by the data center, wherein each initial encrypted license file is bound to a chip identifier of a terminal device; decrypting the initial encrypted license file and obtaining the initial chip identifier indicated by the terminal information field in the initial encrypted license file; if the initial chip identifier is the same as the chip identifier of the target terminal device, the target terminal device performs the following authorization process: updating the local license file in the local memory of the target terminal device to the initial encrypted license file to obtain the target license file, wherein the content of the terminal information field of the local license file is the chip identifier of the target terminal device, and the service validity content field and service level field of the local license file are empty.
[0008] Optionally, the initial empty license file in the local memory of the target terminal device is updated to an initial encrypted license file to obtain the target license file. This includes: reading the content indicated by the service validity content field and the service level field in the initial encrypted license file, wherein the service validity content field and the service level field are used to limit the usage conditions of the corresponding service, and the service validity content is used to indicate the service validity period of the corresponding service; and updating the content indicated by the service validity content field and the service level field in the initial encrypted license file to the corresponding fields in the local license file to obtain the target license file.
[0009] Optionally, the authentication process based on the target license document includes: reading the terminal identifier of the target terminal device each time the target terminal device is powered on; obtaining the target chip identifier in the target license document; if the target chip identifier is the same as the chip identifier of the target terminal device, performing service validity verification and obtaining the verification result; if the verification result is that the service validity verification is passed, obtaining the service level information in the service level field of the target license document.
[0010] Optionally, if the target chip identifier is the same as the chip identifier of the target terminal device, service validity verification is performed to obtain the verification result, including: the target terminal receiving ephemeris data and obtaining the target time in the ephemeris data; obtaining the service validity period of the service validity content field of the target license document, wherein the service validity period includes the start time and the end time; and performing service validity verification based on the target time and the service validity period to obtain the verification result.
[0011] Optionally, service validity verification is performed based on the target time and service validity period to obtain a verification result, including: if the target time is between the start time and the end time, the verification result is determined to be a successful service validity verification; if the target time is earlier than the start time or later than the end time, the verification result is determined to be a failed service validity verification.
[0012] Optionally, after obtaining the service level information in the service level field of the target license file, the method further includes: determining the service level in the service level information, wherein the service level is one of the following: precise single-point positioning, precise single-point positioning with fixed ambiguity, or real-time dynamic precise single-point positioning; and activating the algorithm corresponding to the service level information to perform positioning calculation.
[0013] Optionally, the initial encrypted license file is obtained by encrypting the service information using an encryption algorithm. The service information is obtained in response to the input instructions of the user using the target terminal, and includes a terminal information field, a service validity field, and a service level field.
[0014] According to another aspect of the embodiments of this application, an authentication device for a terminal device is also provided, comprising: an acquisition module, configured to acquire a target license file in local memory after the target terminal device completes the authorization process in an offline state; and an authentication module, configured to perform an authentication process based on the target license file, wherein the target license file is bound to a target chip identifier, and the target chip identifier is the chip identifier of the target terminal device.
[0015] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, wherein a program is stored in the non-volatile storage medium, and the program controls the device where the non-volatile storage medium is located to execute the above-mentioned authentication method of the terminal device when it runs.
[0016] According to another aspect of the embodiments of this application, an electronic device is also provided, including: a memory and a processor, wherein the processor is configured to run a program stored in the memory, wherein the program executes the authentication method of the terminal device described above when it runs.
[0017] According to another aspect of the embodiments of this application, a computer program product is also provided, including computer instructions, which, when executed by a processor, implement the authentication method of the terminal device described above.
[0018] In this embodiment, the target terminal device obtains the target license file in its local memory after completing the authorization process in an offline manner; and performs an authentication process based on the target license file. The target license file is bound to a target chip identifier, which is the chip identifier of the target terminal device. By retrieving the target license file from its local memory after authorization and performing the authentication process based on it, the authentication process is conducted entirely offline, relying solely on the target license file. This solves the technical problem of related technologies where offline authentication relies on cloud interaction, requires multiple pre-set keys or updates via satellite communication, and is not suitable for independent authorization and authentication by offline terminals. Attached Figure Description
[0019] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0020] Figure 1 This is a hardware structure block diagram of a computer terminal for implementing an authentication method for a terminal device, according to an embodiment of this application.
[0021] Figure 2 This is a flowchart of an authentication method for a terminal device according to an embodiment of this application;
[0022] Figure 3 This is a flowchart of an authorization and authentication system for a terminal device provided according to an embodiment of this application;
[0023] Figure 4 This is a flowchart illustrating the generation of an authorization document according to an embodiment of this application;
[0024] Figure 5 This is a flowchart illustrating an encryption process for a license file according to an embodiment of this application;
[0025] Figure 6 This is an authorization flowchart provided according to an embodiment of this application;
[0026] Figure 7 This is an authentication flowchart provided according to an embodiment of this application;
[0027] Figure 8 This is a schematic diagram of the structure of an authentication device for a terminal device according to an embodiment of this application. Detailed Implementation
[0028] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0029] The information collected in this application embodiment is information and data authorized by the user or fully authorized by all parties. The collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data all comply with the relevant laws, regulations and standards of the relevant regions, and necessary confidentiality measures have been taken. It does not violate public order and good morals, and provides corresponding operation entry points for users to choose to authorize or reject the automated decision results. If the user chooses to reject, the process will proceed to the expert decision-making process.
