Authentication method and apparatus, device, and storage medium
By adding operation certificates to the first function set of the Internet of Things system, the first type of credentials generated by the management node in the operation network solves the problem of overprivileged access between devices in the Internet of Things system and achieves secure business interaction.
Patent Information
- Application Number
- PCT/CN2023/135315
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-30
- Publication Date
- 2025-06-05
AI Technical Summary
In IoT technology, if two mobile phones are connected to the same car, both mobile phones have the administrator rights of the car, which can easily cause problems such as overprivileged access or illegal control of the car.
By adding operation certificates in the first function set, the management node generates the first type of credentials in the operating network, the second device can use the first type of credentials to establish a connection with the first device for business interaction without assigning administrator rights, ensuring that the second device does not have administrator rights and cannot access security credential resources.
The business interaction between the first device and the second device is realized, and the second device does not need to obtain administrator rights, effectively avoiding security issues such as overriding access, and ensuring the security of the first device.
Smart Images

Figure CN2023135315_05062025_PF_FP_ABST
Abstract
Description
Authentication method, device, equipment and storage medium Technical Field
[0001] The embodiments of the present application relate to the field of Internet of Things technology, and in particular to an authentication method, apparatus, device, and storage medium. Background Art
[0002] With the development of technology, the Internet of Things (IoT) is becoming increasingly popular and widely used in daily life. For example, the connection between a mobile phone and a car is common. However, in related technologies, if two mobile phones are connected to the same car, both phones have administrator privileges for the car, which can easily lead to unauthorized access or illegal control of the car.
[0003] Summary of the Invention
[0004] The present invention provides an authentication method, apparatus, device, and storage medium. The technical solution is as follows:
[0005] According to one aspect of an embodiment of the present application, an authentication method is provided, the method being performed by a first device, the method including:
[0006] An operation certificate is added to the first function set, where the first function set is used to manage the first type of credentials generated by the node in the operation network. The operation certificate is a credential for controlling the first device, and the first type of credential has the first operation permission of the first device.
[0007] According to one aspect of an embodiment of the present application, an authentication method is provided, the method being performed by a second device, the method including:
[0008] A first request is sent to a first device, where the first request is used to request the addition of an operation certificate in a first function set, where the first function set is used to manage a first type of credential generated by a node in an operating network, where the operation certificate is a credential for controlling the first device, and where the first type of credential has a first operation permission for the first device.
[0009] According to one aspect of an embodiment of the present application, an authentication method is provided, the method being executed by a client, the method comprising:
[0010] First configuration information is sent to a first device, where the first configuration information is used to instruct the first device to open a configuration window, where the configuration window is used to establish a session channel.
[0011] According to one aspect of an embodiment of the present application, an authentication device is provided, the device comprising:
[0012] A processing module is used to add an operation certificate to a first function set, where the first function set is used to manage a first type of credential generated by a node in an operating network, where the operation certificate is a credential for controlling a first device, and where the first type of credential has a first operation permission for the first device.
[0013] According to one aspect of an embodiment of the present application, an authentication device is provided, the device comprising:
[0014] A sending module is used to send a first request to a first device, where the first request is used to request the addition of an operation certificate in a first function set, where the first function set is used to manage a first type of credential generated by a node in an operating network, where the operation certificate is a credential for controlling the first device, and where the first type of credential has a first operation permission for the first device.
[0015] According to one aspect of an embodiment of the present application, an authentication device is provided, the device comprising:
[0016] The sending module is used to send first configuration information to the first device, where the first configuration information is used to instruct the first device to open a configuration window, and the configuration window is used to establish a session channel.
[0017] According to one aspect of an embodiment of the present application, a communication device is provided, the communication device including a processor and a memory, the memory storing a computer program, the processor executing the computer program to implement the above-mentioned authentication method. The communication device is a first device, or the communication device is a second device.
[0018] According to one aspect of an embodiment of the present application, a computer-readable storage medium is provided, in which a computer program is stored. The computer program is configured to be executed by a processor to implement the above-mentioned authentication method.
[0019] According to one aspect of an embodiment of the present application, a chip is provided, which includes a programmable logic circuit and / or program instructions, and when the chip is running, is used to implement the above-mentioned authentication method.
[0020] According to one aspect of an embodiment of the present application, a computer program product is provided, which includes computer instructions stored in a computer-readable storage medium. A processor reads and executes the computer instructions from the computer-readable storage medium to implement the above-mentioned authentication method.
[0021] The technical solutions provided by the embodiments of the present application may have the following beneficial effects:
[0022] By using the first functional set to manage the first type of credentials generated by nodes in the operating network, a second device can use the first type of credentials to establish a connection with the first device and subsequently perform business interactions. This allows business interactions between the first and second devices without assigning administrator privileges to the second device. A second device using the first type of credentials to establish a connection with the first device does not have administrator privileges on the first device and is not authorized to access the security credential resources of the first device, thus ensuring the security of the first device and effectively preventing security issues such as unauthorized access. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] FIG1 is a schematic diagram of a network architecture provided by an embodiment of the present application;
[0024] FIG2 is a flow chart of an authentication method provided by an embodiment of the present application;
[0025] FIG3 is a flow chart of an authentication method provided by another embodiment of the present application;
[0026] FIG4 is a flow chart of an authentication method provided by another embodiment of the present application;
[0027] FIG5 is a flowchart of an authentication method provided by another embodiment of the present application;
[0028] FIG6 is a flowchart of an authentication method provided by another embodiment of the present application;
[0029] FIG7 is a block diagram of an authentication device provided by an embodiment of the present application;
[0030] FIG8 is a block diagram of an authentication device provided by another embodiment of the present application;
[0031] FIG9 is a block diagram of an authentication device provided by another embodiment of the present application;
[0032] FIG10 is a schematic structural diagram of a first device provided by an embodiment of the present application;
[0033] FIG11 is a schematic structural diagram of a second device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0034] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0035] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. A person skilled in the art will appreciate that, with the evolution of the network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.
[0036] Please refer to Figure 1, which shows a schematic diagram of a network architecture provided by an embodiment of the present application. The network architecture may include: a core network 11, an access network 12, and a terminal device 13.
[0037] The core network 11 includes several core network devices. The functions of the core network devices are mainly to provide user connections, user management, and service carrying, and to provide an interface to the external network as a bearer network. For example, the core network of a 5G NR (New Radio) system may include devices such as an AMF (Access and Mobility Management Function) entity, a UPF (User Plane Function) entity, and an SMF (Session Management Function) entity.
[0038] The access network 12 includes several access network devices 14. The access network in the 5G NR system can be called NG-RAN (New Generation-Radio Access Network). The access network device 14 is a device deployed in the access network 12 to provide wireless communication functions for the terminal device 13. The access network device 14 may include various forms of macro base stations, micro base stations, relay stations, access points, etc. In systems using different wireless access technologies, the names of devices with access network device functions may be different. For example, in the 5G NR system, they are called gNodeB or gNB. With the evolution of communication technology, the name of "access network device" may change. For the convenience of description, in the embodiments of the present application, the above-mentioned devices that provide wireless communication functions for the terminal device 13 are collectively referred to as access network devices.
[0039] The number of terminal devices 13 is usually multiple, and one or more terminal devices 13 can be distributed in the cell managed by each access network device 14. The terminal device 13 may include various handheld devices with wireless communication functions, vehicle-mounted devices, wearable devices, computing devices or other processing devices connected to a wireless modem, as well as various forms of UE (User Equipment), mobile stations (MS), etc. For the convenience of description, the devices mentioned above are collectively referred to as terminal devices, that is, the terminal devices and UEs mentioned in the embodiments of the present application can be understood as having the same meaning. The access network device 14 and the core network device communicate with each other through some air technology, such as the NG interface in the 5G NR system. The access network device 14 and the terminal device 13 communicate with each other through some air technology, such as the Uu interface.
