Method for joining trust ring
By establishing a trust ring between devices, using the same account device certificate and trust root data for identity authentication and data transmission, the problem of poor cloud data security in the existing technology is solved, and secure identity authentication and data transmission between devices is realized.
Patent Information
- Application Number
- PCT/CN2024/126067
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-06
- Filing Date
- 2024-10-21
- Publication Date
- 2025-06-12
AI Technical Summary
In the prior art, the identity authentication of the interconnection between the device and the user relies on the account password, resulting in the risk of counterfeiting users in the cloud, and users cannot control the security of cloud data, resulting in concerns about privacy data leakage.
Through a method of adding a trust ring, the device to be authenticated obtains the verification of the trust device through the same account device certificate, receives the trust root data, including the root key and the root certificate, and performs signature verification to ensure the security of the device's identity authentication and data transmission.
This method ensures the legality and validity of the root certificate through two signatures, avoids data being manipulated in the cloud, enhances data security, and ensures the authentication and data transmission between the device to be authenticated and the device trusted.
Smart Images

Figure CN2024126067_12062025_PF_FP_ABST
Abstract
Description
How to join the trust circle
[0001] This application claims priority to Chinese patent application No. 202311667846.6, filed on December 6, 2023, with the invention name “Method for Joining a Trust Ring”. The entire contents of the above Chinese patent application are incorporated into this application by reference. Technical Field
[0002] The present application relates to the field of computer technology, and specifically provides a method for joining a trust ring. Background Art
[0003] Currently, authentication for device-user connections is account-based. Devices logged into the same account can communicate and exchange data. However, because account and password verification occurs in the cloud, impersonation is possible, allowing users to access user data or devices without requiring a password. Furthermore, once user data is in the cloud, it relies entirely on cloud services for protection, leaving users with no control over cloud data leaks or unauthorized access. Consequently, reports of backend data breaches frequently surface, raising significant concerns among users about the security of their private data.
[0004] Accordingly, the art needs a new method for adding a trust ring to solve the above problems.
[0005] Summary of the Invention
[0006] In order to overcome the above-mentioned defects, the present application is proposed to provide a method for joining a trust ring that solves or at least partially solves the technical problem of poor data security in the prior art.
[0007] In a first aspect, the present application provides a method for joining a trust ring, performed by a device to be authenticated, the method comprising:
[0008] Obtain verification of a trusted device based on a device certificate with the same account, wherein the trusted device is an existing device in the trust ring;
[0009] Receive the trust root data sent by the trusted device, wherein the trust root data includes a root key and a root certificate, and the root certificate is obtained by signing the root key based on the same account CA, the trusted ring CA and the cloud server;
[0010] Join the trust ring according to the trust root data.
[0011] In one technical solution of the above-mentioned method for joining a trust ring, the root certificate is obtained by the following steps:
[0012] The trusted device signs the root key for the first time based on the CA with the same account to obtain first signature information;
[0013] The trusted device sends the first signature information to the cloud server, so that the cloud server signs the first signature information for the second time based on the trusted ring CA to obtain the root certificate;
[0014] The trust device receives the root certificate sent by the cloud server.
[0015] In one technical solution of the above-mentioned method for joining a trust ring, the verification of obtaining a trusted device based on a device certificate with the same account includes:
[0016] The same-account device certificate is sent to the trusted device, so that the trusted device verifies the received same-account device certificate of the device to be authenticated based on its own same-account device certificate.
[0017] In one technical solution of the above-mentioned method for joining a trust ring, joining the trust ring according to the trust root data includes:
[0018] Based on the trusted ring CA, verify the signature of the root certificate and determine whether the device sending the root certificate is the trusted device;
[0019] After the verification is passed, confirm to join the trust ring.
[0020] In one technical solution of the above-mentioned method for joining a trust ring, the root key is received in ciphertext form, wherein the root key is encrypted by the trusted device based on the device certificate with the same account as the device to be authenticated;
[0021] The method further comprises:
[0022] The ciphertext is decrypted based on the device certificate with the same account as the device to be authenticated to obtain the root key.
[0023] In a second aspect, the present application provides a method for joining a trust ring, the method comprising:
[0024] The device to be authenticated sends its own device certificate with the same account to the trusted device, wherein the trusted device is a device that already exists in the trust ring;
[0025] The trusting device verifies the received device certificate of the device to be authenticated based on its own device certificate of the same account;
[0026] If the verification is successful, the trust device sends the trust root data to the device to be authenticated, wherein the trust root data includes a root key and a root certificate;
[0027] The device to be authenticated joins the trust ring according to the trust root data.
