Secure access method and apparatus, and cloud, terminal device and storage medium
By generating digital keys on the access device and authorized by the cloud, combined with cloud authorization verification and key matching verification, the security and management efficiency of centralized cloud solutions are solved, and higher security and convenient business management are achieved.
Patent Information
- Application Number
- PCT/CN2024/092556
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-24
- Filing Date
- 2024-05-11
- Publication Date
- 2025-07-31
AI Technical Summary
In the existing digital car key technology, centralized cloud solutions have security risks, which affects the security of keys, and the cloud does not participate in key legality verification is not conducive to business management.
The digital key is generated by the access device and authorized by the cloud. It adopts a two-factor verification mechanism, including cloud authorization verification and key matching verification, to ensure legitimacy.
Improve the security and business management efficiency of digital keys, reduce dependence on the centralized cloud by locally generating keys, and enhance the security of access and business coordination capabilities.
Smart Images

Figure CN2024092556_31072025_PF_FP_ABST
Abstract
Description
Secure access method and device, cloud and terminal equipment and storage medium Technical Field
[0001] This application relates to the field of security technology, and more particularly to a secure access method and apparatus, cloud and terminal devices, and storage medium. This application references Chinese Patent Application No. 202410094549.5, filed on January 24, 2024, entitled "Secure Access Method and Apparatus, Cloud and Terminal Devices, and Storage Medium," which is incorporated herein by reference in its entirety. Background Art
[0002] The rapid development and widespread adoption of digital car keys has brought significant convenience to people's lives. Security is a key fundamental issue for digital keys. Existing digital car key technology solutions fall into two main categories: The first is a centralized cloud-based solution, where keys are generated and issued directly to the access device from the cloud. The second is a device-side key generation solution, where both the device and the vehicle belong to the same trust chain. When the vehicle receives the key from the device, it verifies that it is issued by the same trust chain, thus acknowledging the device's legitimacy. The cloud does not participate in the key verification process. Technical issues
[0003] In solution one, any security risk in the cloud would seriously affect the security of the digital car key. In solution two, the cloud does not participate in key legitimacy verification, which is not conducive to business management. Technical Solutions
[0004] The purpose of some embodiments of this application is to provide a secure access method and device, cloud and terminal equipment and storage medium. The digital key is generated by the access device and serves as the legal key of the accessed device after being authorized by the cloud, which is conducive to improving security and facilitating business management.
[0005] In a first aspect, an embodiment of the present application provides a secure access method, applied to a cloud, comprising:
[0006] issuing a verification trust root for verifying the cloud identity to the at least one first device and the at least one second device that have been trusted respectively;
[0007] Receiving an access authorization request sent by the first device; the access authorization request includes: a digital key generated by the first device for accessing a second device;
[0008] generating an access certificate authorizing the first device to access the second device according to the access authorization request; the access certificate comprising: the digital key;
[0009] The access certificate is sent to the second device for the second device to verify the access certificate based on the verification trust root. After the verification is passed, the first device is verified according to the digital key in the access certificate.
[0010] In a second aspect, an embodiment of the present application further provides a secure access method, applied to a first device, the method comprising:
[0011] Storing the verification trust root issued by the cloud for verifying the cloud;
[0012] Sending an access authorization request to the cloud, for the cloud to generate an access certificate authorizing the first device to access the second device based on the access authorization request; the access authorization request includes: a digital key generated by the first device for accessing the second device, and the access certificate includes: the digital key;
[0013] Access the second device according to the digital key; the second device stores a verification trust root for verifying the cloud; the second device obtains the access certificate and verifies the access certificate based on the verification trust root, and after the verification is passed, verifies the first device according to the digital key in the access certificate.
[0014] In a third aspect, an embodiment of the present application further provides a secure access method, applied to a second device, the method comprising:
[0015] storing the verification trust root sent by the cloud for verifying the cloud;
[0016] Obtain an access certificate, and verify the access certificate based on the verification trust root. After the verification is passed, verify the first device according to the digital key in the access certificate; wherein, the first device sends an access authorization request to the cloud; the access authorization request includes: the digital key generated by the first device for accessing the second device, for the cloud to generate an access certificate authorizing the first device to access the second device according to the access authorization request; the access certificate includes: the digital key.