[0040] Terminal devices 13 and terminal devices 13 (for example, vehicle-mounted devices and other devices (such as other vehicle-mounted devices, mobile phones, RSU (Road Side Unit), etc.)) can communicate with each other through a direct communication interface (such as PC5 (ProSe Communication 5, neighbor communication fifth interface) interface). Accordingly, the communication link established based on the direct communication interface can be called a direct link or SL. SL transmission is the direct communication and data transmission between terminal devices through a side link. Unlike traditional cellular systems where communication data is received or sent through access network equipment, SL transmission has the characteristics of short delay and low overhead, and is suitable for communication between two terminal devices that are geographically close (such as vehicle-mounted devices and other peripheral devices that are geographically close). It should be noted that in Figure 1, only vehicle-to-vehicle communication in the V2X (vehicle to everything) scenario is used as an example. SL technology can be applied to scenarios where direct communication is carried out between various terminal devices. In other words, the terminal device in this application refers to any device that communicates using SL technology.
[0041] The "5G NR system" in the embodiments of this application may also be referred to as a 5G system or an NR system, but those skilled in the art will understand its meaning. The technical solutions described in the embodiments of this application can be applied to the 5G NR system and can also be applied to subsequent evolution systems of the 5G NR system.
[0042] Before introducing the technical solutions of this application, we first introduce and explain some of the background technologies involved in this application. The following related technologies can be combined with the technical solutions of the embodiments of this application as optional solutions, and they all fall within the scope of protection of the embodiments of this application. The embodiments of this application include at least some of the following contents.
[0043] 1. Open the configuration window for the second configurator
[0044] A purchased a smart lightbulb that's Matter (Project Connected Home over Internet Protocol) certified and supports both Bluetooth Low Energy (BLE) and Wi-Fi (Wireless Fidelity). A used the Home app on her phone to configure the new lightbulb in her living room. A few minutes later, she was able to control the lightbulb using the Home app. Her Home app functions as an Admin, Commissioner, and Controller.
[0045] B asks A to show him how to control his new lightbulb with his phone. A adds the Home app to B's phone as the lightbulb's secondary administrator and controller. Now, B can use his Home app to control the lightbulb and see its status. B's Home app can also now configure the device into his smart home.
[0046] 1. User A triggers the configuration mode on device B.
[0047] 2. Ecosystem App A generates a configuration password and its authenticator, a distinguishing code, and PAKE (Password-Authenticated Key Exchange) parameters.
[0048] 3. App A sends a configuration start instruction to device B, which carries the configuration parameters.
[0049] 4. After receiving the command, device B returns a response.
[0050] 5. Device B enters configuration discovery mode.
[0051] 6. Ecosystem App A shares the configuration information with Ecosystem App B through out-of-band methods such as email and voice.
[0052] 7. B Ecology APP turns on discovery mode.
[0053] 8. B ecosystem app discovers device B.
[0054] 9. B Ecosystem App and Device B establish a secure connection using the configuration password and other information.
[0055] 10.B Ecological APP certified device B.
[0056] 11. If B Eco has not been used in the home network, the B Eco APP creates a fabric ID (fabric identifier) for the home network.
[0057] 12. Device B uses the existing operation key.
[0058] 13. Device B sends a device certificate request CSR.B (Certificate Signing Request.B) to the B ecosystem app.
[0059] 14. The B ecosystem app sends CSR.B and fabricID to the B ecosystem CA (Certificate Authority) to request a device certificate.
[0060] 15. After B Eco CA authentication, the device certificate is generated and returned to the B Eco APP.
[0061] 16. B Ecosystem App configures the device certificate and access control permissions to device B.
[0062] 17. Configuration is complete.
[0063] The contents of the configuration parameters are shown in Table 1.
[0064] Table 1: Configuration parameters
[0065] 2. NOC Cluster
[0066] The attributes of the Node Operational Credentials Cluster (NOC Cluster) are shown in Table 2 below.
[0067] Table 2: Node Operation Credential Function Set
[0068] The Fabric description structure list is shown in Table 3 below.
[0069] Table 3: Fabric description structure list
[0070] vendor-id is the vendor ID defined in the standard. fabric-id is the fabric ID defined in the standard. node-id is the device node ID defined in the standard.
[0071] The commands included in the node operation credential function set are shown in Table 4 below.
[0072] Table 4: Commands included in the node operation credential function set
[0073] The A in the Accessibility column in Table 4 indicates that Admin privileges are required.
[0074] 3. ACL Cluster
[0075] Access control policies are contained in an ACL (Access Control List). An ACL is a list of ACEs (Access Control Entries).
[0076] The format of ACE is shown in Table 5 below.
[0077] Table 5: ACE
[0078] The meaning of "subject" is mainly to describe the source of the operation using the given authentication method provided by the secure channel architecture. The subject should be:
[0079] 1. An initiator node interacting via a PASE session during the commissioning phase, implicitly identified by the fact that the two peers in the PASE session have locally authenticated each other;
[0080] 2. The initiator node that interacts through the CASE session during the operation phase is identified using a distinguished name (e.g., node ID) in the operation certificate (NOC) shared during session establishment;
[0081] 3. Groups are initiator nodes that interact through message groups, identified by a group ID and verified by an operation group key.
[0082] The above-mentioned PASE, CASE, and GROUP are the supported authentication types.
[0083] The permission levels are shown in Table 6 below.
[0084] Table 6: Permission levels
[0085] In the above solution, after opening the configuration window, the second configurator (device B in step 1 above) has administrator privileges for the device (the lightbulb) and can freely access security credential resources, such as the NOC cluster. This approach is not suitable for temporary configuration scenarios, such as a passenger configuration and connection to a vehicle, as it can easily lead to security issues such as unauthorized access or illegal vehicle control. To address this, the present embodiment provides an authentication method that can be applied to temporary configuration scenarios.
[0086] Please refer to Figure 2, which shows a flow chart of an authentication method provided by an embodiment of the present application. The method is executed by a first device and may include the following step 210.
[0087] In step 210, the first device adds an operation certificate to the first function set. The first function set is used to manage the first type of credentials generated by the node in the operating network. The operation certificate is a credential for controlling the first device. The first type of credential has the first operation permission of the first device.
[0088] In some embodiments, the first type of credential is a temporary credential. A temporary credential is a credential used to request temporary operating permissions for the first device. If a second device uses the temporary credential to establish a connection with the first device, the second device can only access content disclosed by the first device using the temporary credential. The second device does not have access to the security credential resources of the first device, and the second device does not have administrator privileges on the first device.
[0089] In some embodiments, the first operation permission is a temporary operation permission. A device with the temporary operation permission can interact with the first device, but does not have administrator privileges on the first device and cannot access the NOC cluster of the first device. In other words, a device with the temporary operation permission does not have the right to modify, delete, add, or perform other operations on the security credential resources of the first device.
[0090] In some embodiments, the first function set is used to manage the first type of credentials generated by the node in the operating network. In some embodiments, the first function set can be called a temporary operational credential function set (Temporary Operational Credentials Cluster, TOC Cluster). Of course, the first function set can also have other names, which are not limited in the embodiments of the present application.
[0091] In some embodiments, the first device has both a first feature set and a second feature set.
[0092] In some embodiments, the second function set is used to manage a second type of credentials generated by the node in the operating network. In some embodiments, the second function set is a node operation credential function set.
[0093] In some embodiments, the second type of credential is a permanent credential. A permanent credential is a credential used to apply for permanent operating permissions on the first device. If a second device uses a permanent credential to establish a connection with the first device, the second device can freely access the security credential resources of the first device and has administrator privileges on the first device.
[0094] In some embodiments, the second operation permission is a permanent operation permission. A device with the permanent operation permission can perform business interactions with the first device and also has administrator privileges on the first device, allowing it to arbitrarily access security credential resources on the first device.
[0095] In some embodiments, this method can be applied to temporary configuration scenarios. For example, in the case of a passenger and a vehicle, the first device is the vehicle, and the second device is the passenger's mobile phone. In this scenario, the passenger only needs to connect to the vehicle for business interactions while on the vehicle; after disembarking, the connection is no longer necessary. To address this, a first-class credential can be assigned to the passenger's mobile phone. The passenger's mobile phone establishes a connection with the vehicle based on the first-class credential. The security credentials generated by the passenger's mobile phone and the vehicle in the operating network are stored in the first functional set. The passenger's mobile phone can interact with the vehicle but does not have access to the vehicle's NOC cluster. For the vehicle owner, for example, if the owner uses their mobile phone to control the vehicle, a second-class credential can be assigned to the passenger's mobile phone. The second-class credential is then used to establish a connection with the vehicle. The security credentials generated by the passenger's mobile phone and the vehicle in the operating network are stored in the second functional set. The passenger's mobile phone can interact with the vehicle and has unrestricted access to the vehicle's security credential resources.