[0028] In one technical solution of the above-mentioned method for joining a trust ring, the root certificate is obtained by the following steps:
[0029] The trusted device signs the root key for the first time based on the CA with the same account to obtain first signature information;
[0030] The trusted device sends the first signature information to the cloud server;
[0031] The cloud server signs the first signature information for a second time based on the trusted ring CA to obtain the root certificate;
[0032] The trust device receives the root certificate sent by the cloud server.
[0033] In one technical solution of the above-mentioned method for joining a trust ring, the device to be authenticated joins the trust ring according to the trust root data, including:
[0034] The device to be authenticated verifies the signature of the root certificate based on the trusted ring CA, and determines whether the device sending the trusted device root certificate is the trusted device;
[0035] After the verification is passed, the device to be authenticated confirms to join the trust ring.
[0036] In one technical solution of the above method for joining a trust ring, the method further includes:
[0037] The trusted device encrypts the root key based on the device certificate with the same account as the device to be authenticated, so that the root key is sent in ciphertext form;
[0038] The device to be authenticated decrypts the ciphertext based on its own device certificate with the same account, so that the device to be authenticated obtains the root key.
[0039] In a third aspect, the present application provides a device to be authenticated, the device to be authenticated comprising:
[0040] A data sending module, the data sending module being configured to obtain verification of a trusted device based on a device certificate of the same account, wherein the trusted device is a device already existing in the trust ring;
[0041] A data receiving module, the data receiving module being configured to receive the trust root data sent by the trusted device, wherein the trust root data includes a root key and a root certificate, and the root certificate is obtained by signing the root key based on the same account CA, the trusted ring CA, and the cloud server;
[0042] A data processing module is configured to join the trust ring according to the trust root data.
[0043] In a fourth aspect, the present application provides a data protection system comprising at least a cloud server, a device to be authenticated, and a trusted device, wherein the data protection system is used to execute any one of the technical solutions in the above-mentioned method of joining a trust ring.
[0044] In a fifth aspect, the present application provides an electronic device comprising one or more memories and one or more processors, wherein the memories are used to store computer programs; the processors are used to call the computer programs so that the electronic device executes any technical solution in the above-mentioned method of joining a trust ring.
[0045] In a sixth aspect, the present application provides a computer-readable storage medium comprising computer instructions; when the computer instructions are executed on an electronic device, the electronic device executes any one of the technical solutions in the above-mentioned method of joining a trust ring.
[0046] In a seventh aspect, the present application provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute any one of the above-mentioned technical solutions for joining a trust ring.
[0047] The above one or more technical solutions of this application have at least one or more of the following beneficial effects:
[0048] In the technical solution for implementing this application, verification of the trusted device is obtained based on the same-account device certificate. After the verification is passed, the trusted root data sent by the trusted device is received, so that the device to be authenticated is added to the trust ring based on the trusted root data. In this application, the root certificate sent by the trusted device is obtained by signing the root key based on the same-account CA of the account service and the trusted ring CA of the trust ring service. These two signatures ensure the legitimacy and validity of the finally generated root certificate in the trust ring; in this application, data is exchanged between devices, which avoids the situation where data is manipulated in the cloud and ensures the security of the data.
[0049] Furthermore, in the process of obtaining the verification of the trusted device based on the same-account device certificate, the trusted device verifies the same-account device certificate of the device to be authenticated based on its own same-account device certificate. This application first verifies the same-account device certificates of the trusted device and the device to be authenticated to ensure that the device to be authenticated to be added to the trust ring and the trusted device already in the trust ring belong to the same account name. After this verification process, it prevents devices under different account names from being added to the trust ring established by other accounts, further ensuring data security.
[0050] Furthermore, the signature of the root certificate is verified by the trusted ring CA to determine whether the device sending the root certificate is a trusted device. After the verification is successful, the device to be authenticated confirms its entry into the trusted ring. This application further ensures data security by authenticating the trusted device on the device to be authenticated, combining the authentication of the trusted device on the trusted device with the mutual authentication of the device to be authenticated on the trusted device.