[0017] In a fourth aspect, an embodiment of the present application further provides a secure access method, which is applied to a secure access system, wherein the secure access system includes: a cloud, at least one first device, and at least one second device, and the method includes:
[0018] The at least one first device and the at least one second device receive and store a verification trust root for verifying the cloud;
[0019] A first device sends an access authorization request to the cloud; the access authorization request includes: a digital key generated by the first device for accessing a second device;
[0020] The cloud generates an access certificate authorizing the first device to access the second device according to the access authorization request; the access certificate includes: the digital key;
[0021] The second device obtains the access certificate and verifies the access certificate based on the verification trust root. After the verification is passed, the first device is verified according to the digital key in the access certificate.
[0022] In a fifth aspect, an embodiment of the present application further provides a secure access device, configured in the cloud, comprising:
[0023] A trust root issuing module, configured to issue a verification trust root for verifying the cloud identity to the at least one first device and the at least one second device that have been trusted;
[0024] A receiving module, configured to receive an access authorization request sent by the first device; the access authorization request includes: a digital key generated by the first device for accessing a second device;
[0025] An authorization module is configured to generate an access certificate authorizing the first device to access the second device according to the access authorization request; the access certificate includes: the digital key;
[0026] An access certificate issuing module is used to send the access certificate to the second device, so that the second device can verify the access certificate based on the verification trust root, and after the verification is passed, verify the first device according to the digital key in the access certificate.
[0027] In a sixth aspect, an embodiment of the present application provides a secure access device, configured on a first device, comprising:
[0028] A storage module, configured to store a verification trust root issued by the cloud for verifying the cloud;
[0029] an authorization request module, configured to send an access authorization request to the cloud, for the cloud to generate, based on the access authorization request, an access certificate authorizing the first device to access the second device; the access authorization request including: a digital key generated by the first device for accessing the second device; the access certificate including: the digital key;
[0030] An access module is used to access the second device based on the digital key; the second device stores a verification trust root for verifying the cloud; the second device obtains the access certificate and verifies the access certificate based on the verification trust root, and after the verification is passed, verifies the first device based on the digital key in the access certificate.
[0031] In a seventh aspect, an embodiment of the present application provides a secure access device, configured on a second device, comprising:
[0032] A storage module, configured to store a verification trust root sent by the cloud for verifying the cloud;
[0033] an access certificate verification module, configured to obtain an access certificate and verify the access certificate based on the verification trust root; and
[0034] An access authentication module is used to verify the first device according to the digital key in the access certificate after the access certificate is verified; wherein, the first device sends an access authorization request to the cloud, so that the cloud generates an access certificate authorizing the first device to access the second device according to the access authorization request; the access authorization request includes: the digital key generated by the first device for accessing the second device, and the access certificate includes: the digital key.
[0035] In an eighth aspect, an embodiment of the present application provides a cloud comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, wherein when the processor executes the program, the secure access method as described in the first aspect is implemented.
[0036] In the ninth aspect, an embodiment of the present application provides a terminal device, comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, wherein when the processor executes the program, the secure access method as described in the second or third aspect is implemented.
