Intelligent device configuration method and system for end-to-end authentication
By pre-storing triple certificates during the production of smart devices and using encryption and decryption of identifier codes and public and private key data, the security and efficiency issues of batch installation of wireless devices are solved, enabling batch configuration without power or network and reducing labor costs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HANGZHOU BROADLINK ELECTRONICS TECH
- Filing Date
- 2025-12-26
- Publication Date
- 2026-05-01
AI Technical Summary
The current method of installing wireless devices in batches requires power-on and network connection, which poses risks to installation, configuration and debugging, and makes it impossible to quickly achieve batch configuration and ensure security.
By pre-storing triple certificates during the production of smart devices and encrypting and decrypting them using identifier codes and public/private key data, an end-to-end authentication smart device configuration system is achieved. This system includes smart devices, cloud servers, configuration platforms, and scanning tools, ensuring the binding of devices to intelligent solutions and the security of configuration results.
While ensuring safety, the system enables the batch addition and configuration of smart devices, improving configuration and installation efficiency and reducing labor costs.
Smart Images

Figure CN121966952A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet of Things (IoT) technology applications, and in particular to an end-to-end authentication method and system for configuring smart devices. Background Technology
[0002] Currently, wireless devices require users to scan for the device on their mobile phones and manually pair and bind it before they can be used. This process can only be done one device at a time, and the devices must be connected to the internet and powered on. Moreover, it requires highly skilled operators who need to master the operation methods and software processes of the relevant products, making it unsuitable for mass delivery of projects.
[0003] There is currently no effective solution to the problem that the existing batch installation of wireless devices requires power-on and network connection, and there are risks in installation, configuration and debugging, which makes it impossible to quickly achieve batch configuration and ensure security. Summary of the Invention
[0004] To address the aforementioned technical problems, embodiments of the present invention aim to provide an end-to-end authenticated smart device configuration method and system, thereby at least resolving the issues that existing methods for batch installation of wireless devices require power-on and network connection, and that pose risks during installation, configuration, and debugging, thus hindering rapid batch configuration and ensuring security.
[0005] The technical solution of this invention is implemented as follows: This invention provides an end-to-end authentication smart device configuration system, comprising: a smart device, a cloud server, a configuration platform, and a scanning tool. The smart device pre-stores a triple certificate during production. The smart device also possesses an identification code. The scanning tool scans the identification code of the smart device and sends it to the configuration platform. The configuration platform configures a smart solution based on project information, receives the identification code sent by the scanning device, retrieves the triple certificate from the smart device based on the identification code, and binds the smart device to the smart solution based on the triple certificate. The smart device configures the project according to the smart solution, obtains the configuration result, and sends the configuration result to the cloud server. The cloud server retrieves the configuration result and verifies whether the configuration is complete based on the pre-stored triple certificate of the smart device.
[0006] Optionally, the configuration platform is also used to configure group information, scenes, and linkage control of smart devices based on project information; and to generate intelligent solutions based on the group information, scenes, and linkage control of smart devices.
[0007] Optionally, the configuration platform is also used to add smart devices based on the identification code; to encrypt the smart device's intelligent scheme based on the public and private key data in the triple certificate, and to send the encrypted intelligent scheme to the smart device.
[0008] Optionally, the smart device is also used to receive the intelligent solution, decrypt the intelligent solution using the public and private key data in the triple certificate, obtain the decrypted intelligent solution, configure it according to the decrypted intelligent solution, obtain the configuration result, and upload the configuration result to the cloud server.
[0009] Furthermore, optionally, the cloud server is also used to receive the configuration results sent by the smart device, decrypt the configuration results based on the public and private key data in the pre-stored triple certificate, verify the decrypted configuration results, and determine whether the smart device is fully configured; if the configuration is complete, the configuration ends; if the configuration is incomplete, the smart device is controlled to reconfigure.
[0010] Optionally, the cloud server is also used to store the triplet certificate of the smart device before configuring the intelligent solution on the configuration platform.
[0011] This invention provides an end-to-end authentication smart device configuration method, applied to an end-to-end authentication smart device configuration system, comprising: configuring an intelligent scheme according to project information; receiving an identification code of the smart device sent by a scanning device; obtaining a triple certificate in the smart device based on the identification code; and binding the smart device to the intelligent scheme based on the triple certificate.