[0096] In some embodiments, the first function set may have the same or similar structure as the second function set. In some embodiments, the attributes of the first function set are as shown in Table 7 below.
[0097] Table 7: Attributes of the first functional set
[0098] In some embodiments, the first function set includes a first field, and the first field is used to record the number of second session channels connected to the first device. In some embodiments, the second session channel is used for business interaction. For example, if the first device establishes a second session channel with the second device, the second session channel can be used to transmit business-related information between the first device and the second device. In some embodiments, the first field can be called SessionSurvived (survived session). Of course, the first field can also have other names, which are not limited in this application.
[0099] In some embodiments, the first field may be stored in any list of the first function set, which is not limited in this application. For example, the first field may be stored in a NOC structure list as shown in Table 7, or in a Fabric description structure list as shown in Table 7.
[0100] Taking the first field stored in the Fabric description structure list shown in Table 7 as an example, the Fabric description structure list of the first function set is shown in Table 8 below.
[0101] Table 8: Fabric description structure list of the first functional set
[0102] In some embodiments, the first field can be of type uint X, and the value of the first field represents the number of second session channels connected to the first device. For example, the first field can be of type uint8 as shown in Table 8, or it can be of type uint16, which is not limited in this application. In some embodiments, if all second session channels connected to the first device recorded in the first field have been disconnected, the value of the first field is 0; if any second session channels connected to the first device recorded in the first field are not disconnected, the value of the first field is the number of second session channels that remain connected to the first device.
[0103] In some embodiments, the first field may also be of type bool, and the value of the first field indicates whether a second session channel connected to the first device exists. For example, if the value of the first field is 0, it indicates "false", that is, no second session channel connected to the first device exists; if the value of the first field is 1, it indicates "true", that is, a second session channel connected to the first device exists.
[0104] In some embodiments, the commands included in the first function set may have the same or similar format as the commands included in the second function set. In some embodiments, the commands included in the first function set are shown in Table 9 below.
[0105] Table 9: Commands included in the first function set
[0106] In some embodiments, the Chinese and English names corresponding to the steps of temporary CSR request, temporary CSR response, adding operation certificate, operation certificate response, deleting temporary weaving network, etc. in Table 9 above are all exemplary names provided in the embodiments of the present application. They may have other names, and this application does not limit this.
[0107] In some embodiments, the O in the Accessibility column in Table 9 above indicates that the Operate permission is required.
[0108] The technical solution provided by the embodiments of the present application utilizes a first functional set to manage first-type credentials generated by nodes in an operating network. A second device can use the first-type credentials to establish a connection with the first device and subsequently perform business interaction. This allows business interaction between the first and second devices without assigning administrator privileges to the second device. The second device, which establishes a connection with the first device using the first-type credentials, does not have administrator privileges on the first device and is therefore not authorized to access the security credential resources of the first device. This ensures the security of the first device and effectively avoids security issues such as unauthorized access.
[0109] This application also provides an exemplary embodiment of a method for the second device to connect to the first device using the first type of credentials. Next, the technical solution provided by the embodiment of this application will be exemplified by the interaction between the first device, the second device and the client.
[0110] Please refer to Figure 3, which shows a flow chart of an authentication method provided by an embodiment of the present application. The method may include at least one of the following steps 210 to 330.
[0111] In step 220 , the first device receives first configuration information from the client. The first configuration information is used to instruct the first device to open a configuration window. The configuration window is used to establish a session channel.
[0112] Correspondingly, the client sends the first configuration information to the first device.
[0113] In some embodiments, the client is used to control the first device. In some embodiments, the client mentioned in the embodiments of the present application is a client used by an administrator of the first device, such as a client used by a car owner. In some embodiments, the client can be installed on the first device or on a third device, and a connection is established between the third device and the first device. In some embodiments, the third device is a computer device different from the first device and the second device.
[0114] In some embodiments, the first configuration information includes at least one of the following: a network configuration session timeout, a first identifier, a password verifier, a distinguishing code, an iteration parameter, a salt value, and a valid duration; wherein the first identifier is used to indicate the password of the first device, and the valid duration is the valid duration of the operation certificate of the second device.
[0115] In some embodiments, the network configuration session timeout refers to the time it takes for the first device to interact with the second device. In some embodiments, the first identifier may also be referred to as a password identifier. For example, a password ID is used as the first identifier. In some embodiments, a password verifier, a distinguishing code, an iteration parameter, and a salt value are parameters required for the first device to verify the password. In some embodiments, the validity period may also be referred to as a validity period, a survival period, etc. For example, the validity period may be referred to as a temporary credential survival period or a temporary credential validity period.
[0116] Exemplarily, the parameters included in the first configuration information are shown in Table 10 below.
[0117] Table 10: Parameters included in the first configuration information
[0118] In step 230 , the first device adds an ACE based on the first configuration information, where the ACE is used to manage access rights to the first function set; and opens a configuration window.
[0119] In some embodiments, the first device adds an ACE to the ACL. In some embodiments, the ACE is used to manage access rights for the first function set. Exemplarily, the ACE configures operator rights for the first function set.
[0120] For example, taking the first function set as the temporary operation credential function set and the first identifier as the password ID as an example, the format of ACE is as follows:
[0121] {
[0122] Privilege = operator,
[0123] AuthMode=PASE, Authorization Mode=PASE
[0124] Subjects = passcodeID, Subject = password ID
[0125] Targets = Temporary Operational Credentials Cluster Target = Temporary Operational Credentials Function Set
[0126] }
[0127] In some embodiments, the first device opens a configuration window and enters a configuration mode.
[0128] Step 240: The client sends second configuration information to the second device, where the second configuration information is used to configure authentication-related information for the second device.
[0129] Correspondingly, the second device receives the second configuration information from the client.
[0130] In some embodiments, the second configuration information includes at least one of the following: a password, a first identifier, a distinguishing code, an iteration parameter, and a salt value; wherein the first identifier is used to indicate the password of the first device.
[0131] In some embodiments, after receiving the second configuration information, the second device initiates device discovery and finds the first device based on the identifier.
[0132] Step 250: The second device sends a first message to the first device, where the first message includes a first identifier.
[0133] Accordingly, the first device receives the first message from the second device.
[0134] In step 260, the first device determines the validity of the first identifier based on the first identifier and the password verifier corresponding to the first identifier; if the first identifier is valid, a first session channel is established with the second device, and the first session channel is used to configure relevant information of the operating network.
[0135] In some embodiments, the first device establishes a first session channel with the second device after verifying that the password provided by the second device is correct.
[0136] In some embodiments, the first device and the second device establish a first session channel based on a password and a password verifier corresponding to the first identifier.
[0137] In some embodiments, the first session channel is a PASE secure channel.
[0138] In some embodiments, the first session channel is used for interaction between the first device and the second device in the configured network.
[0139] In some embodiments, the first session channel is used to transmit the first request, the second request, and the third request in the following embodiments.
[0140] In some embodiments, the second device can also verify the legitimacy of the first device based on the identification information of the first device. The identification information of the first device is used to uniquely identify the first device. For example, when a car leaves the factory, it is assigned a unique ID for the car, and the legitimacy information of the car can be queried based on the unique ID.
[0141] Step 270: The second device sends a third request to the first device, where the third request is used to request an operation certificate.
[0142] Correspondingly, the first device receives the third request sent by the second device.
[0143] In step 280 , the first device sends a third response to the second device, where the third response includes the operation certificate.
[0144] Correspondingly, the second device receives the third response sent by the first device.
[0145] In some embodiments, the third request is used to request the first device to allocate an operating certificate to the second device. In some embodiments, the third request is used to request the first device to allocate an operating certificate corresponding to the first type of credential to the second device. Exemplarily, the third request is a temporary CSR request, and the third response is a temporary CSR response. In some embodiments, the third request is used to request the first device to allocate an operating certificate corresponding to the second type of credential to the second device. Exemplarily, the third request is a CSR request, and the third response is a CSR response.