[0037] In a tenth aspect, an embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the secure access method as described in the first aspect. Beneficial effects
[0038] Compared with the prior art, the technical solution provided by the embodiments of the present application has at least the following positive effects:
[0039] In an embodiment of the present application, the first device and the second device store a verification trust root in the cloud. The first device sends an access authorization request to the cloud. The access authorization request includes a digital key generated by the first device for accessing the second device. The cloud generates an access certificate authorizing the first device to access the second device based on the access authorization request, and sends the access certificate to the second device. The second device verifies the access certificate based on the stored verification trust root. After the verification is passed, the access request of the first device is verified based on the digital key in the access certificate. Therefore, the second device (the accessed device) verifies the legitimacy of the digital key using dual authentication of cloud authorization verification and key matching verification. At the same time, when the first device accesses the second device as an access device, it uses a locally generated digital key, which abandons the method of relying on the centralized cloud to uniformly issue digital keys, thereby improving the security of access. At the same time, the cloud is responsible for access authorization management, which facilitates coordinated management of business. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application, a brief introduction will be given below to the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0041] FIG1 is a flow chart of a secure access method according to a first embodiment of the present application;
[0042] FIG2 is a flow chart of a secure access method according to a second embodiment of the present application;
[0043] FIG3 is a flow chart of a secure access method according to a third embodiment of the present application;
[0044] FIG4 is a flow chart of a secure access method according to a fourth embodiment of the present application;
[0045] FIG5 is a schematic diagram of the structure of a secure access device provided in Example 5 of the present application;
[0046] FIG6 is a schematic diagram of the structure of a secure access device provided in Example 6 of the present application;
[0047] FIG7 is a schematic diagram of the structure of a secure access device provided in Example 7 of the present application;
[0048] FIG8 is a schematic diagram of the structure of the cloud provided in Example 8 of the present application;
[0049] FIG9 is a schematic diagram of the structure of the terminal device provided in Example 9 of the present application. Best Mode for Carrying Out the Invention
[0050] In order to make the purpose, technical solutions and advantages of this application more clear, some embodiments of this application are further described in detail below in conjunction with the accompanying drawings and examples. It should be understood that the specific embodiments described here are only used to explain this application and are not used to limit this application.
[0051] The best implementation of the present application may be a preferred embodiment among the following implementation methods, which will not be described in detail here. Modes for Carrying Out the Invention
[0052] Figure 1 is a flow chart of a secure access method provided in Example 1 of the present application. This embodiment of the present application is applicable to secure access to devices with user asset attributes, such as vehicles and charging stations. This method can be executed by a secure access device provided in this embodiment of the present application. The device can be implemented in software and configured in a cloud (also known as a trust center) application. This embodiment of the present application specifically includes the following steps:
[0053] Step 101: issuing a verification trust root for verifying a cloud identity to at least one first device and at least one second device that have been trusted.
[0054] The first device can be a mobile terminal used to access the second device, such as a smartphone, smartwatch, card, or electronic key. The second device can be any device with user asset attributes, such as a vehicle, charging station, or smart door lock.
[0055] After the first and second devices successfully register with the cloud, the cloud recognizes their legitimacy and becomes trusted by the cloud. The cloud then issues a root of trust to the trusted first and second devices, which is used to verify the cloud. The root of trust can be the cloud's root certificate, which is the public key in an asymmetric key, used to verify the cloud's identity. The first and second devices can proactively initiate registration and filing requests to the cloud, providing authentic registration information for the cloud to verify the legitimacy of the devices and file the information. Details are omitted here.
[0056] Step 102: Receive an access authorization request sent by a first device. The access authorization request includes: a digital key generated by the first device for accessing a second device.
[0057] There can be multiple first devices trusted by the cloud. When any of these trusted first devices needs to access a trusted second device, it generates a digital key for accessing the second device and an access authorization request containing the digital key. The access authorization request is then sent to the cloud for authorization. The first device encrypts the access authorization request using a stored authentication root of trust and generates the access authorization request. The request includes, for example, the generated digital key and other access information. The other access information may include information about the second device to be accessed and the validity period of the digital key.
[0058] Step 103: Generate an access certificate authorizing a first device to access a second device according to the access authorization request.
[0059] After receiving the access authorization request, the cloud uses the private key to decrypt the access authorization request to obtain the content of the request. Then, based on the content of the request and the business logic, it authenticates the access rights of the first device to the second device. After the authentication is successful, the first device is authorized to access the access rights of the second device and a corresponding access certificate is generated. For example, an access authorization request is a request from a first device (the owner's mobile phone) to access a second device (the owner's vehicle or charging station). The cloud generates an access certificate after authenticating the access authorization request based on the business logic. The access certificate includes the digital key. The cloud uses the private key to sign the authorized access credential containing the digital key and generates the access certificate.