[0012] Optionally, configuring an intelligent solution based on project information includes: configuring group information, scenes, and linkage control of intelligent devices based on project information; and generating an intelligent solution based on the group information, scenes, and linkage control of intelligent devices.
[0013] Furthermore, optionally, binding the smart device to the smart solution based on the triple certificate includes: adding the smart device based on the identification code; encrypting the smart solution of the smart device based on the public and private key data in the triple certificate to obtain the encrypted smart solution; and sending the encrypted smart solution to the smart device.
[0014] This invention provides an end-to-end authentication smart device configuration method, applied to an end-to-end authentication smart device configuration system, comprising: pre-storing a triple certificate during smart device production; wherein the smart device also has an identification code; receiving an encrypted smart scheme sent by a configuration platform; decrypting the encrypted smart scheme based on the triple certificate to obtain a decrypted smart scheme; configuring the smart scheme based on the decrypted smart optimization scheme to obtain a configuration result; verifying the configuration result and uploading the verified configuration result to a cloud server.
[0015] This invention provides an end-to-end authentication smart device configuration system and method. The system involves pre-storing a triple certificate in the smart device during production. The smart device also possesses an identification code. A scanning tool scans the identification code and sends it to a configuration platform. The configuration platform configures an intelligent solution based on project information, receives the identification code from the scanning device, retrieves the triple certificate from the smart device, and binds the smart device to the intelligent solution based on the triple certificate. The smart device configures the project according to the intelligent solution, obtains the configuration result, and sends the configuration result to a cloud server. The cloud server retrieves the configuration result and verifies its completion based on the pre-stored triple certificate of the smart device. This system enables batch addition and configuration of smart devices while ensuring security, improving configuration and installation efficiency and reducing labor costs. Attached Figure Description
[0016] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings: Figure 1 This is a schematic diagram of an end-to-end authentication smart device configuration system provided in an embodiment of the present invention; Figure 2 This is a schematic diagram illustrating the interaction between a cloud server and a smart device in an end-to-end authentication smart device configuration system provided by an embodiment of the present invention. Figure 3 This is a schematic diagram illustrating the interaction between a cloud server, an intermediate device, and a smart device in an end-to-end authentication smart device configuration system provided by an embodiment of the present invention. Figure 4 A flowchart illustrating an end-to-end authentication smart device configuration method provided in an embodiment of the present invention; Figure 5 This is a flowchart illustrating another end-to-end authentication smart device configuration method provided in an embodiment of the present invention. Detailed Implementation
[0017] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0018] It should be noted that the terms "first," "second," etc., in the specification, claims, and drawings of this invention are used to distinguish different objects, rather than to limit a specific order.
[0019] It should also be noted that the various embodiments of the present invention described below can be executed individually or in combination with each other, and the embodiments of the present invention do not impose specific limitations in this regard.
[0020] This invention provides an end-to-end authentication smart device configuration system. Figure 1 This is a schematic diagram of an end-to-end authentication smart device configuration system provided in an embodiment of the present invention; as shown. Figure 1 As shown, the end-to-end authentication smart device configuration system provided in this application embodiment includes: The system comprises an intelligent device 12, a cloud server 14, a configuration platform 16, and a scanning tool 18. The intelligent device 12 pre-stores a triple certificate during production. It also possesses an identification code. The scanning tool 18 scans the identification code of the intelligent device 12 and sends it to the configuration platform 16. The configuration platform 16 configures the intelligent solution according to project information, receives the identification code sent by the scanning device, retrieves the triple certificate from the intelligent device 12 based on the identification code, and binds the intelligent device 12 to the intelligent solution based on the triple certificate. The intelligent device 12 configures the project according to the intelligent solution, obtains the configuration result, and sends the configuration result to the cloud server 14. The cloud server 14 retrieves the configuration result and verifies whether the configuration is complete based on the pre-stored triple certificate of the intelligent device 12.
[0021] Specifically, in this embodiment, the smart device pre-stores a triple certificate including: the smart device's private key, public key, and the smart device's unique ID (i.e., the identifier code in this embodiment); the triple certificate in this embodiment is only used when the smart device is running.
[0022] Optionally, the configuration platform 16 is also used to configure the group information, scenes, and linkage control of the smart devices 12 according to the project information; and to generate an intelligent solution based on the group information, scenes, and linkage control of the smart devices 12.
