Two way authentication method based on internet of things and its system
Patent Information
- Authority / Receiving Office
- HK · HK
- Patent Type
- Patents
- Current Assignee / Owner
- CHINA UNIONPAY
- Filing Date
- 2023-11-13
- Publication Date
- 2026-07-17
AI Technical Summary
In existing technologies, vehicle and passenger identity authentication cannot effectively identify vehicles with counterfeit license plates and forged mobile phone numbers, resulting in inaccurate identity verification.
By adopting a two-way authentication method based on the Internet of Things (IoT), tag modules, IoT device identity authentication platforms, and management platforms are set up in vehicles and passenger terminals. By utilizing the correspondence between tag IDs and keys, verification codes are generated and decrypted to achieve dual authentication of vehicle and passenger identities.
It enables accurate authentication of vehicle and passenger identities, preventing the occurrence of cloned vehicles and forged identities, and improving the security and reliability of identity verification.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical Field
[0001] This invention relates to Internet of Things (IoT) technology, and more specifically to a two-way authentication method and system based on IoT. Background Technology
[0002] When using ride-hailing services, vehicle identification is generally required. Current technology primarily uses vehicle model and license plate number for this purpose. For example, after a passenger successfully books a ride, the platform sends the registered vehicle model and license plate number to the user. Upon arrival, the passenger confirms the vehicle's identity by observing the model and license plate. However, passenger identification typically only requires the passenger to state the last four digits of the passenger's mobile phone number.
[0003] The problem is that when identifying a vehicle by its model and license plate number, passengers cannot determine whether it is a cloned or counterfeit plate. Furthermore, when verifying a passenger's identity by providing the last four digits of their phone number, others can also provide the same last four digits, making it impossible to truly confirm the passenger's identity. Summary of the Invention
[0004] In view of the above problems, the present invention aims to propose an Internet of Things-based two-way authentication method and system that can perform dual authentication of the identities of two devices (e.g., vehicle identity and passenger identity).
[0005] The present invention discloses a two-way authentication method based on the Internet of Things (IoT), characterized in that the method is implemented through a tag module installed on a first device terminal, a second device terminal, a first device management platform, and an IoT device identity authentication platform. The tag module is pre-configured with a tag ID and a key corresponding to that tag ID. The IoT device identity authentication platform pre-configures a first correspondence between the tag ID and the key, and a second correspondence between the device ID and the device public key of the second device terminal. The method includes the following steps:
[0006] The tag module generates the first verification code based on the specified trigger action. The first verification code is encrypted using the key corresponding to the tag ID to generate the first verification code ciphertext.
[0007] The IoT device identity authentication platform decrypts the first verification code ciphertext using the corresponding key obtained from the first correspondence relationship to obtain the decrypted first verification code. The IoT device identity authentication platform also generates a second verification code. The decrypted first verification code and the second verification code are then encrypted using the key corresponding to the tag ID to generate the second verification code ciphertext.
[0008] The tag module decrypts the second verification code ciphertext using a key corresponding to the tag ID to obtain a decrypted first verification code and a second verification code. It then determines whether the decrypted first verification code matches the first verification code generated based on a predetermined trigger action, thereby authenticating the first device terminal.
[0009] The tag module sends the decrypted second verification code to the second device terminal. The second device terminal signs the second verification code using its device private key. The IoT device identity authentication platform obtains the device public key based on the second correspondence to verify the signature, thereby authenticating the identity of the second device terminal.
[0010] Optionally, the predetermined trigger action includes any one of the following:
[0011] The second device terminal scans the QR code provided by the tag module to establish a communication connection between the second device terminal and the tag module of the first device terminal;
[0012] The second device terminal approaches the tag module in a contactless manner to establish a communication connection between the second device terminal and the tag module of the first device terminal.
[0013] Optionally, the device private key of the second device terminal is stored in the TEE of the second device terminal.
[0014] Optionally, the first device terminal is a vehicle terminal, and the second device terminal is a passenger terminal.
[0015] The present invention discloses a two-way authentication method based on the Internet of Things (IoT), characterized in that the method is implemented on a tag module of a first device terminal, wherein the tag module is pre-configured with a tag ID and a key corresponding to the tag ID, and a first correspondence between the tag ID and the key, and a second correspondence between the device ID and the device public key of a second device terminal are pre-configured in an IoT device identity authentication platform. The method includes the following steps:
[0016] The first verification code is generated based on the specified trigger action. The first verification code is then encrypted using the key corresponding to the tag ID to generate the first verification code ciphertext.