[0060] Step 104: Send the access certificate to a second device for the second device to verify the access certificate based on the verification trust root. After the verification is passed, verify the first device based on the digital key in the access certificate.
[0061] A second device may obtain access credentials by, for example, directly receiving the access credentials from the cloud, or receiving the access credentials from a first device. In this case, the cloud sends the access credentials to the first device, and the first device sends the access credentials to the second device when accessing the second device for the first time. It is understood that the cloud may also send the access credentials to both the first device and the second device simultaneously.
[0062] After receiving the access certificate, the second device verifies the access certificate based on the stored verification trust root. After successful verification, the second device obtains the digital key in the access certificate. The digital key identifies the first device's access to the second device within a certain period of time. The second device can add the digital key in the access certificate to a list of valid keys. Once added to the list of valid keys, the digital key is activated, allowing the first device to access the second device. It is understood that the cloud can first hash the digital key and then sign it with the private key. After successful verification, the hashed digital key is obtained.
[0063] When a first device accesses a second device, the second device receives the digital key sent by the first device and matches it with the digital keys in the list of valid digital keys. If the match is successful, the first device is deemed to have valid access rights and can perform the corresponding service. It is understood that within the validity period of the digital key, the first device can continue to use the digital key to access the second device without having to repeatedly request access certificates from the cloud, which can reduce cloud consumption.
[0064] Compared with the existing technology, in the embodiment of the present application, the first device (access device) generates a digital key locally, abandoning the centralized cloud solution, and the second device (accessed device) uses cloud authorization verification and key matching verification to verify the legitimacy of the digital key, which is conducive to improving the security of access. At the same time, the cloud is responsible for access authorization management, which facilitates the coordinated management of business.
[0065] Figure 2 is a flow chart of a secure access method provided in Example 2 of this application. This embodiment of the application is applicable to secure access to devices with user asset attributes, such as vehicles and charging stations. This method can be executed by a secure access device provided in this embodiment of the application. The device can be implemented in software and configured on a first device (i.e., an access device). This embodiment of the application specifically includes the following steps:
[0066] Step 201: Store the verification trust root issued by the cloud for verifying the cloud.
[0067] After being trusted by the cloud, the first device can obtain the verification trust root issued by the cloud.
[0068] Step 202: Send an access authorization request to the cloud. The access authorization request includes: a digital key generated by the first device for accessing the second device, for the cloud to generate an access certificate authorizing the first device to access the second device based on the access authorization request. The access certificate includes: the digital key.
[0069] Step 203: Access the second device using the digital key. The second device stores a root of trust for verifying the cloud. The second device obtains the access certificate and verifies the access certificate based on the root of trust. Once the access certificate is verified, the second device verifies the first device using the digital key in the access certificate.
[0070] The steps and functions performed by the cloud, the first device, and the second device in this embodiment and embodiment 1 are the same and will not be repeated here.
[0071] Compared with the existing technology, in the embodiment of the present application, the first device (access device) generates a digital key locally, abandoning the centralized cloud solution, and the second device (accessed device) uses cloud authorization verification and key matching verification to verify the legitimacy of the digital key, which is conducive to improving the security of access. At the same time, the cloud is responsible for access authorization management, which facilitates the coordinated management of business.
[0072] Figure 3 is a flow chart of the secure access method provided in Example 3 of this application. This embodiment of the application is applicable to secure access to devices with user asset attributes, such as vehicles and charging stations. This method can be executed by a secure access device provided in this embodiment of the application. The device can be implemented in software and configured on a second device (i.e., the accessed device). This embodiment of the application specifically includes the following steps:
[0073] Step 301: Store the verification trust root sent by the cloud for verifying the cloud.
[0074] Step 302: Obtain access proof and verify the access proof based on the verification trust root.
[0075] Step 303: After verification, the first device is authenticated using the digital key in the access certificate. The first device sends an access authorization request to the cloud. The access authorization request includes the digital key generated by the first device for accessing the second device. The cloud then generates an access certificate authorizing the first device to access the second device based on the access authorization request. The access certificate includes the digital key.