[0023] The group information of the smart device 12 configured according to the project information can be: the configuration information of the network where the smart device 12 is located, including: network ID and network key.
[0024] Optionally, the configuration platform 16 is also used to add the smart device 12 based on the identification code; to encrypt the intelligent scheme of the smart device 12 based on the public and private key data in the triple certificate, and to send the encrypted intelligent scheme to the smart device 12.
[0025] Optionally, the smart device 12 is also used to receive the intelligent scheme, decrypt the intelligent scheme through the public and private key data in the triple certificate to obtain the decrypted intelligent scheme, configure it according to the decrypted intelligent scheme, obtain the configuration result, and upload the configuration result to the cloud server 14.
[0026] Furthermore, optionally, the cloud server 14 is also used to receive the configuration result sent by the smart device 12, decrypt the configuration result based on the public and private key data in the pre-stored triple certificate, verify the decrypted configuration result, and determine whether the smart device 12 is configured completely; if the configuration is complete, the configuration ends; if the configuration is incomplete, the smart device 12 is controlled to reconfigure.
[0027] Optionally, the cloud server 14 is also used to store the triplet certificate of the smart device 12 before configuring the intelligent solution on the configuration platform 16.
[0028] Specifically, the end-to-end certified smart device configuration system provided in this application embodiment can be applied to application scenarios of batch installation, configuration, and debugging of smart devices. In this application embodiment, the smart device 12 can be an agile device. It should be noted that the agile device in this application embodiment can be a device with modularity and reconfigurability, digital and intelligent control, and deep integration and interconnection. Modularity and reconfigurability can be manifested in the ability to quickly reorganize functional units from standardized modules according to different production tasks, thereby manufacturing different products. Digital and intelligent control can be manifested in the use of computer numerical control (CNC), manufacturing process control systems, etc., which can monitor the processing process in real time through sensors and intelligent diagnostic software, ensuring quality and predicting maintenance needs. Deeply integrated and interconnected devices can be represented as agile devices, which are nodes in the factory information network and can be seamlessly integrated with systems such as Manufacturing Execution System (MES) and Enterprise Resource Planning (ERP) to enable continuous data flow between manufacturing, engineering, marketing and other departments.
[0029] The end-to-end authentication smart device configuration system provided in this application aims to overcome the shortcomings of existing wireless device batch installation and configuration processes and security. It achieves batch installation and debugging without power or network and batch installation and debugging by remotely obtaining configuration from cloud servers through end-to-end authentication and QR code (i.e., the identification code in this application) scanning method.
[0030] During the production of smart device 12, a triplet certificate is burned in, which contains public and private key data. The relevant data is only stored on the cloud server and on the smart device 12, and each smart device 12 has its own unique triplet that is different from other smart devices 12.
[0031] The configuration process begins by configuring the entire project's intelligent solution through the configuration platform 16, generating relevant family information, scenes, and intelligent configurations such as linkages. A tool (i.e., the scanning tool 18 in this embodiment) scans the QR code on the product. The QR code contains information such as a signature and a unique ID for the smart device 12, binding the smart device 12 to the configuration platform 16. In this embodiment, the family information may include a unique ID for the family network and a communication key.
[0032] After the user confirms that all smart devices 12 have been added in the configuration platform 16, the configuration platform 16 encrypts the configuration of each smart device 12 according to the triplet information using a public-private key algorithm, and then sends it to the smart devices 12 in sequence.
[0033] After receiving the configuration, smart device 12 uses the triplet to calculate the key, decrypts the configuration, and saves it. Once the configuration is complete, smart device 12 reports the configuration checksum to cloud server 14.
[0034] The cloud server 14 checks if the configuration is complete. If it is complete, the configuration ends; otherwise, the configuration starts again in the next round.
[0035] like Figure 2 and Figure 3 As shown, Figure 2 This is a schematic diagram illustrating the interaction between a cloud server and a smart device in an end-to-end authentication smart device configuration system provided by an embodiment of the present invention. Figure 3 This is a schematic diagram illustrating the interaction between a cloud server, an intermediate device, and a smart device in an end-to-end authentication smart device configuration system provided by an embodiment of the present invention. in, Figure 2 The cloud platform in the cloud server 14 is connected to the smart device 12 via a wireless network. There are multiple smart devices 12, and devices 1 to N are shown as examples. The wireless network in this embodiment can be a Fastcon wireless network. Figure 3 The cloud platform in Zhongyun Server 14 transmits information to smart devices through gateways, apps, or smart screens. The gateway, app, and smart screen are intermediate nodes for forwarding.