[0030] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0031] To better understand the embodiments of this application, the technical terms involved in the embodiments of this application are explained below:
[0032] Satellite-based augmentation systems (SBAs) use geostationary orbit (GEO) satellites equipped with satellite navigation augmentation signal transponders to broadcast various correction information such as ephemeris errors, satellite clock errors, and ionospheric delays to users, thereby improving the positioning accuracy of the original satellite navigation system.
[0033] User authentication: A method for authenticating users attempting to access services from a service provider in a communication network.
[0034] Standard Point Positioning (SPP): A positioning technology based on GNSS (Global Navigation Satellite System). It mainly relies on pseudorange observations and broadcast ephemeris for positioning. It does not require complex error processing strategies and does not use carrier phase observations that require fixed ambiguity.
[0035] Precise Point Positioning (PPP): By using CORS stations evenly distributed around the world to calculate high-precision satellite ephemeris products and correct user orbit and clock errors, PPP can provide static positioning services at the millimeter to centimeter level and dynamic positioning services at the centimeter to decimeter level.
[0036] Precise Point Positioning with Ambiguity Resolution (PPP-AR): A precision point positioning technique that improves positioning accuracy and convergence speed by fixing the phase floating-point ambiguity to an integer using uncorrected phase fractional deviation products.
[0037] Precise Point Positioning (PPP-RTK) is a high-precision positioning technology based on State Domain Recognition (SSR). It generates a set of state corrections, including satellite clock errors, orbital errors, and regional ionospheric errors, by comprehensively estimating and modeling base station data. These corrections are then sent to a rover for position calculation, achieving sub-centimeter-level positioning accuracy under dynamic conditions. PPP-RTK technology is particularly suitable for services requiring high-frequency, high-precision positioning, such as autonomous vehicles and precision agricultural machinery positioning.
[0038] NTRIP (Networked Transport of RTCM via Internet Protocol): A protocol for transmitting RTCM over the Internet.
[0039] In related technologies, many high-precision positioning enhancement services broadcast enhancement information via the internet. Authorization and authentication for these services are primarily implemented when there is a network connection. First, the terminal is registered and authorized. After the terminal powers on, it sends an authentication request. Once authenticated, the terminal uploads its approximate location to a ground data center based on the Nrtip protocol and receives grid differential data to complete high-precision positioning calculations. The entire process relies on the collaboration between the ground network and the data center. Offline authentication depends on cloud interaction: multiple sets of keys need to be pre-configured or updated via satellite communication, violating the core requirements of offline scenarios. There is also a risk of service theft: the cloud periodically generates encryption and decryption keys, with the decryption key generated from the encryption key and related to the device ID. However, in offline scenarios, legitimate terminals do not interact with the cloud. If an attacker clones the legitimate terminal's key + ID to a new device, the new device can decrypt the received information and perform high-precision positioning calculations. Therefore, related technologies suffer from the problem of relying on cloud interaction for offline authentication, requiring multiple sets of keys or updates via satellite communication, which is unsuitable for offline terminal self-authorization and authentication. To address this issue, this application provides a related solution, detailed below.
[0040] According to an embodiment of this application, an embodiment of an authentication method for a terminal device is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0041] The methods and embodiments provided in this application can be executed on a computer terminal or similar computing device. Figure 1 A hardware block diagram of a computer terminal for implementing an authentication method for terminal devices is shown. Figure 1 As shown, the computer terminal 10 may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) 102 (processor 102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0042] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10. As involved in the embodiments of this application, the data processing circuits serve as processor control (e.g., selection of a variable resistor termination path connected to an interface).
[0043] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the authentication method of the terminal device in this embodiment. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby implementing the aforementioned authentication method of the terminal device. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0044] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0045] The display can be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 10.
[0046] In the above operating environment, this application provides an embodiment of an authentication method for a terminal device. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0047] like Figure 2 The diagram shown is a flowchart of an authentication method for a terminal device according to an embodiment of this application, including:
[0048] Step S202: In offline mode, after the target terminal device completes the authorization process, it obtains the target license file in its local memory.