[0076] The steps and functions performed by the cloud, the first device, and the second device in this embodiment and embodiment 1 are the same and will not be repeated here.
[0077] Compared with the existing technology, in the embodiment of the present application, the first device (access device) generates a digital key locally, abandoning the centralized cloud solution, and the second device (accessed device) uses cloud authorization verification and key matching verification to verify the legitimacy of the digital key, which is conducive to improving the security of access. At the same time, the cloud is responsible for access authorization management, which facilitates the coordinated management of business.
[0078] Figure 4 is a flow chart of a secure access method provided in Example 4 of the present application. This embodiment of the present application is applicable to secure access to devices with user asset attributes, such as vehicles and charging stations. This method can be executed by a secure access system provided in an embodiment of the present application, which includes: a cloud, at least one first device, and at least one second device. This embodiment of the present application specifically includes the following steps:
[0079] Step 401: At least one first device and at least one second device receive and store a verification trust root for authenticating the cloud.
[0080] Step 402: A first device sends an access authorization request to the cloud. The access authorization request includes: a digital key generated by the first device for accessing a second device.
[0081] Step 403: The cloud generates an access certificate authorizing a first device to access a second device according to the access authorization request. The access certificate includes a digital key.
[0082] Step 404: A second device obtains an access certificate and verifies the access certificate based on the verification trust root. After the verification is passed, a first device is verified based on the digital key in the access certificate.
[0083] The steps and functions performed by the cloud, the first device, and the second device in this embodiment and embodiment 1 are the same and will not be repeated here.
[0084] Compared with the existing technology, in the embodiment of the present application, the first device (access device) generates a digital key locally, abandoning the centralized cloud solution, and the second device (accessed device) uses cloud authorization verification and key matching verification to verify the legitimacy of the digital key, which is conducive to improving the security of access. At the same time, the cloud is responsible for access authorization management, which facilitates the coordinated management of business.
[0085] The fifth embodiment of the present application provides a secure access device configured in the cloud. As shown in FIG5 , the device 500 includes: a trust root issuing module 502 , a receiving module 504 , an authorization module 506 , and an access certificate issuing module 508 .
[0086] The root of trust issuing module 502 is used to issue a verification root of trust for verifying the cloud identity to at least one first device and at least one second device that have been trusted.
[0087] The receiving module 504 is configured to receive an access authorization request sent by a first device. The access authorization request includes a digital key generated by the first device for accessing a second device.
[0088] The authorization module 506 is used to generate an access certificate authorizing a first device to access a second device according to the access authorization request. The access certificate includes: a digital key.
[0089] The access certificate sending module 508 is used to send the access certificate to a second device, so that the second device can verify the access certificate based on the verification trust root, and after the verification is passed, verify the first device according to the digital key in the access certificate.
[0090] Compared with the existing technology, in the embodiment of the present application, the first device (access device) generates a digital key locally, abandoning the centralized cloud solution, and the second device (accessed device) uses cloud authorization verification and key matching verification to verify the legitimacy of the digital key, which is conducive to improving the security of access. At the same time, the cloud is responsible for access authorization management, which facilitates the coordinated management of business.
[0091] The sixth embodiment of the present application provides a secure access device configured in an access device, hereinafter referred to as the first device. As shown in FIG6 , the device 600 includes a storage module 602 , an authorization request module 604 , and an access module 606 .
[0092] The storage module 602 is used to store the verification trust root sent by the cloud for verifying the cloud.
[0093] The authorization request module 604 is configured to send an access authorization request to the cloud, which generates, based on the access authorization request, an access certificate authorizing the first device to access the second device. The access authorization request includes a digital key generated by the first device for accessing the second device. The access certificate includes the digital key.
[0094] Access module 606 is used to access the second device based on the digital key. The second device stores a verification trust root for verifying the cloud. The second device obtains the access certificate and verifies the access certificate based on the verification trust root. After the verification is successful, the second device verifies the first device based on the digital key in the access certificate.