[0017] The received second verification code ciphertext is decrypted using the key corresponding to the tag ID to obtain the decrypted first verification code and second verification code. It is then determined whether the decrypted first verification code matches the first verification code generated based on a specified trigger action, thereby authenticating the first device terminal. The second verification code ciphertext is obtained by the IoT device authentication platform from the first verification code ciphertext using the key obtained according to the first correspondence. The IoT device authentication platform also generates a second verification code. The decrypted first verification code and the second verification code are encrypted using the key corresponding to the tag ID to generate the second verification code ciphertext.
[0018] The decrypted second verification code is sent to the second device terminal, wherein the second device terminal signs the second verification code with its device private key, and the IoT device identity authentication platform obtains the device public key according to the second correspondence to verify the signature, so as to realize the identity authentication of the second device terminal.
[0019] Optionally, the predetermined trigger action includes any one of the following:
[0020] The second device terminal scans the QR code provided by the tag module to establish a communication connection between the second device terminal and the tag module of the first device terminal;
[0021] The second device terminal approaches the tag module in a contactless manner to establish a communication connection between the second device terminal and the tag module of the first device terminal.
[0022] This aspect discloses a two-way authentication method based on the Internet of Things (IoT), characterized in that the method is implemented in an IoT device identity authentication platform, wherein the tag module has a pre-set tag ID and a key corresponding to the tag ID, and the IoT device identity authentication platform has a pre-set first correspondence between the tag ID and the key and a second correspondence between the device ID and the device public key of the second device terminal, and the method includes the following steps:
[0023] The system receives a first ciphertext verification code, decrypts it using the corresponding key obtained from the first correspondence relationship to obtain a decrypted first verification code, and generates a second verification code. The decrypted first verification code and the second verification code are then encrypted using a key corresponding to the tag ID to generate a second ciphertext verification code. The first ciphertext verification code is generated by the tag module based on a specified trigger action, which encrypts the first verification code using a key corresponding to the tag ID.
[0024] The system receives a second verification code signed with the device's private key, and verifies the signature using the device's public key obtained according to the second correspondence relationship to achieve identity authentication for the second device terminal. Specifically, the tag module decrypts the encrypted second verification code using a key corresponding to the tag ID to obtain a decrypted first verification code and a second verification code. It then determines whether the decrypted first verification code matches the first verification code generated based on a specified trigger action to achieve identity authentication for the first device terminal. Furthermore, the tag module sends the decrypted second verification code to the second device terminal, and the second device terminal signs the second verification code using its device's private key.
[0025] The present invention discloses a two-way authentication system based on the Internet of Things (IoT), characterized in that it comprises: a tag module disposed on a first device terminal, a second device terminal, a first device management platform, and an IoT device identity authentication platform.
[0026] The tag module is pre-configured with a tag ID and a corresponding key. The IoT device authentication platform also pre-configures a first correspondence between the tag ID and the key, and a second correspondence between the device ID and the public key of the second device terminal.
[0027] The tag module generates a first verification code based on a predetermined trigger action. The first verification code is then encrypted using a key corresponding to the tag ID to generate ciphertext.
[0028] The IoT device authentication platform decrypts the first verification code ciphertext using the corresponding key obtained from the first correspondence relationship to obtain the decrypted first verification code. The platform then generates a second verification code. Finally, it encrypts the decrypted first and second verification codes using the key corresponding to the tag ID to generate the second verification code ciphertext.
[0029] The tag module decrypts the second verification code ciphertext using a key corresponding to the tag ID to obtain a decrypted first verification code and a second verification code. It then determines whether the decrypted first verification code matches the first verification code generated based on a specified trigger action to achieve identity authentication for the first device terminal.
[0030] The tag module sends the decrypted second verification code to the second device terminal. The second device terminal signs the second verification code using its device private key. The IoT device identity authentication platform obtains the device public key based on the second correspondence to verify the signature, thereby authenticating the identity of the second device terminal.
[0031] Optionally, the predetermined trigger action includes any one of the following:
[0032] The second device terminal scans the QR code provided by the tag module to establish a communication connection between the second device terminal and the tag module of the first device terminal;
[0033] The second device terminal approaches the tag module in a contactless manner to establish a communication connection between the second device terminal and the tag module of the first device terminal.
[0034] Optionally, the first device terminal is a vehicle terminal, and the second device terminal is a passenger terminal.