[0146] In some embodiments, the first device determines the credential corresponding to the operation certificate assigned to the second device based on the first identifier corresponding to the second device. In some embodiments, the third request is used to request the operation certificate, and the first device carries the corresponding operation certificate in the third response based on the first identifier corresponding to the second device. Exemplarily, the first identifier corresponding to the second device can obtain the operation certificate corresponding to the first type of credential, and the operation certificate carried in the third response is the operation certificate corresponding to the first type of credential. Exemplarily, the first identifier corresponding to the second device can obtain the operation certificate corresponding to the second type of credential, and the operation certificate carried in the third response is the operation certificate corresponding to the second type of credential.
[0147] In some embodiments, the third response may carry permissions corresponding to the operation certificate.
[0148] In some embodiments, the second device may execute the following step 290 or step 310 based on the authority corresponding to the operation certificate carried in the third response.
[0149] Step 290: The second device sends a first request to the first device, where the first request is used to receive the first request sent by the second device, and the first request is used to request to add an operation certificate to the first function set.
[0150] Correspondingly, the first device receives the first request sent by the second device.
[0151] In step 300 , the first device determines whether the second device has the first operation permission based on the first identifier; if the second device has the first operation permission, the first device sends a first response to the second device, where the first response indicates that the operation certificate has been successfully added to the first function set.
[0152] Correspondingly, the second device receives the first response sent by the first device.
[0153] In step 310, the second device sends a second request to the first device. The second request is used to request the addition of an operation certificate in the second function set. The second function set is used to manage the second type of credentials generated by the node in the operating network. The second type of credentials has the second operation permission of the first device.
[0154] Correspondingly, the first device receives the second request sent by the second device.
[0155] In step 320, the first device determines whether the second device has the second operation permission based on the first identifier; if the second device does not have the second operation permission, the first device sends a second response to the second device, where the second response indicates that adding the operation certificate to the second function set failed.
[0156] Correspondingly, the second device receives the second response sent by the first device.
[0157] In some embodiments, the third response may not carry the authority corresponding to the operation certificate.
[0158] In some embodiments, if the third response does not carry the authority corresponding to the operation certificate, the second device may perform both step 290 and step 310. The present application does not limit the execution order of step 290 and step 300.
[0159] In some embodiments, if the third response does not carry the authority corresponding to the operation certificate, the second device may first execute step 290. If the first response is received, step 310 is no longer executed; if the first response is not received, step 310 is executed.
[0160] In some embodiments, if the third response does not carry the authority corresponding to the operation certificate, the second device may first execute step 310, and if a second response is received, execute step 290; if no second response is received, step 310 is no longer executed.
[0161] In some embodiments, the second device may send only one request message to the first device, requesting the addition of the operation certificate. The first device determines whether to add the operation certificate to the first function set or the second function set based on the first identifier corresponding to the second device, and sends a response message to the second device, indicating that the operation certificate was successfully added to the first function set or the second function set.
[0162] When the first device determines that the second device has the first operation permission, step 210 is executed.
[0163] In step 210, the first device adds an operation certificate to the first function set. The first function set is used to manage the first type of credentials generated by the node in the operating network. The operation certificate is a credential for controlling the first device. The first type of credential has the first operation permission of the first device.
[0164] In some embodiments, after step 210 , step 330 is further included.
[0165] Step 330: The first device establishes a second session channel with the second device, where the second session channel is used for service interaction.
[0166] In some embodiments, the first function set includes a first field, and the first field is used to record the number of second session channels connected to the first device.
[0167] Through the above method, after the first device determines that the second device has the first operation permission based on the first identifier corresponding to the second device, it adds the operation certificate corresponding to the second device to the first function set, allowing the second device to obtain the operator permission of the first device and achieve control over the first device. This eliminates the need for the second device to obtain the administrator permission of the first device, effectively avoiding security issues such as unauthorized access.
[0168] In some embodiments, after the second device disconnects the second session channel from the first device, the first device may delete the operation credentials of the second device to reduce storage pressure on the first device.
[0169] 1. Deletion based on client instructions
[0170] Exemplarily, as shown in FIG4 , the method may further include at least one of the following steps 340 to 360 .
[0171] Step 340: The client displays a first field, where the first field is used to record the number of second session channels connected to the first device.
[0172] In some embodiments, the first user can view the number of second session channels connected to the first device recorded in the first field on the client. The first user refers to a user with administrator privileges on the first device, or a user logged into the client with a user account that has administrator privileges on the first device. If the number recorded in the first field is 0, or the first field does not record anything, the first user deletes the operation certificate. Of course, even if the number recorded in the first field is not 0, or the first field does record something, the first user can also choose to delete the operation certificate, and this application does not limit this.
[0173] In some embodiments, the first field may be obtained after the client sends a request message to the first device, or may be actively sent to the client by the first device.
[0174] In some embodiments, the client may send a fourth request to the first device, where the fourth request is for requesting the first field. The first device may send a fourth response to the client, where the fourth response includes the first field.
[0175] In some embodiments, the first device sends first information to the client, where the first information includes a first field.
[0176] In some embodiments, if the first user determines to delete the operation certificate recorded in the first device, the client executes step 350 described below.
[0177] In step 350, the client sends a second indication message to the first device. The second indication message is used to indicate the clearing of the operation certificate recorded in the first function set. The first function set is used to manage the first type of credentials generated by the node in the operating network. The operation certificate is a credential for controlling the first device. The first type of credential has the first operation permission of the first device.
[0178] Correspondingly, the first device receives the second indication information.
[0179] Step 360: The first device clears the operation certificate recorded in the first function set based on the second indication information.
[0180] In some embodiments, after receiving the second indication information, the first device deletes all operation certificates recorded in the first function set.
[0181] In some embodiments, the second indication information may indicate an operation certificate that needs to be deleted. The first device clears the operation certificate recorded in the first function set based on the operation certificate indicated in the second indication information.
[0182] In some embodiments, if a second session channel is still connected to the first device when the first device receives the second indication information, the first device may only clear the operation certificate corresponding to the second session channel that is disconnected from the first device to avoid affecting the second device that is still connected to the first device.
[0183] Through the above method, the first user can manage the operation certificate recorded in the first function set. After the second device corresponding to the operation certificate is disconnected from the first device, the operation certificate corresponding to the second device can be deleted to reduce the storage pressure of the first device.
[0184] 2. Deletion based on the instruction of the second device
[0185] In some embodiments, the second user can choose to disconnect from the first device and clear the operation certificate of the second device recorded in the first device. The second user refers to the user of the second device.
[0186] Exemplarily, as shown in FIG5 , the method further includes at least one of the following steps 370 to 380 .
[0187] In step 370 , the second device sends first indication information to the first device. The first indication information is used to instruct to disconnect the second session channel and clear the operation certificate corresponding to the second device.
[0188] In some embodiments, the second user can independently choose to disconnect from the first device and clear the operation certificate corresponding to the second device recorded in the first device after no longer needing to control the first device.
[0189] In step 380 , the first device disconnects the second session channel based on the first indication information and clears the operation certificate corresponding to the second device.
[0190] Through the above method, the second user can choose to clear the operation certificate of the second device recorded in the first function set of the first device, so as to avoid problems such as information leakage.
[0191] 3. Deletion based on effective duration
[0192] In some embodiments, when the first configuration information includes a valid duration, the first device may automatically clear the operation certificate recorded in the first function set based on the valid duration.
[0193] Exemplarily, as shown in FIG6 , the method may further include at least one of the following steps 390 to 400 .
[0194] Step 390: The first device stores the correspondence between the first identifier, the validity period, and the operation certificate.
[0195] In some embodiments, the validity period can be set for the first device. For example, a validity period is configured for the first device, and after the validity period expires, the first device automatically clears the operation certificate recorded in the first function set. For example, if the validity period is 14 days, the first device automatically clears the operation certificate recorded in the first function set every 14 days.
[0196] In some embodiments, the validity period can be specific to the first identifier or the operation certificate corresponding to the first identifier. For example, a validity period is configured for the first identifier, and after the validity period expires, the first device automatically clears the operation certificate associated with the first identifier. For example, if the validity period is 14 days, the first device automatically clears the operation certificate corresponding to the first identifier after 14 days.
[0197] In some embodiments, the valid durations corresponding to different first identifiers may be the same or different, and this application does not limit this.
[0198] In some embodiments, the effective duration may be set by the first user or pre-configured by the client, and this application does not limit this.
[0199] Step 400: The first device clears the operation certificate recorded in the first function set based on the validity period.