[0095] Compared with the existing technology, in the embodiment of the present application, the first device generates a digital key locally, abandoning the centralized cloud solution, and the second device uses double verification of cloud authorization verification and key matching verification to verify the legitimacy of the digital key, which is conducive to improving the security of access. At the same time, the cloud is responsible for access authorization management, which facilitates the coordinated management of business.
[0096] The seventh embodiment of the present application provides a secure access device configured on an accessed device (hereinafter referred to as the second device). As shown in FIG7 , the device 700 includes a storage module 702 , an access certificate verification module 704 , and an access authentication module 706 .
[0097] The storage module 702 is used to store the verification trust root sent by the cloud for verifying the cloud.
[0098] The access certificate verification module 704 is used to obtain the access certificate and verify the access certificate based on the verification trust root.
[0099] Access authentication module 706 is configured to authenticate the first device based on the digital key in the access certificate after the access certificate is successfully verified. The first device sends an access authorization request to the cloud, which generates an access certificate authorizing the first device to access the second device based on the access authorization request. The access authorization request includes the digital key generated by the first device for accessing the second device, and the access certificate includes the digital key.
[0100] Compared with the existing technology, in the embodiment of the present application, the first device generates the digital key locally, abandoning the e-centralized cloud solution, and the second device uses double verification of cloud authorization verification and key matching verification to verify the legitimacy of the digital key, which is conducive to improving the security of access. At the same time, the cloud is responsible for the authorization management of access, which facilitates the coordinated management of business.
[0101] Figure 8 is a schematic diagram of the cloud structure provided by Example 8 of the present application. The cloud 80 includes a memory 81, a processor 82, and a computer program stored in the memory 81 and executable on the processor 82. When the processor 82 executes the program, the technical solution described in the above-mentioned Example 1 is implemented.
[0102] Figure 9 is a schematic diagram of the structure of a terminal device provided in Example 9 of the present application. The terminal device 90 includes a memory 91, a processor 92, and a computer program stored in the memory 91 and executable on the processor 92. When the processor 82 executes the program, the technical solution described in the second or third embodiment is implemented.
[0103] The tenth embodiment of the present application provides a secure access system, comprising a cloud, at least one first device, and at least one second device in communication with each other, wherein the cloud, the first device, and the second device are respectively configured to execute the secure access methods described in the first, second, and third embodiments.
[0104] Embodiment 11 of the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a computer processor, the computer program is used to execute the technical solution of any method embodiment. Industrial Applicability
[0105] Through the above description of the implementation methods, those skilled in the art can clearly understand that the present application can be implemented with the help of software and necessary general-purpose hardware, and of course it can also be implemented with hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the existing technology, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory (FLASH), hard disk or optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or grid device, etc.) to execute the methods described in each embodiment of the present application.
[0106] It is worth noting that in the embodiments of the above-mentioned device, the various units and modules included are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application.
[0107] Note that the above are only preferred embodiments of the present application and the technical principles employed. Those skilled in the art will understand that the present application is not limited to the specific embodiments described herein, and that various obvious changes, readjustments, and substitutions can be made by those skilled in the art without departing from the scope of protection of the present application. Therefore, although the present application has been described in more detail through the above embodiments, the present application is not limited to the above embodiments and may include many other equivalent embodiments without departing from the scope of the present application. The scope of the present application is determined by the scope of the appended claims. Sequence Listing Free Content
[0108] This application does not involve a sequence listing.
Claims
1. A secure access method, characterized in that, Applied to the cloud, the method includes: Sending a verification trust root for verifying the identity of the cloud to at least one first device and at least one second device that have been trusted respectively; Receiving an access authorization request sent by the first device; the access authorization request includes: a digital key generated by the first device for accessing a second device; Generating an access certificate authorizing the first device to access the second device according to the access authorization request; the access certificate includes: the digital key; Sending the access certificate to the second device for the second device to verify the access certificate based on the verification trust root, and verifying the first device according to the digital key in the access certificate after successful verification.