[0036] Combination Figure 2 and Figure 3 Throughout the configuration process of this application embodiment, intermediate links and gateways are unable to read configuration data, thus achieving security control. Any device that supports wireless communication can act as a forwarding node for configuration data, enabling large-scale automated device configuration.
[0037] While ensuring safety, the system enables batch addition and configuration of intelligent devices, improving configuration and installation efficiency and reducing labor costs. It also achieves product standardization and unification.
[0038] This invention provides an end-to-end authentication smart device configuration system. The system involves pre-storing a triple certificate in the smart device during production. The smart device also possesses an identification code. A scanning tool scans the identification code and sends it to a configuration platform. The configuration platform configures an intelligent solution based on project information, receives the identification code from the scanning device, retrieves the triple certificate from the smart device, and binds the smart device to the intelligent solution based on the triple certificate. The smart device configures the project according to the intelligent solution, obtains the configuration result, and sends the configuration result to a cloud server. The cloud server retrieves the configuration result and verifies its completion based on the pre-stored triple certificate of the smart device. This system enables batch addition and configuration of smart devices while ensuring security, improving configuration and installation efficiency and reducing labor costs.
[0039] This invention provides a method for configuring smart devices with end-to-end authentication. Figure 4 This is a flowchart illustrating an end-to-end authentication smart device configuration method provided in an embodiment of the present invention; as shown below. Figure 4 As shown, applied to Figure 1 The end-to-end authentication smart device configuration system shown includes, on the configuration platform side, an end-to-end authentication smart device configuration method provided in this application embodiment, comprising: Step S400: Configure the intelligent solution based on the project information; Optionally, configuring the intelligent solution based on the project information in step S400 includes: configuring the group information, scenes, and linkage control of intelligent devices based on the project information; and generating the intelligent solution based on the group information, scenes, and linkage control of intelligent devices.
[0040] Step S402: Receive the identification code of the smart device sent by the scanning device; Step S404: Obtain the triplet certificate from the smart device based on the identification code; Step S406: Bind the smart device to the smart solution based on the triple certificate.
[0041] Optionally, the binding of the smart device and the smart solution based on the triple certificate in step S406 includes: adding the smart device based on the identification code; encrypting the smart solution of the smart device based on the public and private key data in the triple certificate to obtain the encrypted smart solution; and sending the encrypted smart solution to the smart device.
[0042] In summary, combining steps S400 to S406, the end-to-end authentication smart device configuration method provided in this application embodiment is applied to... Figure 1 The end-to-end certified smart device configuration system shown is specifically applied to Figure 1 The configuration platform side of the end-to-end certified smart device configuration system shown.
[0043] This invention provides an end-to-end authentication method for configuring smart devices. By configuring a smart solution according to project information; receiving the identification code of the smart device sent by the scanning device; obtaining the triple certificate in the smart device based on the identification code; and binding the smart device with the smart solution based on the triple certificate, this method enables the batch addition and configuration of smart devices while ensuring security, thereby improving configuration and installation efficiency and reducing labor costs.
[0044] This invention provides a method for configuring smart devices with end-to-end authentication. Figure 5 This is a flowchart illustrating another end-to-end authentication smart device configuration method provided in an embodiment of the present invention; as shown below. Figure 5 As shown, applied to Figure 1 The end-to-end authentication smart device configuration system shown includes, on the smart device side, an end-to-end authentication smart device configuration method provided in this application embodiment, comprising: Step S500: Pre-store the triple certificate during the production of the smart device; wherein, the smart device also has an identification code; Step S502: Receive the encrypted intelligent solution sent by the configuration platform; Step S504: Decrypt the encrypted intelligent scheme based on the triple certificate to obtain the decrypted intelligent scheme. Step S506: Configure the system according to the decrypted intelligent optimization scheme to obtain the configuration result; Step S508: Verify the configuration result and upload the verified configuration result to the cloud server.
[0045] In summary, combining steps S500 to S508, the end-to-end authentication smart device configuration method provided in this application embodiment is applied to... Figure 1 The end-to-end certified smart device configuration system shown is specifically applied to Figure 1 The smart devices in the end-to-end certified smart device configuration system are shown.