[0049] Authorization refers to the process by which a resource owner grants access or operation rights to a user or entity for a specific resource. This restricts users to accessing only authorized resources, preventing unauthorized operations. Authentication verifies the authenticity and validity of a user's claimed identity or permissions, ensuring the visitor's identity is genuine, blocking unauthorized requests, and mitigating security risks such as identity forgery and credential theft. Authorization and authentication provide reliability and security guarantees for high-precision positioning enhancement services. As a service with extremely high security and reliability requirements, high-precision positioning enhancement services necessitate the design of an efficient, secure, and easily manageable authorization and authentication method.
[0050] In some embodiments of this application, the authorization and authentication processes performed by the target terminal device are for authorizing and authenticating the target service (high-precision positioning enhancement service, such as satellite-based navigation enhancement service, which broadcasts additional satellite-based enhancement information to GNSS receivers via satellites in geostationary Earth Orbit (GEO) to help users obtain more accurate and reliable positioning, navigation, and timing services in a specific area). The authorization process confirms whether the terminal is authorized to use a specific level of enhancement service, while the authentication process verifies the validity and authenticity of its authorization information before the terminal uses the service, ensuring that the terminal can independently determine its usage rights even in a network-free environment. The application scenario is where the authorization and authentication process cannot be completed by the terminal without interaction with the cloud. It is applicable not only to areas without terrestrial networks, such as oceans and deserts, but also to areas with terrestrial networks. The core equipment involved in the method of this application embodiment includes the satellite side (communication satellite), the terminal side (i.e., the target terminal device), and the data center. The functions of each part are as follows: Communication satellite: broadcasts satellite-based enhancement information. BeiDou Satellites: Medium Earth Orbit (MEO) / Inclined Geosynchronous Satellite Orbit (IGSO) orbit satellites, operating in the L-band (a radio frequency band between 1 and 2 GHz), providing navigation signals and a time reference. User Terminals (i.e., target terminal equipment): Receive navigation signals and satellite-broadcast augmentation signals, perform user hierarchical authentication processes, and calculate positioning. Data Center: Deploys the operation platform and service platform, generates differential augmentation correction information, and generates encrypted license files according to user needs.
[0051] In the technical solution provided in step S202, the initial encrypted license file is obtained by encrypting the service information using an encryption algorithm. The service information is obtained in response to input instructions from a user using the target terminal, and includes a terminal information field, a service validity field, and a service level field. The following describes the construction process of the initial encrypted license file.
[0052] Figure 3 This is a flowchart of an authorization and authentication system for a terminal device according to an embodiment of this application. In the absence of a network, the satellite-based navigation augmentation user authorization and authentication system (i.e., the terminal device's authorization and authentication system) can be used to execute the methods in this embodiment, including an authorization license file generation and encryption module, an authorization license file decryption module, a service authorization and authentication module, and a signal receiving module. The signal receiving module receives navigation signals and satellite broadcast satellite-based augmentation signals. The authorization license file generation and encryption module generates an authorization license file based on user input information. The authorization license file decryption module encrypts and decrypts the generated authorization license file. The service authorization and authentication module authorizes and authenticates services and calls the corresponding satellite-based augmentation algorithm (such as PPP / PPP-AR / PPP-RTK) based on the authentication result.
[0053] The initial encrypted license file is constructed by the data center through the service authorization and authentication module. First, the user of the target terminal inputs service information via input commands. This service information includes terminal information, service validity, and service level fields. The terminal information field contains the terminal's chip identifier (Unique Identifier (UID), which is a unique code embedded in the user terminal hardware). The service validity and service level fields define the usage conditions of the corresponding service. The service validity field indicates the service validity period, i.e., the start and end time of the service. The service level field uses PPP / PPP-AR / PPP-RTK to provide corresponding precision levels according to different service requirements. The data center responds to the user's input commands and generates the initial license file based on the service information input. This license file is bound to the device's unique identifier, the chip UID. The next step is to encrypt the initial license file using an asymmetric encryption algorithm (e.g., RSA or ECC) to obtain the initial encrypted license file.
[0054] The functions of each field in the service information are as follows: When generating the license file, the data center embeds the chip identifier into the terminal information field. This ensures that the authorization is specific to the device, not a general authorization. After the terminal device powers on, it reads the locally stored license file and first checks whether the chip identifier in the terminal information field matches the device's own chip identifier. If they match, the terminal is a legitimate and authorized device; if they do not match, the service is denied, preventing the use of unauthorized devices. When creating the license file, the data center defines the valid start and end times of the service through the service validity field. This means that even if the terminal has the correct UID, the service may be rejected because the time is not within the validity period. The terminal device compares the timestamp in the received satellite ephemeris data with the time range in the service validity field. If the current time is within the service validity period, the service can be activated; if it is outside the validity period, the service authorization is considered invalid, and the terminal can only use the SPP service. When applying for services, users can select different service levels such as PPP, PPP-AR, or PPP-RTK through the service level field according to their needs. The data center sets a Service Level Class (SLC) field in the license file based on the user's selection to ensure accurate service authorization. Terminal devices read the SLC field to confirm the type of service they are authorized to access. This allows the terminal to invoke the appropriate location algorithm based on the SLC information, ensuring that the terminal can only access its authorized services and preventing SLC abuse.