[0035] Optionally, the tag module includes:
[0036] The first storage module is pre-loaded with the tag ID of the tag module and the key corresponding to that tag ID;
[0037] The first verification code generation module generates the first verification code based on the specified trigger action;
[0038] The first encryption / decryption module encrypts the first verification code using a key corresponding to the tag ID to generate first verification code ciphertext, and decrypts the second verification code ciphertext using a key corresponding to the tag ID to obtain the decrypted first verification code and second verification code; and
[0039] The first authentication module determines whether the decrypted first verification code is consistent with the first verification code generated based on the specified trigger action, so as to realize the identity authentication of the first device terminal.
[0040] The first sending module sends the decrypted second verification code to the second device terminal.
[0041] Optionally, the IoT device identity authentication platform includes:
[0042] The second storage module pre-sets the first correspondence between the tag ID and the key of the tag module and the second correspondence between the device ID and the device public key of the second device terminal;
[0043] The second verification code generation module is used to generate the second verification code;
[0044] The second encryption / decryption module decrypts the first verification code ciphertext using the corresponding key obtained from the first correspondence relationship to obtain a decrypted first verification code. It then encrypts the decrypted first verification code and the second verification code using the key corresponding to the tag ID to generate a second verification code ciphertext.
[0045] The second authentication module obtains the device public key based on the second correspondence and performs signature verification to achieve identity authentication for the second device terminal.
[0046] Optionally, the second device terminal includes a TEE.
[0047] The TEE includes:
[0048] Storage module, used for storing the device's private key; and
[0049] The signature processing module uses the device's private key to sign the second verification code.
[0050] The label module of the present invention is characterized in that it comprises:
[0051] The first storage module is pre-loaded with the tag ID of the tag module and the key corresponding to that tag ID;
[0052] The first verification code generation module generates the first verification code based on the specified trigger action;
[0053] The first encryption / decryption module encrypts the first verification code using a key corresponding to the tag ID to generate first verification code ciphertext, and decrypts the second verification code ciphertext using a key corresponding to the tag ID to obtain the decrypted first verification code and second verification code; and
[0054] The first authentication module determines whether the decrypted first verification code matches the first verification code generated based on a specified trigger action, thereby authenticating the identity of the first device terminal; and
[0055] The first sending module sends the decrypted second verification code to the second device terminal.
[0056] The IoT device authentication platform of the present invention is characterized in that it includes:
[0057] The second storage module pre-sets the first correspondence between the tag ID and the key of the tag module and the second correspondence between the device ID and the device public key of the second device terminal;
[0058] The second verification code generation module is used to generate the second verification code;
[0059] The second encryption / decryption module decrypts the first verification code ciphertext using the corresponding key obtained from the first correspondence relationship to obtain a decrypted first verification code. It then encrypts the decrypted first verification code and the second verification code using the key corresponding to the tag ID to generate a second verification code ciphertext.
[0060] The second authentication module obtains the device public key based on the second correspondence and performs signature verification to achieve identity authentication for the second device terminal.
[0061] The computer-readable medium of the present invention stores a computer program thereon, characterized in that,
[0062] When the computer program is executed by the processor, it implements the IoT-based two-way authentication method.
[0063] The computer device of the present invention includes a storage module, a processor, and a computer program stored on the storage module and executable on the processor, characterized in that the processor implements the Internet of Things-based two-way authentication method when executing the computer program. Attached Figure Description
[0064] Figure 1 This is a summary flowchart illustrating the IoT-based two-way authentication method of the present invention.
[0065] Figure 2 This is a flowchart of a specific implementation of the IoT-based two-way authentication method of the present invention.
[0066] Figure 3 This is a structural block diagram illustrating the IoT-based two-way authentication system of the present invention. Detailed Implementation
[0067] The following are some embodiments of the present invention, intended to provide a basic understanding of the invention. They are not intended to identify key or decisive elements of the invention or to limit the scope of protection sought.
[0068] For purposes of brevity and illustrativeness, the principles of the invention are described herein primarily with reference to exemplary embodiments thereof. However, those skilled in the art will readily recognize that the same principles are equivalently applicable to all types of IoT-based two-way authentication methods and systems thereof, and that these same principles can be implemented therein, and that any such variations do not depart from the true spirit and scope of this patent application.
[0069] Furthermore, reference is made in the following description to the accompanying drawings, which illustrate specific exemplary embodiments. Electrical, mechanical, logical, and structural modifications may be made to these embodiments without departing from the spirit and scope of the invention. Moreover, while features of the invention are disclosed in conjunction with only one of several embodiments, this feature may be combined with one or more other features of other embodiments if desired and / or advantageous for any given or identifiable function. Therefore, the following description should not be considered limiting in any sense, and the scope of the invention is defined by the appended claims and their equivalents.