[0200] Through the above method, the first device can automatically clear the operation certificate recorded in the first function set based on the validity period without user operation, and can regularly clear the memory of the first device to reduce the storage pressure of the first device.
[0201] It should be noted that the execution order of the steps in the above embodiments is not limited in this application, and the step numbers do not limit the execution order of the steps.
[0202] In the above method embodiments, the technical solution of the present application is described only from the perspective of the interaction between the first device, the second device and the client. The above steps performed by the first device can be independently implemented as an authentication method on the first device side, the above steps performed by the second device can be independently implemented as an authentication method on the second device side, and the above steps performed by the client can be independently implemented as an authentication method on the client side. In addition, the embodiments provided in this article can be arbitrarily combined to form new embodiments, which are all within the scope of protection of this application.
[0203] The following are device embodiments of the present application, which can be used to implement the method embodiments of the present application. For details not disclosed in the device embodiments of the present application, please refer to the method embodiments of the present application.
[0204] Please refer to Figure 7, which shows a block diagram of an authentication device provided by one embodiment of the present application. This device has the functions of implementing the above-mentioned example authentication method. These functions can be implemented in hardware or by hardware executing corresponding software. This device can be the first device described above, or it can be provided in the first device. As shown in Figure 7, the device 700 may include: a processing module 710.
[0205] Processing module 710 is used to add an operation certificate to the first function set, where the first function set is used to manage the first type of credentials generated by the node in the operating network. The operation certificate is a credential for controlling the first device, and the first type of credential has the first operation permission of the first device.
[0206] In some embodiments, the apparatus further comprises: a receiving module;
[0207] The receiving module is configured to receive first configuration information from a client, where the first configuration information is used to instruct the first device to open a configuration window, where the configuration window is used to establish a session channel;
[0208] The processing module is further configured to add an access control list item ACE based on the first configuration information, where the ACE is used to manage access rights of the first function set;
[0209] The processing module is further configured to open the configuration window.
[0210] In some embodiments, the first configuration information includes at least one of the following: a network configuration session timeout, a first identifier, a password verifier, a distinguishing code, an iteration parameter, a salt value, and a valid duration; wherein the first identifier is used to indicate the password of the first device, and the valid duration is the valid duration of the operation certificate of the second device.
[0211] In some embodiments, the receiving module is further configured to receive a first message sent by a second device, where the first message includes a first identifier;
[0212] The processing module is further configured to determine the validity of the first identifier based on the first identifier and a password verifier corresponding to the first identifier;
[0213] The processing module is further configured to establish a first session channel with the second device when the first identifier is valid, where the first session channel is used to configure relevant information of the operating network.
[0214] In some embodiments, the receiving module is further configured to receive a first request sent by the second device, where the first request is configured to request that the operation certificate be added to the first function set;
[0215] The processing module is further configured to determine, based on the first identifier, whether the second device has the first operation permission;
[0216] The sending module is configured to send a first response to the second device if the second device has the first operation permission, where the first response is used to indicate that the operation certificate is successfully added to the first function set.
[0217] In some embodiments, the receiving module is further configured to receive a second request sent by the second device, the second request being configured to request the addition of the operation certificate to a second function set, the second function set being configured to manage a second type of credential generated by a node in an operating network, the second type of credential having a second operation permission of the first device;
[0218] The processing module is further configured to determine, based on the first identifier, whether the second device has a second operation permission;
[0219] The sending module is configured to send a second response to the second device if the second device does not have the second operation authority, where the second response is used to indicate that adding the operation certificate to the second function set fails.
[0220] In some embodiments, the receiving module is further configured to receive a third request sent by the second device, where the third request is used to request the operation certificate;
[0221] The sending module is further configured to send a third response to the second device, where the third response includes the operation certificate.
[0222] In some embodiments, the processing module is further configured to establish a second session channel with the second device, where the second session channel is used for business interaction.
[0223] In some embodiments, the first function set includes a first field, and the first field is used to record the number of second session channels connected to the first device.
[0224] In some embodiments, when the first configuration information includes the validity period, the processing module is further configured to clear the operation certificate recorded in the first function set based on the validity period.
[0225] In some embodiments, the first response includes the validity period.
[0226] In some embodiments, the processing module is further configured to store a correspondence between the first identifier, the validity period, and the operation certificate.
[0227] In some embodiments, the receiving module is further configured to receive first indication information sent by the second device, where the first indication information is used to instruct to disconnect the second session channel and clear the operation certificate corresponding to the second device;
[0228] The processing module is further configured to disconnect the second session channel and clear the operation certificate corresponding to the second device based on the first indication information.
[0229] In some embodiments, the receiving module is further configured to receive second instruction information from the client, where the second instruction information is configured to instruct the client to clear the operation certificate recorded in the first function set;
[0230] The processing module is further configured to clear the operation certificate recorded in the first function set based on the second indication information.
[0231] In some embodiments, the first type of credential is a temporary credential, and the first operation permission is a temporary operation permission.
[0232] The technical solution provided by the embodiments of the present application utilizes a first functional set to manage first-type credentials generated by nodes in an operating network. A second device can use the first-type credentials to establish a connection with the first device and subsequently perform business interaction. This allows business interaction between the first and second devices without assigning administrator privileges to the second device. The second device, which establishes a connection with the first device using the first-type credentials, does not have administrator privileges on the first device and is therefore not authorized to access the security credential resources of the first device. This ensures the security of the first device and effectively avoids security issues such as unauthorized access.
[0233] Please refer to Figure 8, which shows a block diagram of an authentication device provided by one embodiment of the present application. This device has the functionality to implement the aforementioned example authentication method. This functionality can be implemented in hardware or by hardware executing corresponding software implementations. This device can be the first device described above, or it can be provided within the first device. As shown in Figure 8, the device 800 may include a sending module 810.
[0234] Sending module 810 is used to send a first request to the first device, where the first request is used to request the addition of an operation certificate in a first function set, where the first function set is used to manage a first type of credential generated by a node in an operating network, where the operation certificate is a credential for controlling the first device, and where the first type of credential has a first operation permission for the first device.
[0235] In some embodiments, the apparatus further comprises:
[0236] The receiving module is configured to receive a first response sent by the first device, where the first response is used to indicate that the operation certificate is successfully added to the first function set.
[0237] In some embodiments, the first response includes a validity period, where the validity period is the validity period of the operating certificate of the second device.
[0238] In some embodiments, the receiving module is used to receive second configuration information from the client, where the second configuration information is used to configure authentication-related information for the second device.
[0239] In some embodiments, the second configuration information includes at least one of the following: a password, a first identifier, a distinguishing code, an iteration parameter, and a salt value; wherein the first identifier is used to indicate the password of the first device.
[0240] In some embodiments, the apparatus further comprises: a processing module;
[0241] The sending module is further configured to send a first message to the first device, where the first message includes a first identifier;
[0242] The processing module is configured to establish a first session channel with the first device when the first identifier is valid, where the first session channel is used to configure relevant information of the operating network.
[0243] In some embodiments, the sending module is further configured to send a second request to the first device, where the second request is configured to request that the operation certificate be added to a second function set, where the second function set is configured to manage a second type of credential generated by a node in an operating network, where the second type of credential has a second operation permission of the first device;
[0244] The receiving module is configured to receive a second response sent by the first device when the second device does not have the second operation authority, where the second response is used to indicate that adding the operation certificate to the second function set fails.
[0245] In some embodiments, the sending module is further configured to send a third request to the first device, wherein the third request is configured to request the operation certificate;
[0246] The receiving module is configured to receive a third response sent by the first device, where the third response includes the operation certificate.
[0247] In some embodiments, the sending module is further used to send first indication information to the first device, where the first indication information is used to instruct to disconnect the second session channel and clear the operation certificate corresponding to the second device, and the second session channel is used for business interaction.
[0248] In some embodiments, the first function set includes a first field, and the first field is used to record the number of second session channels connected to the first device.
[0249] In some embodiments, the first type of credential is a temporary credential, and the first operation permission is a temporary operation permission.
[0250] According to the technical solution provided by the embodiment of the present application, the second device can apply for the operator authority of the first device to temporarily control the first device without accessing the security credential resources of the first device, thereby effectively avoiding security issues such as unauthorized access.