[0055] Figure 4 This is a flowchart of an authorization license document generation process provided according to an embodiment of this application. First, the user registers / logs in to the operation platform (deployment). Figure 3 (See the system platform shown). Then select the service duration. Select the service level, determine the service level field, bind the terminal device (i.e., set the terminal information field), select the service effective time (the service effectiveness field is determined by the service effective time and service duration), and finally generate the license file (i.e., the initial license file mentioned above).
[0056] Figure 5 This is a flowchart of an encryption process for an authorization file provided according to an embodiment of this application, which uses an authorization file encryption module (i.e., the one described above). Figure 3 The system's license file generation encryption module requests encryption for the license file, calls an asymmetric encryption algorithm, generates an encrypted license file, and downloads the encrypted license file.
[0057] The terminal device completes the authorization process as follows: It receives an initial encrypted license file created by the data center, where each initial encrypted license file is bound to a terminal device's chip identifier; it decrypts the initial encrypted license file and obtains the initial chip identifier indicated by the terminal information field in the initial encrypted license file; if the initial chip identifier is the same as the target terminal device's chip identifier, the target terminal device performs the following authorization process: it updates the local license file in the target terminal device's local memory with the initial encrypted license file to obtain the target license file, where the terminal information field of the local license file contains the target terminal device's chip identifier, and the service validity content field and service level field of the local license file are empty.
[0058] There are several ways to update the initially empty license file in the local memory of the target terminal device to an initial encrypted license file, thus obtaining the target license file. For example, one method is to read the content indicated by the service validity content field and the service level field in the initial encrypted license file. The service validity content field and the service level field are used to limit the usage conditions of the corresponding service, and the service validity content field indicates the service validity period. The content indicated by the service validity content field and the service level field in the initial encrypted license file is then used to update the corresponding fields in the local license file to obtain the target license file. The authorization process is explained in detail below.
[0059] When the target terminal device first starts up or registers for the target service, it powers on and receives an initial encrypted license file created by the data center through a secure channel (such as BeiDou short message service, USB / serial port, or other physical interfaces). The terminal device has a pre-installed private key shared with the data center, which is used to decrypt the received encrypted file. Upon receiving the encrypted license file, the terminal uses its private key to decrypt it. Successful decryption indicates the license file originates from a trusted data center; failure to decrypt terminates the authorization and authentication process. The decrypted license file contains a terminal information field indicating the initial chip identifier (i.e., chip UID). The target terminal device reads this field and compares it with its own chip identifier. If they match, the terminal is an authorized device, and the authorization process continues; otherwise, a replacement unbinding process is initiated. This process involves sending a different initial encrypted license file if the current one does not belong to the target terminal, and then re-submitting the process. If the initial chip identifier matches the target terminal device's chip identifier, the terminal device updates its local license file in its memory. The update process involves copying the service validity content field and service level field from the initial encrypted license file to the local license file, while retaining the original chip identifier field (i.e., the target terminal device's chip identifier) in the local license file, thus completing the authorization process. It's important to note that before the target terminal device is first started or registered, the local license file is in an initialized state. At this time, its terminal information field contains the target terminal device's chip identifier, and the service validity content field and service level field are empty, indicating that the service is not authorized. It's also important to note that the authorization operation only needs to be performed once. After successful authorization, the target terminal device only needs to perform the authentication process each time it boots up. The authentication process includes verifying the service's validity period and checking whether the service level matches the current requirements. These verifications do not require real-time communication with the data center and can be completed autonomously by the terminal.
[0060] Figure 6 This is an authorization flowchart provided according to an embodiment of this application. After the terminal (i.e., the target terminal device mentioned above) is powered on, the encrypted authorization license file (i.e., the initial encrypted authorization license file mentioned above) is imported, and then the authorization file is decrypted. The SN information (i.e., chip identifier) is read, and it is determined whether the authorization process is complete. If not, the unbinding process is performed. If yes, the authorization process is performed: the service time and service level are identified, and the local authorization license file is updated (i.e., the service validity content field and service level field indicated in the initial encrypted authorization license file are updated to the corresponding fields in the local authorization license file to obtain the target authorization license file), and then the authorization is completed.
[0061] Step S204: Perform the authentication process based on the target license document.
[0062] In the technical solution provided in step S204, the target license file is bound to the target chip identifier, which is the chip identifier of the target terminal device.
[0063] Before obtaining the target chip identifier in the target license file, the terminal device obtains a preset private key to decrypt the target license file, which is an encrypted file.