[0051] Furthermore, the trusted device root key is encrypted by the trusted device based on the device certificate with the same account as the device to be authenticated. The device to be authenticated receives the root key ciphertext and decrypts it based on its device certificate with the same account to obtain the root key. In this application, the root key is encrypted on the trusted device side based on the device certificate with the same account as the device to be authenticated, and the root key ciphertext is decrypted on the device to be authenticated. This encryption strategy ensures that the root key ciphertext can only be decrypted by the designated device to be authenticated, further ensuring data security.
[0052] Furthermore, in the process of signing the root key of the trusted device to obtain the root certificate of the device to be authenticated, the root key is first signed by the CA of the account service. The first signature information is then sent to the server. The server then signs the first signature information a second time based on the trusted ring CA of the trust ring service. Finally, the trusted device receives the root certificate issued by the server. In this application, only the root certificate obtained after being signed twice is valid. Using a valid root certificate for identity authentication or data transmission can ensure data security. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] The disclosure of this application will be more easily understood with reference to the accompanying drawings. Those skilled in the art will readily appreciate that these drawings are for illustrative purposes only and are not intended to limit the scope of protection of this application. Furthermore, similar numbers in the figures represent similar components, where:
[0054] FIG1 is a flow chart showing the main steps of a method for joining a trust ring according to an embodiment of the present application;
[0055] FIG2 is a schematic diagram of a data interaction sequence of a method for joining a trust ring according to an embodiment of the present application;
[0056] FIG3 is a diagram illustrating an implementation example of a method for obtaining a root certificate according to an embodiment of the present application;
[0057] FIG4 is a diagram illustrating an implementation example of a method for joining a trust ring according to an embodiment of the present application;
[0058] FIG5 is a diagram illustrating an implementation example of data protection by devices in a trust ring according to an embodiment of the present application;
[0059] FIG6 is a schematic diagram of a main structure of a device to be authenticated according to an embodiment of the present application;
[0060] FIG7 is a schematic diagram of the internal structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0061] Some embodiments of the present application are described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the present application and are not intended to limit the scope of protection of the present application.
[0062] In the description of this application, "module" and "processor" may include hardware, software, or a combination of both. A module may include hardware circuitry, various suitable sensors, communication ports, and memory. It may also include software components, such as program code, or a combination of software and hardware. A processor may be a central processing unit, a microprocessor, an image processor, a digital signal processor, or any other suitable processor. A processor has data and / or signal processing capabilities. A processor may be implemented in software, hardware, or a combination of both. Non-transitory computer-readable storage media include any suitable medium capable of storing program code, such as magnetic disks, hard disks, optical disks, flash memory, read-only memory, random access memory, etc. The term "A and / or B" refers to all possible combinations of A and B, such as only A, only B, or both A and B. The terms "at least one of A or B" or "at least one of A and B" have similar meanings to "A and / or B" and may include only A, only B, or both A and B. The singular forms "a" and "the" may also include the plural forms.
[0063] The relevant user personal information that may be involved in the various embodiments of this application is strictly in accordance with the requirements of laws and regulations, following the principles of legality, legitimacy and necessity, and based on the reasonable purposes of business scenarios, to process the personal information that users actively provide during the use of products / services or generated due to the use of products / services, as well as the personal information obtained with the user's authorization.
[0064] The user personal information processed in this application will vary depending on the specific product / service scenario and will be based on the specific scenario in which the user uses the product / service. This may involve the user's account information, device information, driving information, vehicle information, or other related information. The applicant will treat the user's personal information and its processing with a high degree of diligence.
[0065] This application attaches great importance to the security of user personal information and has taken reasonable and feasible security protection measures that comply with industry standards to protect user information and prevent personal information from being accessed, disclosed, used, modified, damaged or lost without authorization.
[0066] Please refer to Figure 1, which is a flow chart of the main steps of the method for joining a trust ring according to an embodiment of the present application. As shown in Figure 1, the method for joining a trust ring of the present application mainly includes steps S11 to S14:
[0067] Step S11: The device to be authenticated sends its own device certificate with the same account to the trusted device.
[0068] In this embodiment, the device to be authenticated is a device that has not joined the trust ring and is undergoing identity authentication to join the trust ring. Similarly, the trusted device is a device that has joined the trust ring, where the trust ring is a trust chain composed of mutually trusting devices, and all devices in the trust ring are trusted devices.