[0251] Please refer to Figure 9, which shows a block diagram of an authentication device provided by one embodiment of the present application. This device has the functions of implementing the above-mentioned example authentication method. These functions can be implemented in hardware or by hardware executing corresponding software. This device can be the first device described above, or it can be provided in the first device. As shown in Figure 9, the device 900 may include: a sending module 910.
[0252] The sending module 910 is configured to send first configuration information to a first device, where the first configuration information is used to instruct the first device to open a configuration window, where the configuration window is used to establish a session channel.
[0253] In some embodiments, the first configuration information includes at least one of the following: a network configuration session timeout, a first identifier, a password verifier, a distinguishing code, an iteration parameter, a salt value, and a valid duration; wherein the first identifier is used to indicate the password of the first device, and the valid duration is the valid duration of the operation certificate of the second device.
[0254] In some embodiments, the sending module is further used to send second configuration information to the second device, where the second configuration information is used to configure authentication-related information for the second device.
[0255] In some embodiments, the second configuration information includes at least one of the following: a password, a first identifier, a distinguishing code, an iteration parameter, and a salt value; wherein the first identifier is used to indicate the password of the first device.
[0256] In some embodiments, the apparatus further comprises: a display module;
[0257] The display module is configured to display a first field, where the first field is configured to record the number of second session channels connected to the first device;
[0258] The sending module is also used to send a second indication message to the first device, and the second indication message is used to indicate the clearing of the operation certificate recorded in the first function set, the first function set is used to manage the first type of credentials generated by the node in the operating network, the operation certificate is a credential for controlling the first device, and the first type of credential has the first operation permission of the first device.
[0259] In some embodiments, the first type of credential is a temporary credential, and the first operation permission is a temporary operation permission.
[0260] The technical solution provided in the embodiment of the present application allows the user to control the first device based on the client, assign operator permissions to the second device, prevent the second device from accessing the security credential resources of the first device, and effectively avoid security issues such as unauthorized access.
[0261] It should be noted that the device provided in the above embodiment only uses the division of the above-mentioned functional modules as an example to implement its functions. In actual applications, the above-mentioned functions can be assigned to different functional modules according to actual needs, that is, the content structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0262] Regarding the apparatus in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.
[0263] Please refer to Figure 10, which shows a schematic diagram of the structure of a first device provided in one embodiment of the present application. The first device 1000 may include: a processor 1001, a transceiver 1002, and a memory 1003. The transceiver 1002 is used to implement transmission and / or reception functions, and the processor 1001 may be used to implement other processing functions or control transmission and / or reception, such as implementing the functions of the processing module 710 described above.
[0264] The processor 1001 includes one or more processing cores. The processor 1001 executes various functional applications and information processing by running software programs and modules.
[0265] The transceiver 1002 may include a receiver and a transmitter. For example, the receiver and the transmitter may be implemented as the same wireless communication component, which may include a wireless communication chip and a radio frequency antenna.
[0266] The memory 1003 may be connected to the processor 1001 and the transceiver 1002 .
[0267] The memory 1003 may be used to store a computer program executed by the processor, and the processor 1001 may be used to execute the computer program to implement the various steps in the above-mentioned method embodiment on the first device side.
[0268] In some embodiments, the processor 1001 is used to add an operation certificate in a first function set, where the first function set is used to manage a first type of credential generated by a node in an operating network, where the operation certificate is a credential for controlling the first device, and the first type of credential has a first operation permission for the first device.
[0269] For details not described in detail in this embodiment, please refer to the above embodiments and will not be described in detail here.
[0270] In addition, the memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof, including but not limited to: magnetic or optical disks, electrically erasable programmable read-only memory, erasable programmable read-only memory, static access memory, read-only memory, magnetic memory, flash memory, and programmable read-only memory.
[0271] Please refer to Figure 11, which shows a schematic diagram of the structure of a second device provided in one embodiment of the present application. The second device 1100 may include: a processor 1101, a transceiver 1102, and a memory 1103. The transceiver 1102 is used to implement the functions of the sending module 810 described above.
[0272] The processor 1101 includes one or more processing cores, and executes various functional applications and information processing by running software programs and modules. The processor 1101 is used to execute the other steps except the sending and receiving steps executed by the second device in the above method embodiment.
[0273] Transceiver 1102 may include a receiver and a transmitter. For example, the receiver and transmitter may be implemented as the same wireless communication component, which may include a wireless communication chip and a radio frequency antenna. Transceiver 1102 is configured to perform the sending and / or receiving steps performed by the first device in the above method embodiment.
[0274] The memory 1103 may be connected to the processor 1101 and the transceiver 1102 .
[0275] The memory 1103 may be used to store a computer program executed by the processor, and the processor 1101 may be used to execute the computer program to implement the various steps in the above-mentioned method embodiment on the second device side.
[0276] In addition, the memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof, including but not limited to: magnetic or optical disks, electrically erasable programmable read-only memory, erasable programmable read-only memory, static access memory, read-only memory, magnetic memory, flash memory, and programmable read-only memory.
[0277] In some embodiments, the transceiver 1102 is used to send a first request to a first device, where the first request is used to request the addition of an operation certificate in a first function set, where the first function set is used to manage a first type of credential generated by a node in an operating network, where the operation certificate is a credential for controlling the first device, and where the first type of credential has a first operating permission for the first device.
[0278] For details not described in detail in this embodiment, please refer to the above embodiments and will not be described in detail here.
[0279] An embodiment of the present application also provides a computer-readable storage medium, in which a computer program is stored, and the computer program is used to be executed by a processor to implement the above-mentioned authentication method on the first device side, or to implement the above-mentioned authentication method on the second device side. In some embodiments, the computer-readable storage medium may include: ROM (Read-Only Memory), RAM (Random-Access Memory), SSD (Solid State Drives) or optical disks, etc. Among them, random access memory may include ReRAM (Resistance Random Access Memory) and DRAM (Dynamic Random Access Memory).
[0280] An embodiment of the present application also provides a chip, which includes a programmable logic circuit and / or program instructions. When the chip is running, it is used to implement the above-mentioned authentication method on the first device side, or to implement the above-mentioned authentication method on the second device side.
[0281] An embodiment of the present application also provides a computer program product, which includes a computer program, wherein the computer program is stored in a computer-readable storage medium, and a processor reads and executes the computer program from the computer-readable storage medium to implement the above-mentioned authentication method on the first device side, or implement the above-mentioned authentication method on the second device side.
[0282] It should be understood that the "indication" mentioned in the embodiments of this application can be a direct indication, an indirect indication, or an indication of an association. For example, "A indicates B" can mean that A directly indicates B, for example, B can be obtained through A; it can also mean that A indirectly indicates B, for example, A indicates C, and B can be obtained through C; it can also mean that A and B are associated with each other.
[0283] In the description of the embodiments of the present application, the term "corresponding" may indicate a direct or indirect correspondence between the two, or an association relationship between the two, or a relationship between indication and being indicated, configuration and being configured, etc.
[0284] In some embodiments of the present application, "predefined" may be implemented by pre-storing corresponding codes, tables, or other methods that can be used to indicate relevant information in devices (e.g., including the first device and the second device). The present application does not limit the specific implementation method. For example, predefined may refer to those defined in the protocol.
[0285] In some embodiments of the present application, the "protocol" may refer to a standard protocol in the field of communications, for example, it may include an LTE protocol, a NR protocol, and related protocols used in future communication systems, and this application does not limit this.
[0286] In this document, "plurality" refers to two or more. "And / or" describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, or B exists alone. The character " / " generally indicates an "or" relationship between the associated objects.
[0287] The term “greater than or equal to” mentioned herein may mean greater than or equal to, or greater than, and the term “less than or equal to” may mean less than or equal to, or less than.
[0288] In addition, the step numbers described in this document only illustrate a possible execution order between the steps. In some other embodiments, the above steps may not be executed in the order of the numbers, such as two steps with different numbers are executed at the same time, or two steps with different numbers are executed in the opposite order of the diagram. The embodiments of the present application are not limited to this.
[0289] Those skilled in the art will appreciate that in one or more of the above examples, the functions described in the embodiments of the present application can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any media that facilitates the transmission of computer programs from one place to another. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0290] The above description is merely an exemplary embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. An authentication method, It is characterized in that The method is performed by a first device, and includes: An operation certificate is added to the first function set, where the first function set is used to manage the first type of credentials generated by the node in the operating network, the operation certificate is a credential for controlling the first device, and the first type of credential has the first operation permission for the first device.