[0064] There are several ways to implement the authentication process based on the target license document. For example: each time the target terminal device is powered on, the terminal identifier of the target terminal device is read; the target chip identifier in the target license document is obtained; if the target chip identifier is the same as the chip identifier of the target terminal device, service validity verification is performed and the verification result is obtained; if the verification result is that the service validity verification is passed, the service level information in the service level field of the target license document is obtained.
[0065] When the target chip identifier is the same as the target terminal device's chip identifier, service validity verification can be performed in several ways to obtain the verification result. For example, the target terminal receives ephemeris data and obtains the target time from the ephemeris data; obtains the service validity period from the service validity content field of the target license file, where the service validity period includes the start time and end time; performs service validity verification based on the target time and service validity period to obtain the verification result.
[0066] Service validity verification is performed based on the target time and service validity period. There are several ways to obtain the verification result. For example, if the target time is between the start time and the end time, the verification result is determined to be a successful service validity verification; if the target time is earlier than the start time or later than the end time, the verification result is determined to be a failed service validity verification.
[0067] After obtaining the service level information from the service level field of the target license file, the service level in the service level information is determined. The service level is one of the following: precise point positioning, precise point positioning with fixed ambiguity, or real-time dynamic precise point positioning. The algorithm corresponding to the service level information is then activated to perform positioning calculation. The authentication process is explained in detail below.
[0068] The authentication process is performed every time the target terminal device is powered on after the authorization process is completed. It verifies the validity of the service and whether the service level meets the current requirements, ensuring that the terminal device can only use the satellite navigation augmentation service within the authorized scope. Upon powering on, the terminal device first reads its internally stored terminal identifier, i.e., the chip UID. Then, it parses the target license file to obtain the target chip identifier. It compares the terminal identifier on the target terminal device with the target chip identifier in the license file to ensure they match. If they do not match, the target terminal device can only perform the SPP service and outputs the SPP positioning result. If the target chip identifier matches the target terminal device's chip identifier, service validity verification is performed: the target terminal receives ephemeris data and obtains the target time (i.e., the current time) from the ephemeris data. The ephemeris data can be BeiDou ephemeris data, which describes the position data and motion status information of satellites in the BeiDou satellite navigation system. This data is crucial for accurate positioning and navigation by the ground receiver. Ephemeris data contains orbital parameters for each satellite, including but not limited to the satellite's orbital position, velocity, and time information, enabling the receiver to calculate the exact position of the satellite at any given time, and then calculate the receiver's own geographical location based on the received satellite signals.
[0069] The next step is to read the service validity content field from the target license file to obtain the service start and end times. It then determines whether the target time is within the service's validity period, i.e., whether the target time is later than the start time and earlier than the end time. If so, the service validity verification passes, and the terminal can continue with service level verification. If not, the service validity verification fails, the terminal algorithm rejects the service, and only the Standard Positioning Service (SPP) can be used, outputting the SPP positioning result.
[0070] After the service validity verification is successful, the terminal obtains the service level information from the service level field of the target license file. The terminal then further reads the service level field from the target license file to obtain service level information (PPP, PPP-AR, or PPP-RTK). The service level corresponding to the service level information is determined, and the appropriate positioning algorithm is activated based on this information. The activated algorithm performs positioning calculations and outputs a satellite-based augmentation high-precision positioning result. This process is explained in detail below.
[0071] Positioning calculation refers to the process of using satellite navigation signals, combined with ground-based auxiliary information or services, to perform geometric inversion calculations to determine the precise location, velocity, and time of a target user terminal. Positioning calculation algorithms can be classified according to accuracy requirements and resource consumption, including: SPP, PPP, PPP-AR, and PPP-RTK. After service validity verification is passed, the terminal device selects and activates the corresponding positioning calculation algorithm based on the service level information in the target license document. The specific process is as follows: The terminal device reads the service level field in the target license document to obtain service level information (PPP, PPP-AR, or PPP-RTK). Based on the service level information, the terminal determines the required accuracy level and usage conditions for this positioning service.
[0072] Based on the service level information, the terminal selects and activates the corresponding positioning algorithm. If the service level information is PPP-AR, the terminal further processes the carrier phase ambiguity based on the PPP algorithm, fixing it to an integer value to accelerate positioning convergence. Specifically, the target terminal device receives the satellite's carrier phase observations and obtains the high-precision satellite orbit, clock products, and atmospheric delay correction model required for PPP-AR. Using satellite-based augmentation information, the terminal performs ambiguity resolution, attempting to fix the carrier phase ambiguity from floating-point values to integer values. Dynamic constraints (such as the user's motion pattern and known location information) are applied to further optimize the ambiguity search process. The ambiguity fixing result and correction information are input into the PPP-AR positioning model to calculate the target terminal device's position, velocity, and time information. A high-precision positioning result under satellite-based augmentation service is generated.