[0069] In this embodiment, the same-account device certificate includes the device information of the device to be authenticated and the ID information of the user account. In one implementation, the same-account device certificate can be obtained based on the following steps: first, the server issues a device certificate for the device to be authenticated based on the device CA, wherein the device CA is used to sign the certificate of the device or application, and the device certificate includes the device information of the device to be authenticated; then, the device certificate and the user account password are sent to the server. After the server verifies the user account password, the server issues a same-account device certificate for the device to be authenticated based on the same-account CA of the account service, and the same-account device certificate includes the device information of the device to be authenticated and the user account ID information to bind the user account to the device.
[0070] Step S12: The trusting device verifies the received device certificate of the device to be authenticated based on its own device certificate of the same account.
[0071] In this embodiment, the device certificate with the same account number of the trusted device itself and the device certificate with the same account number of the device to be authenticated in the above step S11 are obtained in the same way and have the same function.
[0072] In this embodiment, the device certificate of the device to be authenticated is verified based on the device certificate of the trusted device. It can be determined whether the two devices belong to the same user account by verifying whether the part of the user account ID in the information contained in the two is consistent.
[0073] Step S13: If the verification is successful, the trusting device sends the trust root data to the device to be authenticated.
[0074] In this embodiment, the trusted root data includes at least the root key and root certificate of the trusted device. The trusted device can send the root key and root certificate to the device to be authenticated in batches to further ensure data security. For example, the root certificate is first sent for verification by the device to be authenticated, and the root key is sent after the verification is passed. Alternatively, the root key and root certificate can be sent to the device to be authenticated at one time to improve the efficiency of identity authentication. The specific transmission method is not limited here. The trusted root data can also include a trusted device certificate issued by the trusted device to the device to be authenticated. This certificate is usually associated with the device certificate with the same account number of the device to prove that the device to be authenticated is a trusted device that has passed the verification.
[0075] In this embodiment, the root certificate is obtained by signing the root key on the server side using the Trusted Ring CA of the Trusted Ring Service. The Trusted Ring CA is the root CA, representing the highest level of the entire PKI system and serving as the starting point of trust. In one embodiment, the root certificate of the trusted device is obtained through the following steps: the trusted device first signs the root key using the same account CA of the account service; the Trusted Ring CA then signs the root key a second time based on the first signature; and finally, the root certificate is obtained after these two signatures.
[0076] Step S14: The device to be authenticated joins the trust ring based on the trust root data.
[0077] In this embodiment, since the trusted device has already verified and approved the identity of the device to be authenticated through the above steps, the subsequent process of joining the trust ring depends on the device to be authenticated. The device to be authenticated can also verify the identity of the trusted device again and only choose to join the trust ring after the verification is successful.
[0078] In one embodiment, the device to be authenticated needs to verify the identity of the trusted device. This verification process includes at least the following steps: the device to be authenticated verifies the signature of the trusted device's root certificate based on the trusted ring CA to determine whether the device sending the root certificate is the trusted device. The trusted ring CA can come from the trusted device, for example, it can be included in the trusted root data and sent to the device to be authenticated along with the root key and root certificate; it can also come from a cloud server. After receiving the trusted device's root certificate, the device to be authenticated sends a request to the cloud server to call the trusted ring CA. The cloud server responds to the request and sends the trusted ring CA to the device to be authenticated.
[0079] In this embodiment, after the device to be authenticated joins the trust ring, its role is changed to a trusted device, and it can use the received trust root data to invite other devices to be authenticated to join the trust ring. Therefore, it can be seen that the trust ring manages the devices to be authenticated based on the transfer of root keys and root certificates.
[0080] From the above description of the embodiments of the present application, it can be seen that in this application, the root certificate sent by the trusted device is obtained after the root key is signed by the same-account CA of the account service and the trusted ring CA of the trust ring service. These two signatures ensure the legitimacy and validity of the finally generated root certificate in the trust ring; this application is based on the same-account device certificate and the trusted root data for identity authentication, and there is no need to upload private data to the cloud, which avoids the manipulation of data in the cloud and ensures the security of the data.
[0081] Please refer to Figure 2, which is a schematic diagram of the data interaction sequence of the method for joining a trust ring according to an embodiment of the present application. Based on Figure 2, please refer to Figure 3, which is an implementation example diagram of the method for obtaining a root certificate according to an embodiment of the present application. In the implementation example shown in Figure 3, the root certificate is obtained through the following steps:
[0082] 1. The device CA creates a device certificate signing request (CSR). The CSR contains the device's public key and other information, such as device identification information. After confirming the device's identity, the device CA signs the CSR to generate a device certificate. The generated device certificate is returned to the device.