2. The method according to claim 1, It is characterized in that The method further comprises: Receiving first configuration information from a client, where the first configuration information is used to instruct the first device to open a configuration window, where the configuration window is used to establish a session channel; Adding an access control list item ACE based on the first configuration information, where the ACE is used to manage access rights of the first function set; The configuration window is opened.
3. The method according to claim 2, It is characterized in that The first configuration information includes at least one of the following: a network configuration session timeout, a first identifier, a password verifier, a distinguishing code, an iteration parameter, a salt value, and a valid duration; wherein the first identifier is used to indicate the password of the first device, and the valid duration is the valid duration of the operation certificate of the second device.
4. The method according to claim 2 or 3, It is characterized in that The method further comprises: receiving a first message sent by a second device, where the first message includes a first identifier; Determining the validity of the first identifier based on the first identifier and a password verifier corresponding to the first identifier; When the first identifier is valid, a first session channel is established with the second device, where the first session channel is used to configure relevant information of the operating network.
5. The method according to claim 4, It is characterized in that The method further comprises: receiving a first request sent by the second device, where the first request is used to request to add the operation certificate to the first function set; Based on the first identifier, determining whether the second device has the first operation authority; In a case where the second device has the first operation authority, a first response is sent to the second device, where the first response is used to indicate that the operation certificate is successfully added to the first function set.
6. The method according to claim 4 or 5, It is characterized in that The method further comprises: receiving a second request sent by the second device, the second request being used to request adding the operation certificate to a second function set, the second function set being used to manage a second type of credential generated by a node in an operation network, the second type of credential having a second operation permission of the first device; Based on the first identifier, determining whether the second device has a second operation authority; In a case where the second device does not have the second operation authority, a second response is sent to the second device, where the second response is used to indicate that adding the operation certificate to the second function set fails.
7. The method according to claim 5 or 6, It is characterized in that The method further comprises: receiving a third request sent by the second device, where the third request is used to request the operation certificate; A third response is sent to the second device, the third response including the operational certificate.
8. The method according to claim 5, It is characterized in that The method further comprises: A second session channel is established with the second device, where the second session channel is used for service interaction.
9. The method according to claim 8, It is characterized in that The first function set includes a first field, where the first field is used to record the number of second session channels connected to the first device.
10. The method according to any one of claims 3 to 9, It is characterized in that In the case where the first configuration information includes the effective duration, the method further includes: Based on the validity period, the operation certificate recorded in the first function set is cleared.
11. The method according to any one of claims 5 to 10, It is characterized in that The first response includes the validity period.
12. The method according to any one of claims 3 to 11, It is characterized in that The method further comprises: The correspondence between the first identifier, the validity period and the operation certificate is stored.
13. The method according to claim 8, It is characterized in that The method further comprises: receiving first indication information sent by the second device, where the first indication information is used to instruct to disconnect the second session channel and clear the operation certificate corresponding to the second device; Based on the first indication information, the second session channel is disconnected, and the operation certificate corresponding to the second device is cleared.
14. The method according to any one of claims 1 to 13, It is characterized in that The method further comprises: receiving second indication information from the client, where the second indication information is used to instruct to clear the operation certificate recorded in the first function set; Based on the second indication information, clear the operation certificate recorded in the first function set.
15. The method according to any one of claims 1 to 14, It is characterized in that The first type of credential is a temporary credential, and the first operation authority is a temporary operation authority.
16. An authentication method, It is characterized in that The method is performed by a second device, and includes: A first request is sent to a first device, where the first request is used to request to add an operation certificate to a first function set, where the first function set is used to manage a first type of credential generated by a node in an operating network, where the operation certificate is a credential for controlling the first device, and where the first type of credential has a first operation permission for the first device.
17. The method according to claim 16, It is characterized in that The method further comprises: A first response sent by the first device is received, where the first response is used to indicate that the operation certificate is successfully added to the first function set.
18. The method according to claim 17, It is characterized in that The first response includes a validity period, where the validity period is the validity period of the operation certificate of the second device.
19. The method according to any one of claims 16 to 18, It is characterized in that The method further comprises: Second configuration information is received from the client, where the second configuration information is used to configure authentication-related information for the second device.
20. The method according to claim 19, It is characterized in that The second configuration information includes at least one of the following: a password, a first identifier, a distinguishing code, an iteration parameter, and a salt value; wherein the first identifier is used to indicate the password of the first device.
21. The method according to claim 19 or 20, It is characterized in that The method further comprises: Sending a first message to the first device, where the first message includes a first identifier; When the first identifier is valid, a first session channel is established with the first device, where the first session channel is used to configure relevant information of the operating network.
22. The method according to any one of claims 16 to 21, It is characterized in that The method further comprises: Sending a second request to the first device, where the second request is used to request adding the operation certificate to a second function set, where the second function set is used to manage a second type of credentials generated by a node in an operating network, where the second type of credentials has a second operation permission of the first device; In a case where the second device does not have the second operation authority, a second response sent by the first device is received, where the second response is used to indicate that adding the operation certificate to the second function set fails.
23. The method according to any one of claims 16 to 22, It is characterized in that The method further comprises: Sending a third request to the first device, where the third request is used to request the operation certificate; A third response sent by the first device is received, where the third response includes the operation certificate.
24. The method according to any one of claims 16 to 23, It is characterized in that The method further comprises: Sending first indication information to the first device, where the first indication information is used to instruct to disconnect a second session channel and clear an operation certificate corresponding to the second device, where the second session channel is used for service interaction.
25. The method according to claim 24, It is characterized in that The first function set includes a first field, where the first field is used to record the number of second session channels connected to the first device.
26. The method according to any one of claims 16 to 25, It is characterized in that The first type of credential is a temporary credential, and the first operation authority is a temporary operation authority.
27. An authentication method, It is characterized in that The method is executed by a client, and includes: First configuration information is sent to a first device, where the first configuration information is used to instruct the first device to open a configuration window, where the configuration window is used to establish a session channel.
28. The method according to claim 27, It is characterized in that The first configuration information includes at least one of the following: a network configuration session timeout, a first identifier, a password verifier, a distinguishing code, an iteration parameter, a salt value, and a valid duration; wherein the first identifier is used to indicate the password of the first device, and the valid duration is the valid duration of the operation certificate of the second device.
29. The method according to claim 27 or 28, It is characterized in that The method further comprises: Send second configuration information to the second device, where the second configuration information is used to configure authentication-related information for the second device.
30. The method according to claim 29, It is characterized in that The second configuration information includes at least one of the following: a password, a first identifier, a distinguishing code, an iteration parameter, and a salt value; wherein the first identifier is used to indicate the password of the first device.
31. The method according to any one of claims 27 to 30, It is characterized in that The method further comprises: displaying a first field, where the first field is used to record the number of second session channels connected to the first device; Sending second indication information to the first device, the second indication information is used to instruct to clear the operation certificate recorded in the first function set, the first function set is used to manage the first type of credentials generated by the node in the operation network, and the operation certificate is used to control the first device The first type of credential has a first operation permission for the first device.
32. The method according to claim 31, It is characterized in that The first type of credential is a temporary credential, and the first operation authority is a temporary operation authority.
33. An authentication device, It is characterized in that The device comprises: A processing module is used to add an operation certificate to a first function set, wherein the first function set is used to manage a first type of credential generated by a node in an operating network, wherein the operation certificate is a credential for controlling a first device, and the first type of credential has a first operation permission for the first device.
34. The device according to claim 33, It is characterized in that The device further comprises: a receiving module; The receiving module is used to receive first configuration information from a client, where the first configuration information is used to instruct the first device to open a configuration window, where the configuration window is used to establish a session channel; The processing module is further used to add an access control list item ACE based on the first configuration information, wherein the ACE is used to manage access rights of the first function set; The processing module is further used to open the configuration window.
35. The device according to claim 34, It is characterized in that The first configuration information includes at least one of the following: a network configuration session timeout, a first identifier, a password verifier, a distinguishing code, an iteration parameter, a salt value, and a valid duration; wherein the first identifier is used to indicate the password of the first device, and the valid duration is the valid duration of the operation certificate of the second device.