[0070] Terms such as “possessing” and “comprising” indicate that, in addition to having units (modules) and steps that are directly and explicitly stated in the specification and claims, the technical solution of the present invention does not exclude the presence of other units (modules) and steps that are not directly or explicitly stated.
[0071] Figure 1 This is a summary flowchart illustrating the IoT-based two-way authentication method of the present invention.
[0072] As an example of a two-way authentication method based on the Internet of Things (IoT), the following explanation will focus on authenticating vehicle and passenger identities. For instance, in this example, the two-way authentication method of the present invention is primarily implemented through a vehicle tag module (installed on the vehicle), a passenger terminal (e.g., a passenger's mobile phone), a vehicle management platform (e.g., a ride-hailing platform), and an IoT device identity authentication platform.
[0073] like Figure 1 As shown, the IoT-based two-way authentication method of the present invention mainly includes the following steps:
[0074] First verification code generation encryption step S100: The vehicle tag module is triggered to generate a first verification code based on the specified triggering conditions, and the first verification code is encrypted with the key preset in the vehicle tag module to generate the first verification code ciphertext. The vehicle tag module has a preset tag ID and a key corresponding to the ID. At the same time, the correspondence between the tag ID and the key is also pre-stored in the IoT device identity authentication platform. The passenger terminal forwards the first verification code ciphertext and the read tag ID to the IoT device identity authentication platform through the vehicle management platform.
[0075] First verification code decryption step S200: The IoT device identity authentication platform finds the corresponding key based on the tag ID according to the pre-stored correspondence between tag ID and key, and uses the key to decrypt the first verification code ciphertext to obtain the first verification code;
[0076] Second verification code generation encryption step S300: The IoT device identity authentication platform generates a second verification code, encrypts the second verification code with a key and the first verification code obtained from the first verification code decryption step S200, and obtains the second verification code ciphertext. The IoT device identity authentication platform forwards the tag ID and the second verification code ciphertext to the vehicle tag module through the vehicle management platform and passenger terminal.
[0077] Second verification code decryption step S400: After the vehicle tag module decrypts the second verification code ciphertext using the pre-stored key, it obtains the first verification code and the second verification code.
[0078] The authentication step based on the first verification code (i.e., the vehicle identity authentication step) S500: The vehicle tag module compares the first verification code decrypted in the second verification code decryption step S400 with the first verification code generated in the first verification code generation and encryption step S100. If they are the same, it means that the vehicle identity authentication is successful.
[0079] The authentication step based on the second verification code (i.e., the passenger identity authentication step) S600: The vehicle tag module sends the decrypted second verification code to the passenger terminal. The passenger terminal signs the second verification code using its device private key and forwards the signed second verification code and device ID to the IoT device identity authentication platform through the vehicle management platform. The IoT device identity authentication platform obtains the device public key pre-stored by the passenger terminal when binding to the IoT device identity authentication platform based on the device ID and the second verification code generated in the encryption step S300. It then verifies the signed second verification code. If the signature verification passes, the passenger identity authentication is successful.
[0080] Authentication result notification step S700: The IoT device identity authentication platform sends the verification result to the vehicle management platform, and the vehicle management platform notifies the driver of the vehicle of the verification result.
[0081] Next, a specific embodiment of the IoT-based two-way authentication method of the present invention will be described. In this embodiment, two-way authentication includes vehicle identity authentication and passenger identity authentication.
[0082] Figure 2 This is a flowchart of a specific implementation of the IoT-based two-way authentication method of the present invention.
[0083] like Figure 2 As shown, a specific embodiment of the IoT-based two-way authentication method of the present invention includes the following process:
[0084] Step S1: Based on the prescribed trigger action, the passenger terminal obtains the tag in the vehicle tag module and obtains the tag ID. For example, the prescribed trigger action can be scanning the QR code provided by the vehicle encrypted tag module, or using NFC to "touch" the tag in the vehicle tag module.
[0085] Step S2: The vehicle tag module is triggered to generate a first verification code, denoted as a, according to the specified trigger action. The first verification code a is encrypted with the key K preset in the vehicle tag module to generate the first verification code ciphertext, denoted as (a). The first verification code ciphertext (a) is sent to the passenger terminal. The vehicle tag module has a preset tag ID and a key K corresponding to the ID. At the same time, the correspondence between the tag ID and the key K is also pre-stored in the IoT device identity authentication platform. For example, when the vehicle tag module leaves the factory, the correspondence between the tag ID and the key K is stored in the IoT device identity authentication platform and the tag ID and the key K corresponding to the tag ID are written into the vehicle tag module.