[0083] 2.1. Use the device certificate to verify whether the account password comes from a specific device.
[0084] 2.2. Send the device certificate and account password to the account service center in the cloud;
[0085] 2.3. The Account Service Center verifies whether the account password is correct and sends the verification result to the CA with the same account;
[0086] 2.4. If the verification result is correct, the CA with the same account will sign the data information and account password contained in the device certificate to obtain the device certificate with the same account, which proves that the device is bound to the specified user account;
[0087] 3.1. The device generates a root key and signs it for the first time using the CA with the same account. This first signature information is used to prove that the root key was issued from the designated device with the same account. The first signature information includes the signature result and the public key of the root key.
[0088] 3.2. Send the first signature information to the server to obtain the device key certificate and confirm that the root key comes from the specified device with the same account;
[0089] 3.3. The server signs the first signature information a second time based on the trusted ring CA to obtain a compliant root certificate.
[0090] 3.4. Return the root certificate to the device.
[0091] Based on Figure 2, refer to Figure 4, which is an implementation example diagram of a method for joining a trust ring according to an embodiment of the present application. In the implementation example shown in Figure 4, the following method for joining a trust ring is used to join the new phone 2 (the device to be authenticated) to the trust ring where the old phone 1 (the trusted device) is located:
[0092] a. New phone 2 sends a request to join the trust ring to old phone 1;
[0093] b. Old phone 1 confirms the request;
[0094] c. The old phone 1 notifies the new phone 2 of the confirmation result;
[0095] d. New phone 2 sends its own device certificate with the same account to old phone 1;
[0096] e. Old phone 1 verifies the device certificate of new phone 2 based on its own device certificate of the same account to determine whether the two devices belong to the same account;
[0097] f. After the old phone 1 successfully authenticates the new phone 2, the old phone 1 sends the root certificate to the new phone 2;
[0098] g. New phone 2 reverse-verifies the signature information of the root certificate based on the server's trusted ring CA to determine whether the root certificate comes from the designated trusted device. In practice, there is a possibility that someone will mistakenly request to add new phone 2 to the trusted ring of old phone 1. Therefore, the purpose of this setting is to prevent new phone 2 from being added to the wrong trusted ring due to human error.
[0099] h. New phone 2 notifies old phone 1 of the authentication result of old phone 1;
[0100] i. Old phone 1 uses the device certificate of the same account as new phone 2 to encrypt the root key;
[0101] j. Old phone 1 sends the root key ciphertext and the trusted device certificate issued for new phone 2 to new phone 2;
[0102] k. New phone 2 uses its own device certificate with the same account to decrypt the root key ciphertext and obtain the root key;
[0103] 1. New phone 2 confirms joining the trust ring and sends the confirmation result to old phone 1 and the server.
[0104] It should be understood that the description in this implementation example is only used to explain this application, and the above description does not have a limiting effect.
[0105] Please refer to FIG5 , which is a flowchart illustrating the main steps of protecting data by devices in a trust ring according to an embodiment of the present application. As shown in FIG5 , the process of protecting data by devices in a trust ring can be described as follows:
[0106] The trusted device of the data sender uses its own root key to encrypt the data to be transmitted, and then sends the obtained ciphertext data to the data receiver; the trusted device of the data receiver uses its own root key to decrypt the received ciphertext data to obtain the data to be transmitted.
[0107] In this embodiment, because the trusted device of the data sender and the trusted device of the data receiver are in the same trust ring, they both share the same root key. In addition to trusted devices, the data receiver may also include other devices not in the trust ring. These devices, because they do not share the same root key as the trusted devices, are unable to decrypt received ciphertext data. In the example shown in Figure 5, mobile phone 3 does not belong to the same trust ring as mobile phone 1 and mobile phone 2. Therefore, mobile phone 3 does not share the same root key as mobile phone 1 and mobile phone 2. Even if mobile phone 3 receives encrypted data sent by mobile phone 1, it still cannot decrypt it.
[0108] The above describes the method for joining a trust ring provided by the present application. It should be pointed out that although the various steps are described in a specific order in the above embodiment, those skilled in the art can understand that in order to achieve the effect of the present application, different steps do not have to be performed in such an order. They can be performed simultaneously (in parallel) or in other orders. These changes are within the scope of protection of the present application.
[0109] Furthermore, the present application also provides a device to be authenticated.