36. The device according to claim 34 or 35, It is characterized in that The receiving module is further configured to receive a first message sent by a second device, where the first message includes a first identifier; The processing module is further configured to determine the validity of the first identifier based on the first identifier and a password verifier corresponding to the first identifier; The processing module is further configured to establish a first session channel with the second device when the first identifier is valid, wherein the first session channel is used to configure relevant information of the operating network.
37. The device according to claim 36, It is characterized in that The receiving module is further configured to receive a first request sent by the second device, where the first request is used to request to add the operation certificate to the first function set; The processing module is further used to determine whether the second device has the first operation authority based on the first identifier; The device also includes: a sending module; The sending module is used to send a first response to the second device when the second device has the first operation authority, wherein the first response is used to indicate that the operation certificate is successfully added to the first function set.
38. The device according to claim 36 or 37, It is characterized in that The receiving module is further used to receive a second request sent by the second device, the second request is used to request to add the operation certificate in a second function set, the second function set is used to manage a second type of credentials generated by the node in the operation network, and the second type of credentials has a second operation permission of the first device; The processing module is further used to determine whether the second device has a second operation authority based on the first identifier; The device also includes: a sending module; The sending module is used to send a second response to the second device when the second device does not have the second operation authority, wherein the second response is used to indicate that adding the operation certificate to the second function set fails.
39. The device according to claim 37 or 38, It is characterized in that The receiving module is further configured to receive a third request sent by the second device, where the third request is used to request the operation certificate; The sending module is further configured to send a third response to the second device, where the third response includes the operation certificate.
40. The device according to claim 37, It is characterized in that The processing module is further used to establish a second session channel with the second device, where the second session channel is used for business interaction.
41. The device according to claim 40, It is characterized in that The first function set includes a first field, where the first field is used to record the number of second session channels connected to the first device.
42. The device according to any one of claims 35 to 41, It is characterized in that In the case where the first configuration information includes the validity period, the processing module is further configured to clear the operation certificate recorded in the first function set based on the validity period.
43. The device according to any one of claims 37 to 42, It is characterized in that The first response includes the validity period.
44. The device according to any one of claims 35 to 43, It is characterized in that The processing module is further used to store the corresponding relationship between the first identifier, the validity period and the operation certificate.
45. The device according to claim 40, It is characterized in that The receiving module is further used to receive first indication information sent by the second device, where the first indication information is used to instruct to disconnect the second session channel and clear the operation certificate corresponding to the second device; The processing module is further configured to disconnect the second session channel and clear the operation certificate corresponding to the second device based on the first indication information.
46. The device according to any one of claims 33 to 45, It is characterized in that The receiving module is further used to receive second indication information from the client, where the second indication information is used to instruct to clear the operation certificate recorded in the first function set; The processing module is further configured to clear the operation certificate recorded in the first function set based on the second indication information.
47. The device according to any one of claims 33 to 46, It is characterized in that The first type of credential is a temporary credential, and the first operation authority is a temporary operation authority.
48. An authentication device, It is characterized in that The device comprises: A sending module is used to send a first request to a first device, wherein the first request is used to request to add an operation certificate in a first function set, the first function set is used to manage a first type of credential generated by a node in an operating network, the operation certificate is a credential for controlling the first device, and the first type of credential has a first operation permission for the first device.
49. The device according to claim 48, It is characterized in that The device also includes: The receiving module is used to receive a first response sent by the first device, where the first response is used to indicate that the operation certificate is successfully added to the first function set.
50. The device according to claim 49, It is characterized in that The first response includes a validity period, where the validity period is the validity period of the operation certificate of the second device.
51. The device according to any one of claims 48 to 50, It is characterized in that The device also includes: The receiving module is used to receive second configuration information from the client, where the second configuration information is used to configure authentication-related information for the second device.
52. The device according to claim 51, It is characterized in that The second configuration information includes at least one of the following: a password, a first identifier, a distinguishing code, an iteration parameter, and a salt value; wherein the first identifier is used to indicate the password of the first device.
53. The device according to claim 51 or 52, It is characterized in that The device further comprises: a processing module; The sending module is further configured to send a first message to the first device, where the first message includes a first identifier; The processing module is used to establish a first session channel with the first device when the first identifier is valid, and the first session channel is used to configure relevant information of the operating network.
54. The device according to any one of claims 48 to 53, It is characterized in that The device further comprises: a receiving module; The sending module is further used to send a second request to the first device, where the second request is used to request to add the operation certificate in a second function set, where the second function set is used to manage a second type of credentials generated by a node in an operating network, where the second type of credentials has a second operation permission of the first device; The receiving module is used to receive a second response sent by the first device when the second device does not have the second operation authority, and the second response is used to indicate that adding the operation certificate to the second function set fails.
55. The device according to any one of claims 48 to 54, It is characterized in that The device further comprises: a receiving module; The sending module is further used to send a third request to the first device, where the third request is used to request the operation certificate; The receiving module is configured to receive a third response sent by the first device, where the third response includes the operation certificate.
56. The device according to any one of claims 48 to 55, It is characterized in that The sending module is further used to send first indication information to the first device, where the first indication information is used to instruct to disconnect the second session channel and clear the operation certificate corresponding to the second device, and the second session channel is used for business interaction.
57. The device according to claim 56, It is characterized in that The first function set includes a first field, where the first field is used to record the number of second session channels connected to the first device.
58. The device according to any one of claims 48 to 57, It is characterized in that The first type of credential is a temporary credential, and the first operation authority is a temporary operation authority.
59. An authentication device, It is characterized in that The device comprises: The sending module is used to send first configuration information to the first device, where the first configuration information is used to instruct the first device to open a configuration window, and the configuration window is used to establish a session channel.
60. The device according to claim 59, It is characterized in that The first configuration information includes at least one of the following: a network configuration session timeout, a first identifier, a password verifier, a distinguishing code, an iteration parameter, a salt value, and a valid duration; wherein the first identifier is used to indicate the password of the first device, and the valid duration is the valid duration of the operation certificate of the second device.
61. The device according to claim 59 or 60, It is characterized in that The sending module is further used to send second configuration information to the second device, where the second configuration information is used to configure authentication-related information for the second device.
62. The device according to claim 61, It is characterized in that The second configuration information includes at least one of the following: a password, a first identifier, a distinguishing code, an iteration parameter, and a salt value; wherein the first identifier is used to indicate the password of the first device.
63. The device according to any one of claims 59 to 62, It is characterized in that The device further comprises: a display module; The display module is used to display a first field, where the first field is used to record the number of second session channels connected to the first device; The sending module is also used to send second indication information to the first device, and the second indication information is used to indicate clearing the operation certificate recorded in the first function set, the first function set is used to manage the first type of credentials generated by the node in the operating network, the operation certificate is the credential for controlling the first device, and the first type of credential has the first operation authority of the first device.
64. The device according to claim 63, It is characterized in that The first type of credential is a temporary credential, and the first operation authority is a temporary operation authority.
65. A communication device, It is characterized in that The communication device includes a processor and a memory, wherein a computer program is stored in the memory, and the processor executes the computer program to implement the method according to any one of claims 1 to 15, or to implement the method according to any one of claims 16 to 26, or to implement the method according to any one of claims 27 to 32.
66. A computer readable storage medium, It is characterized in that The storage medium stores a computer program, which is used to be executed by a processor to implement the method according to any one of claims 1 to 15, or to implement the method according to any one of claims 16 to 26, or to implement the method according to any one of claims 27 to 32.
67. A chip, It is characterized in that The chip includes a programmable logic circuit and / or program instructions, and when the chip is running, it is used to implement the method as described in any one of claims 1 to 15, or to implement the method as described in any one of claims 16 to 26, or to implement the method as described in any one of claims 27 to 32.
68. A computer program product, It is characterized in that The computer program product includes computer instructions, which are stored in a computer-readable storage medium. The processor reads and executes the computer instructions from the computer-readable storage medium to implement the method according to any one of claims 1 to 15, or the method according to any one of claims 16 to 26, or the method according to any one of claims 27 to 32.
Citation Information
Patent Citations
Automobile control method, automobile control information sending method, terminal, automobile-mounted terminal and automobile
CN106314360A
Method and apparatus for third party to control device
CN106468886A
Certificate issuing method and system based on Matter protocol
CN115714975A
Method and system for authentication
US20170244676A1
Wireless communication method and device
WO2022217561A1