2. A secure access method, characterized in that, Applied to the first device, the method includes: Storing a verification trust root sent by the cloud for verifying the cloud; Sending an access authorization request to the cloud for the cloud to generate an access certificate authorizing the first device to access the second device according to the access authorization request; the access authorization request includes: a digital key generated by the first device for accessing the second device, and the access certificate includes: the digital key; Accessing the second device according to the digital key; the second device stores a verification trust root for verifying the cloud; the second device obtains the access certificate and verifies the access certificate based on the verification trust root, and verifies the first device according to the digital key in the access certificate after successful verification.
3. A secure access method, characterized in that: Applied to the second device, the method includes: Storing a verification trust root sent by the cloud for verifying the cloud; Obtaining an access certificate and verifying the access certificate based on the verification trust root, and verifying the first device according to the digital key in the access certificate after successful verification; wherein, the first device sends an access authorization request to the cloud; the access authorization request includes: a digital key generated by the first device for accessing the second device, for the cloud to generate an access certificate authorizing the first device to access the second device according to the access authorization request; the access certificate includes: the digital key.
4. A secure access method, characterized in that, Applied to a secure access system, the secure access system includes: a cloud and at least one first device and at least one second device, the method includes: The at least one first device and at least one second device receive and store a verification trust root for verifying the cloud; A first device sends an access authorization request to the cloud; the access authorization request includes: a digital key generated by the first device for accessing a second device; The cloud generates an access certificate authorizing the first device to access the second device according to the access authorization request; the access certificate includes: the digital key; The second device obtains the access certificate and verifies the access certificate based on the verification trust root, and verifies the first device according to the digital key in the access certificate after successful verification.
5. A secure access device, characterized in that, Configured in the cloud, the device includes: The root-of-trust distribution module is configured to distribute, to at least one first device and at least one second device that have been trusted, a verification root of trust for verifying the identity of the cloud. The receiving module is configured to receive an access authorization request sent by the first device. The access authorization request includes: a digital key generated by the first device for accessing a second device. The authorization module is configured to generate, according to the access authorization request, an access certificate for authorizing the first device to access the second device. The access certificate includes: the digital key. The access-certificate distribution module is configured to send the access certificate to the second device, for the second device to verify the access certificate based on the verification root of trust. After the verification is passed, the second device verifies the first device according to the digital key in the access certificate.
6. A secure access device, characterized in that: Configured in a first device, the apparatus includes: The storage module is configured to store a verification root of trust sent by the cloud for verifying the cloud. The authorization-request module is configured to send an access authorization request to the cloud, for the cloud to generate, according to the access authorization request, an access certificate for authorizing the first device to access the second device. The access authorization request includes: a digital key generated by the first device for accessing the second device. The access certificate includes: the digital key. The access module is configured to access the second device according to the digital key. The second device stores a verification root of trust for verifying the cloud. The second device obtains the access certificate and verifies the access certificate based on the verification root of trust. After the verification is passed, the second device verifies the first device according to the digital key in the access certificate.
7. A secure access device, characterized in that, Configured in a second device, the apparatus includes: The storage module is configured to store a verification root of trust sent by the cloud for verifying the cloud. The access-certificate verification module is configured to obtain an access certificate and verify the access certificate based on the verification root of trust; and The access authentication module is configured to verify the first device according to the digital key in the access certificate after the access certificate verification is passed. Wherein, the first device sends an access authorization request to the cloud, for the cloud to generate, according to the access authorization request, an access certificate for authorizing the first device to access the second device. The access authorization request includes: a digital key generated by the first device for accessing the second device. The access certificate includes: the digital key.
8. A cloud, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and capable of running on the processor. When the processor executes the program, the security access method as claimed in claim 1 is implemented.
9. A terminal device, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and capable of running on the processor. When the processor executes the program, the security access method as claimed in claim 2 or 3 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by the processor, the security access method as claimed in any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Digital key authorization method
CN113556235A
Automobile Bluetooth key security management method, system, equipment and medium
CN115967920A
Security access method and device, cloud, terminal equipment and storage medium
CN117641352A
Unlocking method, device for realizing unlocking, and computer readable medium
WO2020258837A1