[0086] Step S3: The passenger terminal sends the first verification code ciphertext (a) and the obtained tag ID to the ride-hailing platform;
[0087] Step S4: The ride-hailing platform forwards the first verification code ciphertext (a) and the obtained tag ID to the IoT device identity authentication platform;
[0088] Step S5: The IoT device identity authentication platform finds the corresponding key K based on the tag ID according to the pre-stored correspondence between tag ID and key K, and uses the key K to decrypt the first verification code ciphertext (a) to obtain the first verification code a'. Then, the IoT device identity authentication platform generates the second verification code b, and uses the key K to encrypt the first verification code a' and the second verification code b to obtain the second verification code ciphertext (a'+b). The tag ID and the second verification code ciphertext (a'+b) are forwarded to the passenger terminal through the ride-hailing platform.
[0089] Step S6: The passenger terminal sends the tag ID and the second verification code ciphertext (a'+b) to the vehicle encrypted tag;
[0090] Step S7: After the vehicle tag module decrypts the second verification code ciphertext (a'+b) using the pre-stored key K, it obtains the first verification code a' and the second verification code b. The vehicle tag module compares whether the decrypted first verification code a' is the same as the first verification code a generated in step 2. If they are the same, it means that the tag in the vehicle tag module has been verified, that is, the vehicle identity verification is completed. After that, the decrypted second verification code b is sent to the passenger terminal.
[0091] Step S8: The passenger terminal uses the device private key to sign the second verification code b, and obtains the signed second verification code B;
[0092] Step S9: The passenger terminal sends the signed second verification code B and the device ID to the ride-hailing platform. At the same time, the passenger terminal sends a ride confirmation notification to the ride-hailing platform. This ride confirmation notification is also sent from the passenger terminal to the ride-hailing platform to indicate that the vehicle tag verification has been completed. After that, the verification of the passenger terminal device will begin.
[0093] Step S10: The ride-hailing platform sends the signed second verification code B and the device ID to the IoT device identity authentication platform;
[0094] Step S11: The IoT device identity authentication platform obtains the device public key stored in advance when the passenger terminal is bound to the IoT device identity authentication platform based on the device ID and the second verification code b generated in step 5. The platform verifies the second verification code B after the device is signed. If the signature verification is successful, it means that the passenger identity authentication is successful.
[0095] Step S12: The IoT device identity authentication platform sends the verification result to the ride-hailing platform; and
[0096] Step S13: The ride-hailing platform confirms the trip and notifies the driver of the verification result.
[0097] Before steps S1 to S13 in the diagram, an initialization setting step is further included. Specifically, the initialization setting step includes:
[0098] The tag ID and the key K corresponding to the tag ID are pre-written into the vehicle tag module;
[0099] The mapping between tag IDs and keys K is pre-stored in the IoT device identity authentication platform; and
[0100] The mapping between device IDs and device public keys is pre-stored in the IoT device identity authentication platform; and
[0101] The passenger terminal has a pre-installed private key corresponding to the device public key (installed in the TEE of the passenger terminal).
[0102] As described above, according to the IoT-based vehicle and passenger identity authentication method of the present invention, after authenticating the vehicle, the ride-hailing platform issues a corresponding encrypted tag to the vehicle. During authentication, the vehicle's identity can be authenticated by authenticating the encrypted tag. On the other hand, for passenger identity authentication, the passenger terminal needs to support TEE. When a passenger registers with the ride-hailing platform, the ride-hailing platform account is bound to the passenger terminal device. Only when the passenger uses the bound device to use the ride-hailing service can the passenger identity authentication be passed as described above.
[0103] Figure 3This is a structural block diagram illustrating the IoT-based two-way authentication system of the present invention.
[0104] like Figure 3 As shown, the IoT-based two-way authentication system of the present invention includes: a tag module 100 set on a first device terminal, a second device terminal 200, a first device management platform 300, and an IoT device identity authentication platform 400.
[0105] The tag module 100 is pre-configured with a tag ID and a corresponding key. The IoT device authentication platform pre-configures a first correspondence between the tag ID and the key, and a second correspondence between the device ID and the public key of the second device terminal. The tag module 100 generates a first verification code based on a predetermined trigger action. This first verification code is then encrypted using the key corresponding to the tag ID to generate ciphertext. The tag module 100 forwards the generated ciphertext to the IoT device authentication platform 400 via the second device terminal 200 and the first device management platform 300.