[0046] This invention provides an end-to-end authenticated smart device configuration method. The method involves pre-storing a triple certificate during smart device manufacturing; the smart device also possesses an identification code; receiving an encrypted smart scheme from a configuration platform; decrypting the encrypted smart scheme based on the triple certificate to obtain a decrypted smart scheme; configuring the smart scheme based on the decrypted smart optimization scheme to obtain a configuration result; verifying the configuration result; and uploading the verified configuration result to a cloud server. This method enables batch addition and configuration of smart devices while ensuring security, improving configuration and installation efficiency and reducing labor costs.
[0047] The above are merely preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention.
Claims
1. An end-to-end authenticated smart device configuration system, characterized in that, include: Smart devices, cloud servers, configuration platforms, and scanning tools, among which, The smart device pre-stores a triple certificate during production; the smart device also has an identification code. The scanning tool is used to scan the identification code of the smart device and send the identification code to the configuration platform; The configuration platform is used to configure an intelligent solution according to project information, receive the identification code sent by the scanning device, obtain the triple certificate in the intelligent device according to the identification code, and bind the intelligent device to the intelligent solution according to the triple certificate. The intelligent device is used to configure the project according to the intelligent scheme, obtain the configuration result, and send the configuration result to the cloud server; The cloud server is used to obtain the configuration result and verify whether the configuration result is complete based on the pre-stored triple certificate of the smart device.
2. The intelligent device configuration system with end-to-end authentication according to claim 1, characterized in that, The configuration platform is also used to configure the group information, scene, and linkage control of the smart devices according to the project information; and to generate the intelligent solution based on the group information, scene, and linkage control of the smart devices.
3. The intelligent device configuration system with end-to-end authentication according to claim 2, characterized in that, The configuration platform is also used to add the smart device based on the identification code; encrypt the smart device's intelligent scheme based on the public and private key data in the triple certificate, and send the encrypted intelligent scheme to the smart device.
4. The intelligent device configuration system with end-to-end authentication according to claim 3, characterized in that, The smart device is further configured to receive the intelligent scheme, decrypt the intelligent scheme using the public and private key data in the triple certificate to obtain the decrypted intelligent scheme, configure it according to the decrypted intelligent scheme to obtain the configuration result, and upload the configuration result to the cloud server.
5. The intelligent device configuration system with end-to-end authentication according to claim 4, characterized in that, The cloud server is also used to receive the configuration result sent by the smart device, decrypt the configuration result according to the public and private key data in the pre-stored triple certificate, verify the decrypted configuration result, and determine whether the smart device is fully configured. If the configuration is complete, the configuration process ends; if the configuration is incomplete, the smart device is reconfigured.
6. The intelligent device configuration system with end-to-end authentication according to claim 5, characterized in that, The cloud server is also used to store the triplet certificate of the smart device before configuring the intelligent solution on the configuration platform.
7. A method for configuring an intelligent device with end-to-end authentication, characterized in that, A smart device configuration system for end-to-end authentication includes: Configure intelligent solutions based on project information; Receive the identification code of the smart device sent by the scanning device; Obtain the triplet certificate in the smart device based on the identification code; The smart device is bound to the intelligent solution based on the triple certificate.
8. The intelligent device configuration method for end-to-end authentication according to claim 7, characterized in that, The intelligent solution configuration based on project information includes: Configure the group information, scenes, and linkage control of the smart devices according to the project information; The intelligent solution is generated based on the group information of the intelligent devices, the scene, and the linkage control.
9. The intelligent device configuration method for end-to-end authentication according to claim 8, characterized in that, Binding the smart device to the smart solution based on the triple certificate includes: The smart device is added based on the identification code; The intelligent scheme of the smart device is encrypted based on the public and private key data in the triple certificate to obtain the encrypted intelligent scheme. The encrypted intelligent solution is sent to the intelligent device.
10. A method for configuring an intelligent device with end-to-end authentication, characterized in that, A smart device configuration system for end-to-end authentication includes: The triple certificate is pre-stored during the production of the smart device; the smart device also has an identification code; Receive the encrypted intelligent solution sent by the configuration platform; The encrypted intelligent scheme is decrypted based on the triple certificate to obtain the decrypted intelligent scheme; Configure the system according to the decrypted intelligent optimization scheme to obtain the configuration result; The configuration result is verified, and the verified configuration result is uploaded to the cloud server.