[0110] Refer to Figure 6, which is a block diagram of the main structure of a device to be authenticated according to an embodiment of the present application. As shown in Figure 6, the device to be authenticated in this embodiment of the present application mainly includes a data sending module 11, a data receiving module 12, and a data processing module 13. In some embodiments, one or more of the data sending module 11, the data receiving module 12, and the data processing module 13 can be combined into a single module. In some embodiments:
[0111] The data sending module 11 is configured to obtain verification of a trusted device based on a device certificate of the same account, wherein the trusted device is a device that already exists in the trust ring;
[0112] The data receiving module 12 is configured to receive the trust root data sent by the trusted device, wherein the trust root data includes a root key and a root certificate. The root certificate is obtained by signing the root key based on the same account CA, the trusted ring CA and the cloud server;
[0113] The data processing module 13 is configured to join the trust ring according to the trust root data.
[0114] The above-mentioned device to be authenticated is used to execute the embodiment of the method for joining the trust ring shown in Figures 1 to 5. The technical principles, technical problems solved and technical effects produced by the two are similar. Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working process and related instructions of the device to be authenticated can refer to the contents described in the embodiment of the method for joining the trust ring, and will not be repeated here.
[0115] It will be understood by those skilled in the art that all or part of the processes in the method for implementing the above embodiment of the present application can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of each of the above method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file or some intermediate form. The computer-readable storage medium can include: any entity or device, medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory, random access memory, electric carrier signal, telecommunication signal and software distribution medium that can carry the computer program code. It should be noted that the content contained in the computer-readable storage medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable storage media do not include electric carrier signals and telecommunication signals.
[0116] Furthermore, the present application also provides a data protection system, which includes at least a cloud server, a device to be authenticated, and a trusted device, and is used to execute any technical solution of the above-mentioned method of joining a trust ring.
[0117] Those skilled in the art will appreciate that the various modules in the device can be adaptively split or merged. Such splitting or merging of specific modules will not cause the technical solution to deviate from the principles of this application. Therefore, the technical solutions after splitting or merging will fall within the scope of protection of this application.
[0118] Furthermore, the present application also provides an electronic device. See Figure 7, which is a schematic diagram of the internal structure of an electronic device according to an embodiment of the present application. The electronic device includes one or more memories and one or more processors. The memories are used to store computer programs; the processors are used to invoke the computer programs so that the electronic device executes any of the technical solutions in the method for joining a trusted ring. The processor can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), a graphics processing unit (GPU), or one or more integrated circuits, configured to execute relevant programs to implement the method in any of the implementations of the present application. The processor can also be an integrated circuit electronic device with signal processing capabilities. During implementation, the various steps of the method in any of the implementations of Figures 1 to 5 of the present application can be completed by hardware integrated logic circuits in the processor or by software instructions. The processor can also be a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The disclosed methods, steps, and logic block diagrams in the embodiments of the present application can be implemented or executed. A general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc. The steps of the method disclosed in conjunction with the embodiments of the present application may be directly embodied as being executed by a hardware decoding processor, or may be executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory, and in combination with its hardware completes the functions required to be executed by the units included in the data processing device of the embodiment of the present application, or executes the various steps of the method in any one of the implementation methods in Figures 1 to 5 of the present application.
[0119] Furthermore, the present application also provides a computer-readable storage medium. In a computer-readable storage medium embodiment according to the present application, the computer-readable storage medium can be configured to store a program for executing the method of joining a trusted ring in the above-mentioned method embodiment, and the program can be loaded and run by the processor to implement any one of the technical solutions in the above-mentioned method of joining a trusted ring. For ease of explanation, only the parts related to the embodiment of the present application are shown. For specific technical details not disclosed, please refer to the method part of the embodiment of the present application. The computer-readable storage medium can be a storage device formed by various electronic devices. Optionally, the computer-readable storage medium in the embodiment of the present application is a non-temporary computer-readable storage medium.
[0120] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product, which includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the process or function described in accordance with the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method.
[0121] Thus far, the technical solutions of the present application have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is readily understood by those skilled in the art that the scope of protection of the present application is obviously not limited to these specific embodiments. Without departing from the principles of the present application, those skilled in the art may make equivalent changes or substitutions to the relevant technical features, and the technical solutions after such changes or substitutions will fall within the scope of protection of the present application.