[0106] The IoT device authentication platform 400 decrypts the first verification code ciphertext using the corresponding key obtained from the first correspondence relationship to obtain the decrypted first verification code. The IoT device authentication platform 400 then generates a second verification code. The decrypted first verification code and the second verification code are encrypted using the key corresponding to the tag ID to generate a second verification code ciphertext. The IoT device authentication platform 400 forwards the generated second verification code ciphertext to the tag module 100 through the first device management platform 300.
[0107] The tag module 100 decrypts the second verification code ciphertext using a key corresponding to the tag ID to obtain a decrypted first verification code and a second verification code. It then determines whether the decrypted first verification code is consistent with the first verification code generated based on a specified trigger action to achieve identity authentication for the first device terminal.
[0108] The tag module 100 sends the decrypted second verification code to the second device terminal 200. The second device terminal 200 signs the second verification code with its device private key. The IoT device identity authentication platform 400 obtains the device public key according to the second correspondence to verify the signature, so as to realize the identity authentication of the second device terminal.
[0109] As an example, the first device terminal is the vehicle terminal, and the second device terminal is the passenger terminal.
[0110] The label module 100 includes:
[0111] The first storage module 110 is pre-loaded with the tag ID of the tag module and the key corresponding to the tag ID;
[0112] The first verification code generation module 120 generates the first verification code based on the specified trigger action;
[0113] The first encryption / decryption module 130 encrypts the first verification code using a key corresponding to the tag ID to generate first verification code ciphertext, and decrypts the second verification code ciphertext using a key corresponding to the tag ID to obtain the decrypted first verification code and second verification code; and
[0114] The first authentication module 140 determines whether the decrypted first verification code is consistent with the first verification code generated based on the specified trigger action, so as to realize the identity authentication of the first device terminal.
[0115] The first sending module 150 sends the decrypted second verification code to the second device terminal.
[0116] The IoT device identity authentication platform 400 includes:
[0117] The second storage module 410 is configured with a first correspondence between the tag ID and the key of the tag module and a second correspondence between the device ID and the device public key of the second device terminal.
[0118] The second verification code generation module 420 is used to generate the second verification code;
[0119] The second encryption / decryption module 430 decrypts the first verification code ciphertext using the corresponding key obtained from the first correspondence relationship to obtain a decrypted first verification code; then, it encrypts the decrypted first verification code and the second verification code using the key corresponding to the tag ID to generate a second verification code ciphertext.
[0120] The second authentication module 440 obtains the device public key based on the second correspondence and performs signature verification to achieve identity authentication for the second device terminal.
[0121] The second device terminal 200 includes a TEE, wherein the TEE includes:
[0122] Storage module 210 is used for storing the private key of the storage device; and
[0123] The signature processing module 220 uses the device's private key to sign the second verification code.
[0124] By applying the IoT-based two-way authentication method and system of this invention in the scenario of using ride-hailing services, passengers only need to perform a single reading operation on the encrypted tag in the vehicle tag module set on the vehicle through the passenger terminal to achieve two-way authentication of vehicle identity and passenger identity.
[0125] The above examples primarily illustrate the IoT-based two-way authentication method and system of the present invention. Although only some specific embodiments of the invention have been described, those skilled in the art should understand that the invention can be implemented in many other forms without departing from its spirit and scope. Therefore, the examples and embodiments shown are to be considered illustrative rather than restrictive, and the invention may encompass various modifications and substitutions without departing from the spirit and scope of the invention as defined by the appended claims.
Claims
1. A two-way authentication method based on the Internet of Things, characterized in that, This method is implemented through a tag module set in a first device terminal, a second device terminal, a first device management platform, and an IoT device identity authentication platform. The tag module has a pre-set tag ID and a corresponding key. The IoT device identity authentication platform has a pre-set first correspondence between the tag ID and the key, and a second correspondence between the device ID and the device public key of the second device terminal. The method includes the following steps: The tag module generates the first verification code based on the specified trigger action. The first verification code is encrypted using the key corresponding to the tag ID to generate the first verification code ciphertext. The IoT device identity authentication platform decrypts the first verification code ciphertext using the corresponding key obtained from the first correspondence relationship to obtain the decrypted first verification code. The IoT device identity authentication platform also generates a second verification code. The decrypted first verification code and the second verification code are then encrypted using the key corresponding to the tag ID to generate the second verification code ciphertext. The tag module decrypts the second verification code ciphertext using a key corresponding to the tag ID to obtain a decrypted first verification code and a second verification code. It then determines whether the decrypted first verification code matches the first verification code generated based on a predetermined trigger action, thereby authenticating the first device terminal. The tag module sends the decrypted second verification code to the second device terminal. The second device terminal signs the second verification code using its device private key. The IoT device identity authentication platform obtains the device public key based on the second correspondence to verify the signature, thereby authenticating the identity of the second device terminal.