[0073] If the service level information is PPP-RTK, the target terminal device will combine real-time base station correction data or state domain corrections with the PPP-RTK algorithm to perform high-precision positioning calculations under dynamic conditions. Specifically, the target terminal device receives carrier phase observations from multiple satellites in real time. It obtains state domain correction information generated by the ground control center through comprehensive processing of data from multiple base stations via satellite-based augmentation services, including satellite clock deviation, orbital error, and regional atmospheric delay. The real-time received carrier phase observations are combined with the state domain correction information to perform real-time positioning calculations. By utilizing real-time correction information, the PPP-RTK positioning algorithm can achieve rapid convergence and provide high-precision positioning results under dynamic conditions. Based on the target terminal device's motion state and position information, dynamic constraints are applied to further optimize the positioning calculation process, improving positioning accuracy and processing efficiency, ultimately generating high-precision positioning results under satellite-based augmentation services.
[0074] If the service level information is PPP, the terminal device receives carrier phase and pseudorange observations from multiple satellites. High-precision satellite orbit (precise ephemeris) and clock differential information, along with an atmospheric delay correction model, are received via satellite-based augmentation service. The carrier phase observations are preprocessed, including corrections for ionospheric and tropospheric delays, as well as satellite and receiver clock errors. Based on the preprocessed observations and preliminary estimates (such as SPP results), the receiver's position, velocity, and clock bias state vectors are initialized. Iterative solutions are performed using least squares or Kalman filtering. In each iteration, the estimation result from the previous cycle is used as the initial value for the current cycle to optimize the state vector estimation until convergence to satisfactory accuracy. Based on the final converged solution, high-precision positioning results under satellite-based augmentation service are output.
[0075] The high-precision positioning results under satellite-based augmentation services include the target terminal's three-dimensional coordinates, velocity, timestamp, as well as positioning accuracy indicators and integrity parameters. This information will be used for navigation, timing, or other high-precision applications.
[0076] Figure 7 This is an authentication flowchart provided according to an embodiment of this application. After the terminal powers on, it reads the license file (locally, i.e., the target license file mentioned above), then parses the license file. If the format is incorrect, it outputs the SPP positioning result. If the format is correct, it reads the device SN and verifies the device identification information. If they are inconsistent, it outputs the SPP positioning result. If they are consistent, it reads the ephemeris time (i.e., the target time obtained by the target terminal from the ephemeris data) and verifies the service validity period (i.e., the service validity verification is performed if the target chip identifier is the same as the target terminal device's chip identifier). If they are inconsistent, it outputs the SPP positioning result. If they are consistent, it matches the satellite-based augmentation service level and outputs the satellite-based augmentation high-precision positioning result (i.e., the service level in the service level information is determined above, and the service level is one of the following: precise point positioning, precise point positioning with fixed ambiguity, or real-time dynamic precise point positioning); and activates the algorithm corresponding to the service level information to perform positioning calculation.
[0077] In related technologies, the common practice for authorizing and authenticating satellite-based navigation augmentation services is as follows:
[0078] The cloud periodically generates encryption keys (the keys are independent of the device ID); after the terminal is powered on, it initiates authentication and authorization requests to the cloud and requests a decryption key. The decryption key is generated from the encryption key, is related to the device ID, and can decrypt the encryption key in reverse. To meet offline use, the decryption key can be imported locally via USB / serial port or updated via BeiDou short message; the terminal receives satellite-based navigation augmentation information and uses the decryption key to decompress, decrypt, and decode it; the high-precision positioning calculation module performs high-precision positioning calculation based on the differential data after decompression, decryption, and decoding.
[0079] The methods described above offer coarse-grained service support, only supporting a single augmentation service and failing to differentiate between multiple service levels such as PPP / PPP-AR / PPP-RTK. They require pre-setting multiple sets of keys or updating them via satellite communication, violating the core requirements of offline scenarios. Encryption and decryption keys are periodically generated in the cloud, with the decryption key generated from the encryption key and related to the device ID. However, in offline scenarios, legitimate terminals do not interact with the cloud. If an attacker clones the legitimate terminal's key and ID to a new device, the new device can decrypt the received satellite-based navigation augmentation information and perform high-precision positioning calculations. This application presents a user authorization and authentication method for satellite-based navigation enhancement in offline environments. It binds the service authorization license file with the device's unique identifier (chip UID), service level, and service validity period. A layered, progressive security verification process is designed for business authentication, performing terminal legitimacy verification, service validity period verification, and service level matching. Anti-theft mechanisms are designed at both the hardware and time layers to avoid service theft risks. At the hardware layer, the target authorization license file is bound to the device's unique identifier (chip UID), and the chip UID is physically tamper-proof to ensure terminal uniqueness. At the time layer, real-time satellite ephemeris data is used as a timestamp to resist clock tampering attacks (synchronization accuracy ±20ns). The entire authentication process can be completed autonomously by the terminal using a single authorization license file in offline environments, without the need for multiple built-in decryption keys or interaction with the cloud to update keys, eliminating key update dependencies (reducing communication overhead by 90%). It also provides fine-grained service control, supporting PPP / PPP-AR / PPP-RTK hierarchical authentication to meet the service needs of different users.