Claims
1. A method for joining a trust ring, performed by a device to be authenticated, characterized in that: The method comprises: Obtaining verification of a trusted device based on a device certificate of the same account, wherein the trusted device is a device that already exists in the trust ring; Receiving the trusted root data sent by the trusted device, wherein the trusted root data includes a root key and a root certificate, and the root certificate is obtained after the root key is signed by the CA with the same account, the trusted ring CA and the cloud server; According to the trust root data, join the trust ring.
2. The method according to claim 1, characterized in that The root certificate is obtained by the following steps: The trusted device signs the root key for the first time based on the CA with the same account to obtain the first signature information; The trusted device sends the first signature information to the cloud server, so that the cloud server performs a second signature on the first signature information based on the trusted ring CA to obtain the root certificate; The trust device receives the root certificate sent by the cloud server.
3. The method according to claim 1 or 2, characterized in that: The verification of obtaining a trusted device based on a device certificate of the same account includes: The same-account device certificate is sent to the trusted device, so that the trusted device verifies the received same-account device certificate of the device to be authenticated based on its own same-account device certificate.
4. The method according to any one of claims 1 to 3, characterized in that: The adding the trust ring according to the trust root data comprises: Based on the trusted ring CA, verify the signature of the root certificate and determine whether the device sending the root certificate is the trusted device; After the verification is passed, confirm to join the trust ring.
5. The method according to claim 4, characterized in that The root key is received in ciphertext form, wherein the root key is encrypted by the trusted device based on the device certificate of the same account as the device to be authenticated; The method further comprises: Based on the device certificate of the same account of the device to be authenticated, the ciphertext is decrypted to obtain the root key.
6. A method for joining a trust ring, characterized in that: The method comprises: The device to be authenticated sends its own device certificate with the same account to the trusted device, wherein the trusted device is a device that already exists in the trust ring; The trusted device verifies the received device certificate of the device to be authenticated based on its own device certificate of the same account; If the verification is successful, the trusted device sends the trusted root data to the device to be authenticated, wherein the trusted root data includes a root key and a root certificate; The device to be authenticated joins the trust ring according to the trust root data.
7. The method according to claim 6, characterized in that The root certificate is obtained by the following steps: The trusted device signs the root key for the first time based on the CA with the same account to obtain the first signature information; The trusted device sends the first signature information to the cloud server; The cloud server performs a second signature on the first signature information based on the trusted ring CA to obtain the root certificate; The trust device receives the root certificate sent by the cloud server.
8. The method according to claim 6 or 7, characterized in that: The device to be authenticated joins the trust ring according to the trust root data, including: The device to be authenticated verifies the signature of the root certificate based on the trusted ring CA and determines Whether the device sending the trusted device root certificate is the trusted device; After the verification is passed, the device to be authenticated confirms to join the trust ring.
9. The method according to any one of claims 6 to 8, characterized in that: The method further comprises: The trusted device encrypts the root key based on the device certificate with the same account number of the device to be authenticated, so that the root key is sent in ciphertext form; The device to be authenticated decrypts the ciphertext based on its own device certificate with the same account number, so that the device to be authenticated obtains the root key.
10. A device to be authenticated, characterized in that: The device to be authenticated includes: A data sending module, wherein the data sending module is configured to obtain verification of a trusted device based on a device certificate of the same account, wherein the trusted device is a device that already exists in the trust ring; A data receiving module, wherein the data receiving module is configured to receive the trusted root data sent by the trusted device, wherein the trusted root data includes a root key and a root certificate, and the root certificate is obtained after the root key is signed by the same account CA, the trusted ring CA and the cloud server; A data processing module, wherein the data processing module is configured to join the trust ring according to the trust root data.
11. A data protection system, characterized in that: The system includes at least a device to be authenticated, a trusted device and a cloud server, and the data protection system is used to execute the method described in any one of claims 1-9.
12. An electronic device, comprising one or more memories and one or more processors, characterized in that: The memory is used to store a computer program; the processor is used to call the computer program so that the electronic device executes the method according to any one of claims 1 to 9.
13. A computer-readable storage medium, characterized in that: The method comprises computer instructions; when the computer instructions are executed on an electronic device, the electronic device is caused to execute the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Method for synchronizing data between equipment via cloud and cloud server
CN108134789A
Authentication method and apparatus for IP camera
CN113557703A
Certificate acquisition method and device, equipment and storage medium
CN114826570A
User login method and electronic equipment
CN117131481A
Login method, authentication method and system based on multi-party authorization, and computing device
WO2022242003A1