2. The two-way authentication method based on the Internet of Things as described in claim 1, characterized in that, The specified trigger action includes any one of the following: The second device terminal scans the QR code provided by the tag module to establish a communication connection between the second device terminal and the tag module of the first device terminal; The second device terminal approaches the tag module in a contactless manner to establish a communication connection between the second device terminal and the tag module of the first device terminal.
3. The two-way authentication method based on the Internet of Things as described in claim 1, characterized in that, The device private key of the second device terminal is stored in the TEE of the second device terminal.
4. The IoT-based two-way authentication method as described in claim 1, characterized in that, The first device terminal is a vehicle terminal, and the second device terminal is a passenger terminal.
5. A two-way authentication method based on the Internet of Things, characterized in that, The method is implemented on a tag module of a first device terminal, wherein the tag module is pre-configured with a tag ID and a key corresponding to the tag ID. A first correspondence between the tag ID and the key, and a second correspondence between the device ID and the device public key of a second device terminal are pre-configured in the IoT device authentication platform. The method includes the following steps: The first verification code is generated based on the specified trigger action. The first verification code is then encrypted using the key corresponding to the tag ID to generate the first verification code ciphertext. The received second verification code ciphertext is decrypted using the key corresponding to the tag ID to obtain the decrypted first verification code and second verification code. It is then determined whether the decrypted first verification code matches the first verification code generated based on a specified trigger action, thereby authenticating the first device terminal. The second verification code ciphertext is obtained by the IoT device authentication platform from the first verification code ciphertext using the key obtained according to the first correspondence. The IoT device authentication platform also generates a second verification code. The decrypted first verification code and the second verification code are encrypted using the key corresponding to the tag ID to generate the second verification code ciphertext. The decrypted second verification code is sent to the second device terminal, wherein the second device terminal signs the second verification code with its device private key, and the IoT device identity authentication platform obtains the device public key according to the second correspondence to verify the signature, so as to realize the identity authentication of the second device terminal.
6. The IoT-based two-way authentication method as described in claim 5, characterized in that, The specified trigger action includes any one of the following: The second device terminal scans the QR code provided by the tag module to establish a communication connection between the second device terminal and the tag module of the first device terminal; The second device terminal approaches the tag module in a contactless manner to establish a communication connection between the second device terminal and the tag module of the first device terminal.
7. A two-way authentication method based on the Internet of Things, characterized in that, This method is implemented in an IoT device identity authentication platform. The tag module has a pre-set tag ID and a corresponding key. The IoT device identity authentication platform also has a pre-set first correspondence between the tag ID and the key, and a second correspondence between the device ID and the device public key of the second device terminal. The method includes the following steps: The system receives a first ciphertext verification code, decrypts it using the corresponding key obtained from the first correspondence relationship to obtain a decrypted first verification code, and generates a second verification code. The decrypted first verification code and the second verification code are then encrypted using a key corresponding to the tag ID to generate a second ciphertext verification code. The first ciphertext verification code is generated by the tag module based on a specified trigger action, which encrypts the first verification code using a key corresponding to the tag ID. The system receives a second verification code signed with the device's private key, and verifies the signature using the device's public key obtained according to the second correspondence relationship to achieve identity authentication for the second device terminal. Specifically, the tag module decrypts the encrypted second verification code using a key corresponding to the tag ID to obtain a decrypted first verification code and a second verification code. It then determines whether the decrypted first verification code matches the first verification code generated based on a specified trigger action to achieve identity authentication for the first device terminal. Furthermore, the tag module sends the decrypted second verification code to the second device terminal, and the second device terminal signs the second verification code using its device's private key.