[0080] Figure 8 This is a schematic diagram of the structure of an authentication device for a terminal device according to an embodiment of this application, including:
[0081] The acquisition module 802 is used to acquire the target license file in the local memory of the target terminal device after the authorization process is completed in an offline situation.
[0082] The acquisition module 802 is also used by the terminal device to complete the authorization process in the following ways: receiving an initial encrypted authorization license file created by the data center, wherein each initial encrypted authorization license file is bound to a chip identifier of a terminal device; decrypting the initial encrypted authorization license file and obtaining the initial chip identifier indicated by the terminal information field in the initial encrypted authorization license file; if the initial chip identifier is the same as the chip identifier of the target terminal device, the target terminal device performs the following authorization process: updating the local authorization license file in the local memory of the target terminal device to the initial encrypted authorization license file to obtain the target authorization license file, wherein the content of the terminal information field of the local authorization license file is the chip identifier of the target terminal device, and the service validity content field and service level field of the local authorization license file are empty.
[0083] The acquisition module 802 is also used to update the initially empty license file in the local memory of the target terminal device to an initial encrypted license file to obtain the target license file: read the content indicated by the service validity content field and the service level field in the initial encrypted license file, wherein the service validity content field and the service level field are used to limit the usage conditions of the corresponding service, and the service validity content is used to indicate the service validity period of the corresponding service; update the content indicated by the service validity content field and the service level field in the initial encrypted license file to the corresponding fields in the local license file to obtain the target license file.
[0084] The authentication module 804 is used to perform the authentication process based on the target license document, wherein the target license document is bound to the target chip identifier, and the target chip identifier is the chip identifier of the target terminal device.
[0085] The authentication module 804 is also used to read the terminal identifier of the target terminal device each time the target terminal device is powered on; obtain the target chip identifier in the target license file; if the target chip identifier is the same as the chip identifier of the target terminal device, perform service validity verification and obtain the verification result; if the verification result is that the service validity verification is passed, obtain the service level information in the service level field of the target license file.
[0086] The authentication module 804 is also used to perform service validity verification when the target chip identifier is the same as the target terminal device's chip identifier, and obtain the verification result: The target terminal receives ephemeris data and obtains the target time from the ephemeris data; it obtains the service validity period from the service validity content field of the target license document, where the service validity period includes a start time and an end time; it performs service validity verification based on the target time and the service validity period, and obtains the verification result. If the target time is between the start time and the end time, the verification result is determined to be a successful service validity verification; if the target time is earlier than the start time or later than the end time, the verification result is determined to be a failed service validity verification.
[0087] The authentication module 804 is also used to obtain the service level information in the service level field of the target license file, determine the service level in the service level information, and the service level is one of the following: precise single point positioning, precise single point positioning with fixed ambiguity, and real-time dynamic precise single point positioning; and activate the algorithm corresponding to the service level information to perform positioning calculation.
[0088] It should be noted that, Figure 8 The authentication device of the terminal device shown is used to perform Figure 2 The authentication method of the terminal device shown, therefore Figure 2 The relevant explanations in the authentication method of the terminal device also apply to the authentication device of the terminal device, and will not be repeated here.
[0089] It should be noted that the modules in the authentication device of the aforementioned terminal equipment can be program modules (e.g., a set of program instructions that implement a specific function) or hardware modules. For the latter, they can take the following forms, but are not limited to them: each of the above modules is represented by a processor, or the functions of each of the above modules are implemented by a processor.
[0090] This application also provides a non-volatile storage medium, which includes a stored program, wherein, when the program is running, it controls the device where the non-volatile storage medium is located to execute the authentication method of the terminal device in any of the above embodiments.
[0091] This application also provides an electronic device, which includes a processor for running a program, wherein the authentication method of the terminal device in any of the above embodiments is executed when the program is running.
[0092] According to another aspect of the embodiments of this application, a computer program product is also provided, including a computer program that, when executed by a processor, implements the authentication method of the terminal device in any of the above embodiments.