8. A two-way authentication system based on the Internet of Things, characterized in that, include: The tag module installed on the first device terminal, the second device terminal, the first device management platform, and the IoT device identity authentication platform. The tag module is pre-configured with a tag ID and a corresponding key. The IoT device authentication platform also pre-configures a first correspondence between the tag ID and the key, and a second correspondence between the device ID and the public key of the second device terminal. The tag module generates a first verification code based on a predetermined trigger action. The first verification code is then encrypted using a key corresponding to the tag ID to generate ciphertext. The IoT device identity authentication platform decrypts the first verification code ciphertext using the corresponding key obtained from the first correspondence relationship to obtain the decrypted first verification code. The platform then generates a second verification code. Finally, it encrypts the decrypted first and second verification codes using the key corresponding to the tag ID to generate the second verification code ciphertext. The tag module decrypts the second verification code ciphertext using a key corresponding to the tag ID to obtain a decrypted first verification code and a second verification code. It then determines whether the decrypted first verification code matches the first verification code generated based on a specified trigger action to achieve identity authentication for the first device terminal. The tag module sends the decrypted second verification code to the second device terminal. The second device terminal signs the second verification code using its device private key. The IoT device identity authentication platform obtains the device public key based on the second correspondence to verify the signature, thereby authenticating the identity of the second device terminal.
9. The IoT-based two-way authentication system as described in claim 8, characterized in that, The specified trigger action includes any one of the following: The second device terminal scans the QR code provided by the tag module to establish a communication connection between the second device terminal and the tag module of the first device terminal; The second device terminal approaches the tag module in a contactless manner to establish a communication connection between the second device terminal and the tag module of the first device terminal.
10. The IoT-based two-way authentication system as described in claim 8, characterized in that, The first device terminal is a vehicle terminal, and the second device terminal is a passenger terminal.
11. The IoT-based two-way authentication system as described in claim 8, characterized in that, The tag module includes: The first storage module is pre-loaded with the tag ID of the tag module and the key corresponding to that tag ID; The first verification code generation module generates the first verification code based on the specified trigger action; The first encryption / decryption module encrypts the first verification code using a key corresponding to the tag ID to generate first verification code ciphertext, and decrypts the second verification code ciphertext using a key corresponding to the tag ID to obtain the decrypted first verification code and second verification code; and The first authentication module determines whether the decrypted first verification code is consistent with the first verification code generated based on the specified trigger action, so as to realize the identity authentication of the first device terminal. The first sending module sends the decrypted second verification code to the second device terminal.
12. The IoT-based two-way authentication system as described in claim 11, characterized in that, The IoT device authentication platform includes: The second storage module pre-sets the first correspondence between the tag ID and the key of the tag module and the second correspondence between the device ID and the device public key of the second device terminal; The second verification code generation module is used to generate the second verification code; The second encryption / decryption module decrypts the first verification code ciphertext using the corresponding key obtained from the first correspondence relationship to obtain a decrypted first verification code. It then encrypts the decrypted first verification code and the second verification code using the key corresponding to the tag ID to generate a second verification code ciphertext. The second authentication module obtains the device public key based on the second correspondence and performs signature verification to achieve identity authentication for the second device terminal.
13. The IoT-based two-way authentication system as described in claim 12, characterized in that, The second device terminal includes a TEE. The TEE includes: Storage module, used for storing the device's private key; and The signature processing module uses the device's private key to sign the second verification code.
14. A label module, characterized in that, include: The first storage module is pre-loaded with the tag ID of the tag module and the key corresponding to that tag ID; The first verification code generation module generates the first verification code based on the specified trigger action; The first encryption and decryption module encrypts the first verification code using a key corresponding to the tag ID to generate the first verification code ciphertext, and decrypts the second verification code ciphertext using a key corresponding to the tag ID to obtain the decrypted first verification code and second verification code. as well as The first authentication module determines whether the decrypted first verification code is consistent with the first verification code generated based on the specified trigger action, so as to realize the identity authentication of the first device terminal. as well as The first sending module sends the decrypted second verification code to the second device terminal.
15. An Internet of Things (IoT) device identity authentication platform, characterized in that, include: The second storage module pre-sets the first correspondence between the tag ID and the key of the tag module and the second correspondence between the device ID and the device public key of the second device terminal; The second verification code generation module is used to generate the second verification code; The second encryption and decryption module obtains the corresponding key for the first verification code ciphertext according to the first correspondence relationship and decrypts it to obtain the decrypted first verification code. The decrypted first verification code and the second verification code are encrypted using the key corresponding to the tag ID to generate the second verification code ciphertext. as well as The second authentication module obtains the device public key based on the second correspondence and performs signature verification to achieve identity authentication for the second device terminal.
16. A computer-readable medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the IoT-based two-way authentication method as described in any one of claims 1 to 7.
17. A computer device comprising a storage module, a processor, and a computer program stored on the storage module and executable on the processor, characterized in that, When the processor executes the computer program, it implements the IoT-based two-way authentication method according to any one of claims 1 to 7.