[0093] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0094] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0095] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0096] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0097] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to related technologies, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0098] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. An authentication method for a terminal device, characterized in that, include: In offline mode, after the target terminal device completes the authorization process, it obtains the target license file from its local memory; An authentication process is performed based on the target license document, wherein the target license document is bound to a target chip identifier, and the target chip identifier is the chip identifier of the target terminal device; The terminal device completes the authorization process in the following ways: Receive an initial encrypted license file created by the data center, wherein each of the initial encrypted license files is bound to a chip identifier of a terminal device; The initial encrypted license file is decrypted, and the initial chip identifier indicated by the terminal information field in the initial encrypted license file is obtained; If the initial chip identifier is the same as the chip identifier of the target terminal device, the target terminal device performs the following authorization process: The local license file in the local memory of the target terminal device is updated with the initial encrypted license file to obtain the target license file. The terminal information field of the local license file contains the chip identifier of the target terminal device, and the service validity content field and service level field of the local license file are empty. The authentication process based on the target license document includes: Each time the target terminal device is powered on, its chip identifier is read. Obtain the target chip identifier from the target license file; If the target chip identifier is the same as the chip identifier of the target terminal device, a service validity verification is performed to obtain the verification result; If the verification result is that the service validity verification is passed, obtain the service level information from the service level field of the target license file; If the target chip identifier is the same as the chip identifier of the target terminal device, service validity verification is performed to obtain the verification result, including: The target terminal receives ephemeris data and obtains the target time from the ephemeris data; Obtain the service validity period from the service validity content field of the target license file, wherein the service validity period includes a start time and an end time; The service validity is verified based on the target time and the service validity period to obtain the verification result.
2. The method according to claim 1, characterized in that, The step of updating the local license file in the local memory of the target terminal device to the initial encrypted license file to obtain the target license file includes: Read the contents indicated by the service validity content field and the service level field in the initial encrypted license file, wherein the service validity content field and the service level field are used to limit the usage conditions of the corresponding service, and the service validity content is used to indicate the service validity period of the corresponding service; The content indicated by the service validity content field and service level field in the initial encrypted license file is updated to the corresponding fields in the local license file to obtain the target license file.
3. The method according to claim 1, characterized in that, The process of verifying service validity based on the target time and the service validity period to obtain the verification result includes: If the target time is between the start time and the end time, the verification result is determined to be a successful service validity verification. If the target time is earlier than the start time or later than the end time, the verification result is determined to be a service validity verification failure.
4. The method according to claim 1, characterized in that, After obtaining the service level information from the service level field of the target license file, the method further includes: The service level in the service level information is determined, and the service level is one of the following: precise single-point positioning, precise single-point positioning with fixed ambiguity, and real-time dynamic precise single-point positioning. The algorithm corresponding to the service level information is activated to perform location calculation.
5. The method according to claim 1, characterized in that, The initial encrypted license file is obtained by encrypting the service information using an encryption algorithm. The service information is obtained in response to the input instructions of the user using the target terminal, and the service information includes a terminal information field, a service validity content field, and a service level field.
6. An authentication device for a terminal device, characterized in that, include: The acquisition module is used to acquire the target license file in the local memory of the target terminal device after the authorization process is completed in an offline situation. The terminal device completes the authorization process as follows: receiving an initial encrypted authorization license file created by the data center, wherein each initial encrypted authorization license file is bound to a chip identifier of a terminal device; decrypting the initial encrypted authorization license file and obtaining the initial chip identifier indicated by the terminal information field in the initial encrypted authorization license file; if the initial chip identifier is the same as the chip identifier of the target terminal device, the target terminal device performs the following authorization process: updating the local authorization license file in the local memory of the target terminal device to the initial encrypted authorization license file to obtain the target authorization license file, wherein the content of the terminal information field of the local authorization license file is the chip identifier of the target terminal device, and the service validity content field and service level field of the local authorization license file are empty; An authentication module is used to perform an authentication process based on the target license document, wherein the target license document is bound to a target chip identifier, and the target chip identifier is the chip identifier of the target terminal device. The authentication process based on the target license document includes: reading the chip identifier of the target terminal device each time the target terminal device is powered on; obtaining the target chip identifier from the target license document; if the target chip identifier is the same as the chip identifier of the target terminal device, performing service validity verification and obtaining a verification result; if the verification result indicates that the service validity verification is successful, obtaining the service level information from the service level field of the target license document; if the target chip identifier is the same as the chip identifier of the target terminal device, performing service validity verification and obtaining a verification result includes: the target terminal receiving ephemeris data and obtaining the target time from the ephemeris data; obtaining the service validity period from the service validity content field of the target license document, wherein the service validity period includes a start time and an end time; performing service validity verification based on the target time and the service validity period and obtaining the verification result.
7. A non-volatile storage medium, characterized in that, The non-volatile storage medium stores a program, wherein when the program is executed, it controls the device where the non-volatile storage medium is located to execute the authentication method of the terminal device according to any one of claims 1 to 5.
8. An electronic device, characterized in that, include: A memory and a processor, the processor being configured to run a program stored in the memory, wherein the program, when running, executes the authentication method of the terminal device according to any one of claims 1 to 5.
9. A computer program product comprising computer instructions, characterized in that, When the computer instructions are executed by the processor, they implement the authentication method of the terminal device according to any one of claims 1 to 5.
Citation Information
Patent Citations
Authorization method and device for edge device
CN115292691A
Off-line authorization method and off-line authorization system based on security equipment and storage medium
CN118070316A